Mark Ostrowski
10:00 am - 10:50 am
Organizations treating red teaming as a one-time gate before launch are missing the real value. This session will discuss how ADS Harbour Services reframes red teaming as a continuous lifecycle practice that supports responsible AI at three critical points: (1) Development — integrate adversarial testing into your build cycle to surface risks early as prompts, guardrails, and model configurations change; (2) Validation — execute comprehensive red team campaigns against live applications and agents before production release; (3) Ongoing Operations — schedule recurring red team assessments following updates and capability changes to catch regression and drift. Learn why this three-phase approach uncovers the four essential risk categories—application-specific vulnerabilities, safety and compliance gaps, security weaknesses, and regression risks—and how to build red teaming into your governance model rather than treating it as testing overhead.
Mark Ostrowski has provided thought leadership for the IT security industry for over 25 years, outlining the threat landscape and helping organizations understand how they can proactively mitigate and manage risk in our world of digital transformation and artificial intelligence. Mark is an active cybersecurity educator and media contributor, frequently helping translate complex security issues into practical guidance for organizations and households alike. Today Mark is the CTO at Atlantic Data Security where he is helping clients usher in the latest era of cybersecurity where AI has become a force multiplier in threat prevention and business operations.
Mark Rosenecker
11:00 am - 11:50 am
In the present era of artificial intelligence, its adoption in office environments poses a significant risk of sensitive data types (such as PII, PHI, IP, and more) being inappropriately shared through insecure applications. Given the multitude of AI applications available, it is crucial for organizations to effectively monitor and safeguard their sensitive data from unintentional (or even deliberate) misappropriation. Fortinet offers comprehensive solutions to address these challenges. By leveraging our industry-leading FortiGate, cloud-based FortiSASE, and endpoint-based FortiDLP, Fortinet enables organizations to observe, inspect, and control the flow of sensitive data regardless of the location of their users.
With 31 years of experience in the IT industry, half of which dedicated to cybersecurity, Mark has a solid understanding of the field. Throughout his career, he has held various positions at private colleges, service providers, and large multinational corporations, and his current role as a Senior System Engineer at Fortinet began 7 years ago. Mark also has extensive hands-on experience with a diverse range of solutions, including Palo Alto Networks, Cisco, Checkpoint, and SonicWall, and his decade of experience as a server and virtualization engineer further enhances his skill set. This diverse experience has enabled Mark to develop his unique insights into the industry and identify effective strategies for safeguarding his customers.
John Loya
1:00 pm - 1:50 pm
Every company is becoming an agentic enterprise, where humans and autonomous AI agents work side by side. The competitive edge is no longer any single system. It is the workflows: how human and machine intelligence combine with proprietary data to get work done. Most security leaders are now expected to approve AI adoption, not block it. Yet the tools in place were designed to inspect content at fixed checkpoints, not to follow data through AI tools and agents. The result is AI usage spreading faster than security teams can see or govern, which is how shadow AI takes hold. This session treats data security as part of AI transformation planning rather than a separate tooling decision: one understanding of enterprise data, protection that stays with data through workflows, and action before data leaves the organization's control.
John Loya is the Field CTO at Cyberhaven, where he helps customers and prospects worldwide address data protection needs across compliance, governance, privacy, classification, and agentic wofklows. He previously held roles at Microsoft, McAfee, and Digital Guardian, and began his career as a developer, quality assurance engineer, and automation engineer. With over 20 years of experience in the security industry, John brings deep expertise in Data Loss Prevention and Insider Risk Management.
Sean Wilson and Clarke Caporale
2:00 pm - 2:50 pm
As businesses embrace AI, protecting data and easing organizational security concerns is a top priority. This session goes past the hype to show real-world use cases using Cisco Cloud Control and the AI Canvas workspace. Discover how these tools bring together scattered security systems into a single, easy-to-manage blueprint for stopping threats. By streamlining your workflows, you can confidently adopt AI while keeping your systems safe. As a Cisco Security Preferred partner, ePlus provides the expert advisory, setup, and managed services needed to make this security model a reality. All attendees will be entered into a raffle to win a Jaguar E-Type Lego Set.
Sean Wilson is the UNY Regional Director for ePlus Technology, Inc.
Clarke Caporale is a Cybersecurity Solutions Architect at Cisco.