Showing posts with label conferences. Show all posts
Showing posts with label conferences. Show all posts

Monday, January 18, 2021

Forward into 2021

 Well, here we are in 2021.  A lot has happened to all of us this past year.  I think all the security conferences I usually attend this past year from March on were either cancelled or went virtual.  And it looks like the same will occur thru some of this year.

I've also been behind in trying to post regularly on this blog and hope to address this and aim to post at least twice a month.  I am planning on tackling some additional certifications in the cloud and privacy areas, and will be posting on this, as well as areas I have an interest in.  Futher, I plan on presenting at upcoming conferences and events, so will be posting on that.

Here in Florida, I know that BSides Tampa will be virtual in 2021, and I have proposed a few ideas.  Not sure about BSides Orlando.  South Florida ISSA does plan on doing their Hack the Flag, hopefully live.  Both SFISSA and HackMiami will be having regular meetings on-line, as well as South Florida ISACA.

If anyone has any ideas or suggests, please post them.


Monday, February 17, 2020

Upcoming Security Events in Florida

There are several upcoming information security events in Florida that some may not be aware of.

First up is the South Florida ISACA Chapter's annual WOW event.  This year its the thirteenth year of the event.  It will be held on Friday February 21st, 2020, again at FIU's Koven Center at their Biscayne Bay campus.  This is a single-track conference, with various speakers and a panel discussion.  Its usually a good event, and plan on being there.

Next up is Security BSides Tampa.  The seventh year for this event, it will be held Saturday, February 29th, 2020 at the Embassy Suites on the USF Campus in Tampa.  There will be training sessions on Friday.  This event is a multi-track conference, with tracks including CISO, Cloud, and job fair.  They also have other activities like a CTF, Lockpicking, and more.  This is a pretty good event.  Sadly, I don't plan on attending this year.

Then there is Security BSides Orlando.  This will be Saturday, April 11, 2020 at Full Sail University's Live Venue.  I believe they are planning on doing training sessions on Friday.  The schedule hasn't yet been announced.  They also have other activities like CTF, Lockpicking, and more.  This is also a pretty good event and it seems BSides Tampa and Orlando have some of the largest BSides outside of Vegas.  I'm not sure at this point if I'll be going.

Finally, there is HackMiamiCon.  This time it will be Saturday, May 30th, 2020 at Broward Library.  There will be training events on Friday.  This is a change of venue from hotels on Miami Beach, so will remain to be seen how this works out.  They should have other activities like a CTF.  This is also a good event.  Due to a conflict with another event, I may not attend this year.

These are all great events and I encourage folks to check them out and attend.


Wednesday, February 12, 2020

2020 SecureMiami Conference

This past weekend I attended the 2020 SecureMiami Conference.  This was the 4th time this conference was held, again at FIU's Graham Center and co-located with BrewMiami held later that day at the FIU stadium.  I've been to all of these events, promoting the South Florida ISSA Chapter and had a good time.

This event was organized by DigitalEra and again had a great number of speakers and panels, and a good set of sponsors and exhibitors. 

I enjoyed Jorge Orchilles talk.  He is a past president of our chapter.  Hacker Hector Monsegur was the final speaker, and I wasn't previously aware of him.  He gave a great talk from the point of being a former 'black hat' who has become a 'white hat.

I look forward to next years event.  This one sold a quickly with a large waiting list.  Will they move to a new location because of this?


Tuesday, April 9, 2019

2019 Security BSides Orlando

Saturday March 30th, the 2019 Security BSides Orlando conference was held.  This is the 6th one, and the largest yet.  Believe they had over 700 in attendance.  As last year, it was held at Full Sail University's Live venue location. 

This year there were 4 tracks of speakers, along with several workshops and a CFT.  Several sponsors were in attendance.  No job track this year.

There was a book signing with the book Tribe of Hackers as there were 3 hackers from the book in attendance.

And there was an electronic badge again this year, but this time was a little more complex and programmable. 

No idea where next year's event will be, but will probably be tied to SANS Orlando again.



Thursday, April 4, 2019

SFISSA Security Conference

On March 22, 2019, the South Florida ISSA held their biannual 2019 Security Conference.  This time the theme was "A New Year, a New Era of Cybersecurity".

The conference had 4 tracks of speakers, as well as a 2 hour workshop on your cybersecurity career.  A keynote address was given by Dave Aitel of Cygtera, and a CISO panel was held with 4 local CISO from different companies.

An array of sponsors were present as well.  Breakfast and lunch were provided, and everyone had a great time.

The next event of the chapter will be their annual Hack the Flag/Chili Cookoff held September 7th at FIU's Graham Center.



Wednesday, February 13, 2019

2019 Secure Miami

This past weekend I attended 2019 Secure Miami conference, the third edition of this local cybersecurity conference.  Organized by DigitalEra, and held at FIU, it also tied to BrewMiami, held later that day at FIU.

