Daniel Megalo
10:00 am - 10:50 am
What began as a traditional SOC modernization effort (replacing a SIEM, staffing an in-house 24/7 SOC, and automating with SOAR) quickly evolved into something very different as AI capabilities matured. AI isn't just another capability to add to the SOC. It changes the assumptions the SOC was built on. Drawing from firsthand experience, this session shares practical lessons on leadership, technology, and organizational change, including how the role of the SOC analyst is evolving from alert triage to AI oversight, detection engineering, and continuous improvement. Attendees will leave with actionable ideas for building security operations that defend at machine speed without losing human judgment.
Dan Megalo is a cybersecurity executive with more than 15 years of experience leading security strategy, engineering, and operations across the public and private sectors, including government, healthcare, biotechnology, and banking. He specializes in transforming security programs by aligning technology, people, and business objectives to deliver resilient and scalable capabilities. His recent work has focused on applying AI to modernize security operations and rethink how security teams function as AI and automation reshape traditional SOC models. Dan is passionate about sharing practical lessons that help security leaders navigate emerging threats and new technologies while staying grounded in sound engineering and good judgment.
Rich Ingersoll
11:00 am - 11:50 am
Vulnerability management (VM) is one of the most fundamental — and most frequently underperformed — disciplines in information security. This session delivers a practical framework for building and running an effective VM program, covering core components (asset inventory, scanning, pen testing, and threat intelligence), risk-based prioritization that goes beyond CVSS scores, remediation workflow design, and the metrics that matter. We'll tackle the organizational challenges that break programs — siloed teams, scan theater, alert fatigue, and lack of executive buy-in — and how to address them. Attendees leave with actionable guidance they can apply immediately, regardless of where their program sits on the maturity curve.
Steve Stasiukonis
1:00 pm - 1:50 pm
Rich Ingersoll is the Director of Vulnerability Management at Rochester Regional Health and an Adjunct Professor in the Cybersecurity Department at SUNY Canton, where he brings real-world expertise into the classroom. With a 20-year career at Cisco Systems spanning leadership and technical roles, and subsequent director-level positions in both systems engineering and information security, he has built a reputation as a trusted voice in IT infrastructure and cybersecurity. He holds two master's degrees — one in Cybersecurity and one in IT Management — along with a range of industry certifications.
Steve Stasiukonis is the President of Secure Network Technologies, where he leads penetration testing, information-security risk assessments, IR, and digital investigations. With more than 29 years of experience in the information-security field, Steve has built a distinguished career helping organizations identify critical vulnerabilities, quantify cyber risk, and respond decisively to complex security incidents. Widely recognized for his deep expertise in social engineering, Steve specializes in demonstrating how threat actors exploit human behavior alongside technology to compromise organizations. Steve is a respected thought leader in the cybersecurity community. He regularly contributes expert commentary as a columnist for InformationWeek and DarkReading.
Thomas Richards
2:00 pm - 2:50 pm
Threat-led penetration testing (TLPT) is a pro-active, intelligence driven assessment where the assessors will mimic real world threats faced by the organization. Going beyond traditional penetration testing and differing from a goal-based red team assessment, a TLPT will identify active threat actors in the specific market segment or region. Using this information and understanding their attack patterns, techniques, and motives to drive meaningful penetration testing activities.
Thomas Richards is the Infrastructure Security Practice Manager at DirectDefense. Thomas is currently responsible for overseeing DirectDefense’s network penetration testing, social engineering, and red teaming services. He currently holds the Offensive Security Certified Professional (OSCP) certification and has publicly disclosed dozens of vulnerabilities.