RSS:2026 Track 2 (Day 1) :: Rochester Security Summit

RSS:2026 Track 2 (Day 1)

Defending at Machine Speed Without Losing Human Judgment

Daniel Megalo
10:00 am - 10:50 am

What began as a traditional SOC modernization effort (replacing a SIEM, staffing an in-house 24/7 SOC, and automating with SOAR) quickly evolved into something very different as AI capabilities matured. AI isn't just another capability to add to the SOC. It changes the assumptions the SOC was built on. Drawing from firsthand experience, this session shares practical lessons on leadership, technology, and organizational change, including how the role of the SOC analyst is evolving from alert triage to AI oversight, detection engineering, and continuous improvement. Attendees will leave with actionable ideas for building security operations that defend at machine speed without losing human judgment.

Dan Megalo

Dan Megalo is a cybersecurity executive with more than 15 years of experience leading security strategy, engineering, and operations across the public and private sectors, including government, healthcare, biotechnology, and banking. He specializes in transforming security programs by aligning technology, people, and business objectives to deliver resilient and scalable capabilities. His recent work has focused on applying AI to modernize security operations and rethink how security teams function as AI and automation reshape traditional SOC models. Dan is passionate about sharing practical lessons that help security leaders navigate emerging threats and new technologies while staying grounded in sound engineering and good judgment.

Running an Effective Vulnerability Management Program

Rich Ingersoll
11:00 am - 11:50 am

Vulnerability management (VM) is one of the most fundamental — and most frequently underperformed — disciplines in information security. This session delivers a practical framework for building and running an effective VM program, covering core components (asset inventory, scanning, pen testing, and threat intelligence), risk-based prioritization that goes beyond CVSS scores, remediation workflow design, and the metrics that matter. We'll tackle the organizational challenges that break programs — siloed teams, scan theater, alert fatigue, and lack of executive buy-in — and how to address them. Attendees leave with actionable guidance they can apply immediately, regardless of where their program sits on the maturity curve.

Rich Ingersoll

Rich Ingersoll is the Director of Vulnerability Management at Rochester Regional Health and an Adjunct Professor in the Cybersecurity Department at SUNY Canton, where he brings real-world expertise into the classroom. With a 20-year career at Cisco Systems spanning leadership and technical roles, and subsequent director-level positions in both systems engineering and information security, he has built a reputation as a trusted voice in IT infrastructure and cybersecurity. He holds two master's degrees — one in Cybersecurity and one in IT Management — along with a range of industry certifications.

The Real Risk: Ransomware, Extortion, and the Dark Web

Bruce Cheney
1:00 pm - 1:50 pm

Cybercriminals aren’t just using ransomware—they’re running extortion campaigns, leaking data on the dark web, and adapting faster than ever. With losses exceeding $20 billion in 2025, the stakes are higher than ever for security teams. In this technical session, Bruce Cheney, Sr. Engineer at Arctic Wolf, dives deep into how today’s most dangerous threat actors operate. He’ll analyze real-world data leaks, dissect extortion tactics, and walk through the dark web ecosystems where stolen data is traded. Expect real-world insights, examples of leaked data, and a no-jargon framework to guide strategic cybersecurity decisions. This talk is designed to sharpen your understanding of Risk and strengthen your response.

Bruce Cheney

Bruce Cheney is a cybersecurity expert and keynote speaker with over 25 years of experience in IT and threat intelligence. He helps organizations identify and mitigate real-world cyber risks—including ransomware, extortion, and data leaks from the dark web. Known for making complex threats easy to understand, Bruce regularly speaks at industry conferences, guiding teams and leaders in building stronger, more secure operations.

Don't Go Alone: Take this Threat Intel!

Thomas Richards
2:00 pm - 2:50 pm

Threat-led penetration testing (TLPT) is a pro-active, intelligence driven assessment where the assessors will mimic real world threats faced by the organization. Going beyond traditional penetration testing and differing from a goal-based red team assessment, a TLPT will identify active threat actors in the specific market segment or region. Using this information and understanding their attack patterns, techniques, and motives to drive meaningful penetration testing activities.

Thomas Richards

Thomas Richards is the Infrastructure Security Practice Manager at DirectDefense. Thomas is currently responsible for overseeing DirectDefense’s network penetration testing, social engineering, and red teaming services. He currently holds the Offensive Security Certified Professional (OSCP) certification and has publicly disclosed dozens of vulnerabilities.