This was a full day event held in FIU's Graham Center with key note speakers and panel discussions.  As I've been to the prior events, I felt this as good or better then the last one.

On the panel discussions, topics covered included the "Cybersecurity skills gap", "managing visibility and compliance" and "smart cities".  The skills gap discussion was interesting, as I know several who struggle to find work and our hiring process in IT/infosec is broken.  Had a good chat with one of the people on the panel about the NICE conference that we had at FIU and learned the next one will be in Phoenix.  The smart cities one got into the matter about IoT security and the like.  We'll see where that goes.

On the keynotes, they had an interesting one given by a former FBI Agent and his experiences, and another about artificial intelligence.  AI was a topic I had a keen interest in college, but drifted away from, that seems to have become more a topic in infosec.  I need to get back on top of that.

Afterwards many of us headed over to the BrewMiami event and chatted and had fun.  Another great event.  I look forward to next year's event, as well as other upcoming events in the area:  ISACA South Florida's WOW event, Infragard South Florida's next meeting, South Florida ISSA's Conference and HackMiamiCon.





Monday, February 4, 2019

BSides Tampa 2019

This past Saturday (Feb 2nd), the 2019 BSides Tampa Conference was held.

In a change from past years, they've moved to a new venue, the Embassy Suites on the USF Campus.  The 2020 Conference will also be held there, apparently on February 29th.

This year there were about 8 tracks of talks, including one for job seekers.  There were many vendors in attendance as well as several infosec groups.  The Tampa Bay chapters of ISSA, ISC(2), and IAPP were in attendance, along with a couple of universities with infosec programs.

I spoke again on the topic of updated and upcoming frameworks, standards, and regulations for infosec people.  I'll be posting separably on that talk with links to information I spoke of.

Overall, I thought the event went great.  Sadly, due to other issues, this year I flew in that morning and left that evening, so missed out on the dinner the night before for speakers and couldn't hang around for the afterparty.  Maybe next year.



Sunday, February 3, 2019

2018 NIST Cybersecurity Risk Management Conference

Back in October I was in Baltimore for NIST's 2018 Cybersecurity Risk Management Conference.  For those not aware, let me break this down.  NIST is the National Institute of Standards and Technology, a non-regulatory research arm of the Department of Commerce.  For those of us in the IT and infosec world, we know NIST for their SP800 and SP1800 series of documents on various IT and infosec topics, for creating the Risk Management Framework (sometimes call FISMA) and the Cybersecurity Framework (CSF).

For the last two years they held annual workshops for the CSF (these were actually the 7th and 8th), which I was able to attend and previously reported on.  The main purpose of these workshops was to bring people together to look at the future of the CSF, and develop the next version, which was v1.1 that came out earlier this year.

This year we instead got a 3 day conference held at a hotel in Baltimore.  It was a mix of plenary sessions, work sessions, panel discussions, and presentations.  There were also working lunches for those who paid extra for 'catering'.

It was almost overwhelming the number of sessions, as there were about 8-9 sessions going on at once during certain period.  Some of the slide decks from these presentations are made available, as there was almost too much information.

Some of the items I learned was details on the updating going on with various documents related to FISMA.  I knew this was going on, but got more details.  Also learned more about the plans for PCI-DSS v4, which is planned for development over the coming year.  I also learned more about the Baldridge Cybersecurity Excellence Builder (which will have an update early next year).

There were some problems, I think due to the change in venue and expansion from the workshops.  I hope these will be addressed for the next one.  At this point, we don't know when or even where the next one will be.  So we'll have to see.  I hope I can attend the next one as well.

Monday, October 29, 2018

2018 ISSA International Conference

This past week I attended the 2018 ISSA International Conference in Atlanta.  I've attended the last 4 conferences (San Diego, Austin, Chicago, Orlando).  There were good and bad points about this year's conference.  I'm not sure where the 2019 conference will be, but hope I can attend it as well.

The day before the conference, I attended the ISSA Chapter Leader Summit as the president of the South Florida Chapter.  I've attended the prior 4 as well.  I was at the conference with 3 other chapter officers, and I know we had 2 others from our chapter in attendance as well.

Monday, September 24, 2018

Report on BSides Miami 2018

Saturday, September 22, 2018 we had our first Security BSides conference in the South Florida area: BSides Miami.  Hosted at i2 Labs on Biscayne Bay, we had two tracks of speakers, several panels, and about 80+ participants.

I spoke at the conference on the topic of Security Maturity Models.  Interestingly, the presidents of the South Florida ISACA Chapter and HackMiami also spoke at the conference.

For a first time conference, it was overall good.  There were problems, which will happen with a first time event.  I hope they address this for the next time, and I do hope there is a next time.  I was bothered by the emphasis on blockchain.  For my view, BSides should be a conference by and for the whole infosec community.  We should have sessions that appeal to and be of value to a wide range of folks: those getting into the field, mid-level folks, experienced folks, etc.  I do like that seeing other activities at BSides conferences, like job fairs, hack the flag games, lock picking, etc.  A blockchain track is one thing, but it shouldn't overwhelm the overall conference.

