Brandon Finton
10:00 am - 10:50 am
Every third-party risk program in 2026 is auditing SaaS supply chains and chasing fourth-party risk. Meanwhile, the dominant path to domain compromise in pen tests and incidents is something nobody puts on the agenda: vendor-managed infrastructure with attached privileged accounts. An ISP-managed firewall, an MSP service account, or a vendor's remote access. This session walks through two case studies where vendor-managed infrastructure handed an attacker the keys to the kingdom, and why nobody was looking in the right direction. The failure cascade is the same every time, and it starts where nobody looks. Attendees leave with a practical pattern: back to basics on third parties.
Brandon Finton, MS, CISSP, CISM, is President and Principal Consultant of Orion Secure, a Syracuse-based information security consultancy serving mutual insurance carriers, community banks, municipalities, healthcare organizations, and nonprofits across New York and the Northeast. His practice focuses on virtual CISO services, governance, risk and compliance, vulnerability management, and offensive security testing. Brandon is a board member of the CNY chapter of ISACA and speaks regularly at security conferences and industry events.
Patrick Rost
11:00 am - 11:50 am
Organizations managing multiple compliance frameworks (HIPAA, CMMC, PCI-DSS, State Law) spend weeks preparing for audits covering the same controls. On top of that, more vendors are sending questionnaires and insurance applications are getting longer. Join this session to learn how to create an internal requirements list based on a set of controls that satisfies your external requirements. Become proactive instead of scrambling to answer the same questions several times a year.
Patrick Rost has over 15 years of technology and cybersecurity experience. He is Owner & Advisor at InfoSecurity Blueprint which he founded in 2023 to pursue his passion of helping businesses protect their sensitive information and maintain customer trust. Patrick is dedicated to providing personalized advice to help each business succeed. Previously, he was a Senior Information Security Consultant at a Buffalo-based accounting firm and an IT Manager at a large human services nonprofit. Patrick holds a Bachelor of Technology in Network Administration with a minor in Information Security and Assurance, CISSP, CMMC-RP, and additional certifications. He actively volunteers as a firefighter, EMT, and serves on several local boards and councils.
Andre Piazza
1:00 pm - 1:50 pm
Verification exists to answer one question: is this real? Attackers have stopped answering it; instead, they impersonate the question, cloning verification flows at scale with AI. I walk through two documented cases where deception, not bypass, did the work: a cloned government grant portal that harvested credentials via a fake multi-step login; and a retail scam that weaponized KYC friction to trap victims across brand-swappable infrastructure. The pattern: attackers don't break verification, they impersonate it; the catchable artifact is the infrastructure staged to deliver the lie, observable before the fraud matures. You'll leave able to spot verification theater and turn its signals into detection and user-awareness content.
Andre Piazza is a cybersecurity strategist at BforeAI who works left of boom, catching adversary infrastructure during its staging window, before account fraud or impersonation lands. He works from public signals like certificate transparency and ASN data, linking domains by registration velocity, shared certificate fingerprints, and hosting overlap to surface lookalike infrastructure before it goes live. His work spans verification fraud and AI-built impersonation, and he gives as much weight to the human trust attackers exploit as to the technology. Andre turns published threat research into methods practitioners can use the next day, and speaks at the SANS AI Cybersecurity Summit, Cybr.Sec.Con, and BSides conferences across North America.
Chaim Sanders
2:00 pm - 2:50 pm
Vendors love talking about how they can “solve NHI”, yet when you look at a large-scale analysis of a typical SaaS application portfolio, a horrifying "long tail" of weird and highly insecure access methods reveals itself. From user-generated Personal Access Tokens (PATs) acting as shadow IAM, to immortal SSH keys hiding on disks, these credentials routinely sidestep SSO, Zero Trust, and MFA. We'll explore how these static nightmares break basic assumptions and highlight the unique identity risks introduced by modern AI workflows. Join this session to learn how to wrangle this sprawling attack surface before a forgotten token ruins your weekend!
Chaim Sanders is a security practitioner who discovered a knack for communicating and became a CISO. He is currently the CISO at Lyft. His background is a chaotic mix of academia, offensive engineering, and deep research. This variety forces him to look at security problems—and the current AI hype—through the lens of a builder, a breaker, and a budget-holder simultaneously. Chaim remains overly cynical about the state of computing security, but now he has to do it while wearing a blazer.