Deke Johnson
10:00 am - 10:50 am
Artificial Intelligence is dominating boardroom conversations, regulatory discussions, and cybersecurity headlines, yet many Governance, Risk, and Compliance (GRC) teams are still asking a simple question: where do we start? This session explores practical AI use cases within modern GRC programs, including risk assessments, audit readiness, evidence collection, policy analysis, reporting, and governance workflows. Attendees will learn where AI can deliver measurable value today, where human oversight remains critical, and how organizations can begin introducing AI responsibly while maintaining strong governance, compliance, and risk management practices.
Dekedrian “Deke” Johnson is a Governance, Risk, and Compliance (GRC) professional with 12+ years of experience across cybersecurity, risk management, audit, identity governance, and compliance. He currently serves as a Staff Analyst within the GRC organization at Fanatics, supporting enterprise governance, audit, and access management programs. Previously, he held cybersecurity and risk roles at Paychex, Frontier Communications, and PwC. Deke also serves as Chair of the Supervisory Committee for The Summit Federal Credit Union and as a Board Trustee for Vertus Charter High School. His interests include AI governance, compliance automation, and emerging echnology risk.
Janhavi Dhariya
11:00 am - 11:50 am
Modern systems generate large volumes of high-speed telemetry, making it difficult for security teams to distinguish unusual activity from normal operational variation. This session presents a motorsport-inspired cybersecurity case study that explores how machine learning can support anomaly detection in real-time data streams. Using synthetic, multivariate racing telemetry, the prototype applies Isolation Forest, One-Class SVM, and PCA reconstruction error to identify injected anomalies such as sudden spikes, added noise, and gradual sensor drift. The session examines the analytics pipeline, model behavior, visualization approach, implementation challenges, and limitations encountered during development. It also explores why gradual anomalies can be difficult to detect and how relationships between multiple signals may provide more useful context than evaluating each measurement against a fixed threshold. The findings are connected to telemetry-heavy environments such as industrial systems, manufacturing, connected vehicles, aviation, and clinical monitoring, while recognizing that a research prototype requires further validation before real-world deployment. Attendees will leave with practical guidance for selecting meaningful signals, establishing operational baselines, evaluating detection results, and using anomaly alerts as investigative leads rather than definitive proof of malicious activity.
Janhavi Dhariya is an M.S. student in Cybersecurity at Rochester Institute of Technology and an Information Security Governance, Risk, and Compliance Co-op at Rochester Regional Health. Her experience spans vulnerability analysis, security automation, data analytics, and operational risk. At RIT, her research and technical projects have explored telemetry anomaly detection, post-quantum authentication, and covert channels in enterprise environments. She is particularly interested in translating cybersecurity research into practical controls that help organizations make trustworthy decisions under uncertainty. Janhavi has grown from volunteering at the RSS last year, to speaking her heart out. Her love of motorsport inspired this telemetry case study, and she believes a well-made cup of coffee is usually part of the research process.
Ryan McCoy & Paul Scott
1:00 pm - 1:50 pm
Small IT and security teams are expected to defend modern organizations against evolving threats while managing infrastructure, compliance, user support, and daily operations often without enterprise budgets or dedicated security staff. This session explores practical, real-world strategies for building a mature and sustainable security program in a lean environment. Drawing from hands-on experience aligning operations with frameworks like ISO 27001 and NIST, the talk focuses on high-impact controls, operational simplicity, automation, and reducing security fatigue. Learn how small teams can improve security posture, scale processes effectively, and achieve meaningful security outcomes without overengineering their environment.
Ryan McCoy is Knowledge Systems & Research’s Director of IT and Security Officer with 20+ years in the IT industry with the past 8 years dedicated to KS&R. He is experienced in designing, managing, and securing enterprise network infrastructure with a strong focus on cybersecurity, data protection, and operational reliability. Ryan is passionate about defending organizations from evolving external threats while keeping data security a top priority across all systems and processes. He is CompTIA Security+ (SEC+) certified with a proven track record in risk management and technology strategy.
Paul Scott is the founder of NorthPoint Advisory Group and a CISSP-certified executive with more than 30 years of experience helping organizations manage technology, cybersecurity, and business risk. His background spans governance, data privacy, incident response, software and database development, technology operations, and the protection of sensitive and regulated data. He holds a Master’s degree in Cybersecurity and brings the perspective of a technology executive who understands how cybersecurity decisions affect customers, revenue, operations, and growth.
Dmitrii Korobeinikov, AJ Barea & Dr. Leon Reznik
2:00 pm - 2:50 pm
AI systems that learn from your customers' data create real privacy and compliance risk — but keeping data local doesn't mean you're safe. Federated Learning avoids raw data transfer, yet attackers can compromise individual devices and silently corrupt AI models. This session offers a practical decision framework for designing FL applications that detect and respond to attacks automatically, balance security overhead against model performance, and adapt to changing conditions, all without requiring a research team to operate. Attendees leave with a concrete methodology they can apply to their own AI deployments.
Dmitrii Korobeinikov is a Ph.D. researcher in Computing and Information Sciences at Rochester Institute of Technology specializing in federated learning, AI security, and large-scale experimentation. He is the founder and maintainer of the IntelliFL research framework and has authored numerous publications on trustworthy AI, anomaly detection, and distributed machine learning. With experience in both academic research and industry software development, Dmitrii’s work combines machine learning, cloud computing, and cybersecurity to build robust and scalable intelligent systems.
Arnaldo (AJ) Barea is a Ph.D. researcher in Computing and Information Sciences at Rochester Institute of Technology, working on federated learning, trustworthy distributed machine learning, and human-on-the-loop multi-agent systems. He builds and maintains Velocity-FL and Pharos, open frameworks for benchmarking and auditing federated systems, and has co-authored publications in IEEE Intelligent Systems and IJCNN. AJ’s work combines machine learning, software architecture, and cybersecurity to make distributed AI systems reproducible and auditable.
Dr. Leon Reznik is a Professor of Computer Science and the member of the ESL Global Cybersecurity Institute at the Rochester Institute of Technology, New York, USA. He conducts research and teaches classes in the areas of cybersecurity, federated learning, ML and AI with their applications in computer security and privacy protection, intrusion detection, computer vision, intelligent control systems, sensor systems and networks. His new textbook “Intelligent security systems: How artificial intelligence, machine learning and data science work for and against computer security” was recently released by IEEE Press - Wiley and Sons. Prof. Reznik authored another textbook and almost two hundred papers in these fields as well as edited a few research volumes. This research was supported by NSF, NSA, DoD, CRDF Global as well as ARC. Please, see his website at https://cs.rit.edu/~lr/ for more information.