Search Results for "2016"

Platinum Sponsor Feature: Sunera

www.sunera.com

@suneraLLC

Sunera LLC

Sunera is a leading provider of risk-based consulting including Internal Audit, IT Audit, Information Security, Corporate Governance, and Regulatory Compliance.

Come see us at RVAsec 2016! Register Now.


Speaker Feature: Andrew McNicol & Zack Meyers

Andrew McNicol

Andrew McNicol @PrimalSec

@b3armunch

https://breakpoint-labs.com/blog/

BreakPoint Labs
Andrew McNicol is driven by his passion for helping organizations identify exploitable vulnerabilities before an adversary. He is currently the CTO at BreakPoint Labs specializing in offensive security services, mentor for SANS, and one of the founders and lead authors of Primal Security. Previously, he lead a penetration testing team and worked on an incident response team focusing on malware analysis and network forensics for DoD, Law Enforcement, and Commercial companies.

Andrew holds an M.S. in Information Assurance, and variety of InfoSec qualifications (OSCE, OSCP, OSWP, GICSP, GCFA, GCIA, GCIH, GPEN, GREM, GSEC, GWAPT, GWEB, CISSP, CEH, etc.)

Zack Meyers is a business oriented guy that then became a motivated InfoSec geek after getting started aZack Meyerss a continuous monitoring vulnerability analyst. Shortly after, he took an interest in the offensive side of security work and currently works as an Offensive Security Engineer at BreakPoint Labs. Today he is always looking to learn about new techniques and tools that can help him identify his next big vulnerability finding. He is currently a member of Primal Security Blog | Podcast and holds several security certifications including OSCP, CISSP, GWAPT, GPEN, GCIH, etc

Beyond Automated Testing
Have you ever run a vulnerability scan and thought “Okay… now what?” This talk is all about how to go beyond automated testing to find vulnerabilities that scanners miss. The goal of the talk is to help inspire others to reach beyond Nessus and Burp Suite scans to help their organization identify vulnerabilities that expose high impact risk.

Register Now!


Speaker Feature: Ben Smith

Ben Smith

@Ben_Smith

Ben Smith

blogs.rsa.com/hunting-sharks-teeth-iocs/

RSA
Ben Smith is Field Chief Technology Officer (Field CTO – US East) with RSA, The Security Division of EMC. He is a trusted advisor and consultant to RSA’s global financial services customers, as well as customers in other vertical markets. With over 25 years’ experience in the networking, information security and telecommunications industries, he is responsible for consulting on RSA’s strategic vision around architecture and technical roadmaps for the company’s security and risk management solutions. Prior to joining RSA, he held senior technical positions at UUNET, Intuit, CSC, and the US Government, along with a string of technology-oriented startups. He holds a number of professional technical certifications, including the Certified Information Systems Security Professional (CISSP) certificate, and has presented on RSA’s behalf, both domestically and internationally, at cybersecurity events sponsored by Gartner, FS-ISAC, ISSA, ICI, (ISC)2, ISACA, InfraGard, HTCIA and other organizations.

Measuring Security: How Do I Know What a Valid Metric Looks Like?
There is no universally accepted method to measure security. So how do we translate operational measurements into meaningful security metrics for the business? Doing so effectively is essential, because you can’t manage what you don’t measure. This session will touch on the following general questions: Why are security metrics important, from both a compliance and an operational perspective? What are some best practices to keep in mind when selecting security metrics? Does your audience(s) dictate which metrics to select? What behaviors are you trying to influence with these metrics? What are some unexpected sources of security metrics? How should you communicate those metrics internally within your organization for maximum impact? Are there any examples of poor metrics which should be avoided in most cases?

Register Now!


Speaker Feature: Andrew Hay

Andrew Hay

Andrew Hay

Andrew Hay

@andrewsmhay

www.andrewhay.ca

DataGravity
Andrew Hay is the CISO at DataGravity where he advocates for the company’s total information security needs and is responsible for the development and delivery of the company’s comprehensive information security strategy. Prior to that, Andrew was the Director of Research at OpenDNS (acquired by Cisco) and was the Director of Applied Security Research and Chief Evangelist at CloudPassage, Inc.

Maneuvering Management Madness
Why do practitioners have such a hard time convincing their management team about the value of investing in security training, tools, and other initiatives? Is it because they’re too stubborn or busy to take the time to assess the concerns or is it more likely that you haven’t found the best way to communicate the threat to the business in a language that they understand?

Business leaders have implemented their own language, much of which was learned in business school, to better communicate with shareholders, board members, partners, and peers. Unfortunately, this language is often as foreign to most security practitioners as yours is to them. So what can practitioners do to better communicate with management?

This session will discuss several tactics to help convince your management team that your concerns are valid with examples on how to justify requests for headcount, procedures, policies, and human, tool, and training investment.

