Eric Anderson
10:00 am - 10:50 am
Imagine driving a supercar on a racetrack. Approaching a turn at triple-digit speeds, your confidence to stay on the throttle isn't driven by recklessness — it's driven by trust in the vehicle's brakes. Yet, in business, we often view speed and safety backwards. Innovation pushes the accelerator while governance pulls the handbrake, treating GRC as a roadblock. Using lessons from racing and everyday driving, this session flips the script. We'll explore how safety systems guide, prevent, and mitigate risk — and how good GRC can similarly enable responsible speed, innovation, creativity, emerging technologies like AI, and the work our organizations actually need to accomplish.
Eric Anderson is a cybersecurity practitioner, educator, speaker, and host of the Cybersplainers podcast. Over a career spanning more than three decades, he has worked across engineering, architecture, strategy, and executive advisory roles. Eric specializes in making complex technology and risk concepts understandable without making them boring, and believes good security should help organizations confidently do more — not simply give them more reasons to say no.
Chris Aiwanse
11:00 am - 11:50 am
Technology platformization promises lower costs, unified architectures, and procurement predictability. However, this wave often introduces hidden trade-offs. Does platformization create vendor lock-in? How can organizations strategically leverage frequent vendor acquisitions? This presentation examines why platformization is neither inherently good nor bad. Instead, it introduces a critical tension between operational efficiency and strategic independence—a risk balance cybersecurity leaders must master.
Chris Aiwanse began his career as at Cisco Systems where he was an SE on the Enterprise team, working with the largest clients in the Western NY area. After his time at Cisco, he joined Palo Alto Networks as an SE once again on the Enterprise team but now focusing solely on Healthcare. Following his role at Palo he joined ePlus where he now serves as a Client Security Principal for all of ePlus's clients in Upstate New York. This role allows Chris to provide security guidance and thought leadership across a wide variety of industries.
Greg Stachura
1:00 pm - 1:50 pm
As enterprises rush AI agents into critical workflows, they are creating a new class of compliance, litigation, and insider-risk exposure: decisions made by systems that leave little durable evidence of why they acted, what data informed them, or whether a human actually directed the outcome. This talk examines the emerging AI audit gap, from autonomous agents to cowork-style tools operating on user desktops, and shows how weak logging and poor attribution can turn routine incidents into legal, HR, and regulatory headaches. We will outline pragmatic controls, especially logging, telemetry retention, and EDR-based attribution, to make AI-driven actions defensible
Greg focuses on AI Engineering to support Incident Response and the Cyber Security Operations Center. He has experience managing SIEM, as well as orchestration and automations platforms. He also has extensive background in Incident Response playbook development, forensics and log analysis. Prior to joining Security Risk Advisors, Greg has worked extensively in the financial, healthcare and education sectors.
Kevin Surace
2:00 pm - 2:50 pm
MFA and authenticator apps were built for a world before AI-powered phishing, deepfakes, session theft, device-code attacks, and autonomous agents. Today, attackers do not need to break in — they log in. This session explains why legacy MFA is becoming obsolete and why the next era of cybersecurity requires Biometric Assured Identity: proof that the right human is physically present and authorizing access or action. We will explore how hardware-anchored biometric identity protects employees, privileged users, AI agents, service accounts, APIs, and non-human identities, creating a trusted chain of accountability across the modern enterprise.
Kevin Surace is a Silicon Valley CEO, inventor, futurist, and one of the world’s leading voices on cybersecurity, AI, and biometric assured identity. Known as the “Father of the Virtual Assistant,” Kevin has 95 worldwide patents and has pioneered breakthroughs in AI, mobile computing, cybersecurity, automation, and enterprise transformation. As CEO of TokenCore, he is helping move organizations beyond passwords, MFA, and vulnerable credentials to hardware-anchored biometric assured identity for humans, AI agents, and non-human identities. Kevin delivers 40 keynotes worldwide each year and brings rare energy, humor, and practical urgency to the cyber stage.