Register Now!


Hotel Information – Book now!

RVAsec has reserved a block of rooms at the Crowne Plaza for out of town guests. The rate is $121/night (which does NOT include parking).

You can either book online or call the hotel.

When you call (855-472-7802) the hotel please tell mention the block “RV3” to get the special rate.

  • Secure your reservation by 5/2/16 to ensure receiving the group rate
  • Discounted parking rate of $10.00 per car, per night.
  • Please note that the Booking Link will not work on a smartphone

 

Crowne Plaza Richmond Downtown
555 East Canal Street, Richmond VA 23219

800-2CROWNE



View Larger Map
If for any reason you are unable to get the RVAsec rate or the block of rooms has been filled, please let us know so we can contact the hotel!

Once the block is full or expires we are not able to have it extended.

Make sure you check out information on getting to the conference.


Gold Sponsor Feature: Cigital

https://www.cigital.com

@cigital

Cigital

Cigital is one of the world’s largest application security firms. We go beyond traditional testing services to help our clients find, fix and prevent vulnerabilities in the applications that power their business. Our holistic approach to application security offers a balance of managed and professional services and products tailored to fit your specific needs. We don’t stop when the test is over. Our experts also provide remediation guidance, program design services, and training that empower you to build and maintain secure applications.

Come see us at RVAsec! Register now.

 


Help Choose The RVAsec Logo!

voteJune is fast approaching and we are in high gear planning RVAsec.  The CFP just closed and the committee is in the process of reviewing and choosing talks for this year.  We hope to publish the speaker selection very soon!

A quick reminder that you have until April 20th until ticket prices increase.  If you have not yet purchased your ticket, you might as well go ahead and get it done now:
http://rvasec.com/register/

This year we are having a contest to determine the logo design for the conference and shirts!   We did an initial first round of voting, and used that feedback to help improve the designs.

Now we need everyone to help us and vote on the logos!

Here is the link for the final round of RVAsec logo voting:
https://99designs.com/logo-design/vote-pewk3j

The poll will be open until the end of the week, and then we will choose the winning design.  Thanks everyone for your help, and please spread the link so we get as many votes as possible!


Wendy Nather (@RCISCwendy) To Keynote RVA5ec!

Wendy Bio PicWe are pleased to announce that Wendy Nather will be keynoting RVA5ec 2016!

Wendy Nather is Research Director at the Retail Cyber Intelligence Sharing Center (R-CISC), where she is responsible for advancing the state of resources and knowledge to help organizations defend their infrastructure from attackers. She was previously Research Director of the Information Security Practice at independent analyst firm 451 Research, covering the security industry in areas such as application security, threat intelligence, security services, and other emerging technologies.

Wendy has served as a CISO in both the private and public sectors. She led IT security for the EMEA region of the investment banking division of Swiss Bank Corporation (now UBS), as well as for the Texas Education Agency. She speaks regularly in locations around the world on topics ranging from threat intelligence to identity and access management, risk analysis, incident response, data security, and societal and privacy issues. Wendy is co-author of The Cloud Security Rules, and was listed as one of SC Magazine’s Women in IT Security “Power Players” in 2014. She is an advisory board member for the RSA Conference, and serves on the board of directors for Securing Change, an organization that helps provide free security services to nonprofit groups. She is based in Austin, Texas, and you can follow her on Twitter as @RCISCwendy.


RV4sec Videos: Speed Debates hosted by Chris Eng

Speed Debates hosted by Chris Eng (@chriseng)

Featuring: Pete Herzog (@peteherzog), Robert Stratton (@strat), Boris Sverdlik (@jadedsecurity), Mark Painter (@secpainter), Tim Wilson (@darkreadingtim) and Casey Ellis (@caseyjohnellis)

 


RV4sec 2015 Recap

We have finally recovered from RV4sec and wanted to bring you a quick recap!  We sold 386 tickets this year, and was on par for attendance from the previous year.  It was great to see so many new faces this year and we hoped everyone had a great time.

What were thrilled to bring you:

  • RVAsec 6 pack cooler bag stuffed with swag
  • Capture The Flag with live bug hunting sponsored by UNOS!
  • RVAsec t-shirt with “Inside the Mind of the Hacker” logo designed by 14-year-old @AylaMadison
  • Post-con reception with adult beverages (and more food) with great Passport prizes
  • After party sponsored by Rapid7, GuidePoint and nVisium!

 

What to expect in the coming weeks:

  • Surveys should be sent out shortly, please take the time to provide us your valuable feedback
  • Slides will be posted
  • Videos will be posted to the RVAsec YouTube channel.
  • We hope to be able to post up a CTF recap as well

 

Thanks again to all our our speakers, sponsors and volunteers!

Next year, RVAs5c will be June 2-3, 2016.

See you next year.

Jake and Chris