Do to the problems with my presentation, I'll be posting a summary here soon.




Wednesday, June 13, 2018

Report on HackMiamiCon6

HackMiami held its 6th Conference in 2018.  And this year we had another new location, tho it wasn't the organizers fault.  :)  The previous location suffered a fire, so this year they moved to Seacoast Suites.  This limited them a bit, as the rooms were not as spacious as with the Deauville.  And there were few food options within walking distance as with the Deauville. 

That aside, I thought overall they had another great conference.  This year they did an electronic badge, but this was a limited-run add-on, due to cost.

Two days, both kicked off with keynote addresses.  Both were good, and the second day we had Jack Daniel, who is kind of the father of BSides.  There were a good mix of talks and presentations, even a few longer workshops in the evening.  I spoke on the second day on cyber resilience/disaster recovery.  With the recent hit by Irma in Florida (and Maria in PR), I felt this was a good topic. I think it overall went well.

Congrats as always to the HM folks for putting on this conference.  Am surprised that they have already set the date and location for the 2019 conference, and will be back at the Deauville!  Registration is even open on their website!



Monday, June 11, 2018

Report on BSides Orlando 2018

Security BSides Orlando was back in 2018, the 6th year.  There were some issues this year.  They have been tied, scheduling-wise, to SANS in Orlando, but this year they had a weird schedule of April 3-10, which is Tuesday thru Tuesday, rather Sunday-Saturday like schedule.  So they went with April 7, right in the middle.

The other issue was location.  After several years at University of Central Florida, last year they were at Valencia College.  This year they were at Full Sail University's Live Venue location in Winter Park.  And, yes, another one day event.

The Full Sail location was interesting.  They added a lot of other activities to the schedule, which was nice, but I was sadden that this limited the number of actual talks, as this decreased the number of rooms available, so instead of having 4-5 talk tracks, there were only 2.  I had submitted several proposals, and none were picked.  So this was a personal disappointment for myself.

This year they did an electronic badge, which required participants to solder the items on the board.  They had a station setup to solder them, with people helping, which was great.  Probably needed to have a few more soldering irons, but still nice.  The blue badge was for participants, red was staff/volunteers.  Then they added a plastic hanger below to indicate speakers, sponsors, etc.



Here is a shot of the t-shirt and program book.

Overall a great event this year.  I look forward to next year's event.  SANS has set the date for SANS Orlando, so hopefully the BSides Orlando folks can set their date for next year's event.

Wednesday, February 28, 2018

Report on BSides Tampa 2018

On Saturday, February 17th, I was in Tampa for the 5th Security BSides Tampa Conference.  This was my third time attending, and my third time speaking.  I spoke on the topic of the new "SOC for Cybersecurity" report.  I'll do a separate posting on this report, giving resources.

This conference had about 700 registered people there, not sure how many where there.  As with the prior couple of conferences, it was again held at the Stetson College of Law center in Tampa.

There were 5 tracks, a capture the flag game, lockpick village, training, and a recruitment track again.  Several great speakers.  Jack Daniel, Ira Winkler, Greg Hanis, and more.  I also had some good conversations with several people.

There were some problems last year, and I think they did a good job of addressing these.  My only personal complaint was it being on President's Day Weekend due to other commitments which I had to miss on.  Hopefully what ever date they pick next year won't conflict for me.


Thursday, February 22, 2018

Report on ISACA South Florida's WOW Event

The South Florida Chapter of ISACA has been holding an annual one-day conference each year in February known as the WOW! Event.  In 2018, they held their 11th conference on Friday, February 16th at FIU's Koven Conference Center at their Biscayne Bay campus.

This year's theme was "The InfoSec of Things: Emerging issues in Privacy and Security".  There were about 250 people in attendance for the day, with several speakers and a panel discussion with several local CISOs.

Speakers included:

Tuesday, February 20, 2018

Report on SecureMiami 2018

On Saturday, February 10, 2018, DigitalEra hosted their second "annual" security event, Secure Miami at FIU, co-located with Brew Miami.  Their first event was in December of 2016.

Attendance was pretty good at this event, with about 350 registered to attend.  This year they moved it to the larger Graham Center in the University Center.  Lunch was provided.

There were several security vendors in attendance.  The South Florida ISSA Chapter assisted, so we were there with a booth. 

Speakers were a good selection of national level folks, along with a panel discussion with various security leaders.  These included:  Malcolm Harkins with Cylance, Hollis Howell from Rapid7, and Kevin Reardon with Symantec.  Panelists were from FIU, Trapezoid, Network Health, and Trend Micro.

Overall, a very nice half-day security event.  I believe DigitalEra is planning on doing this again next year, and I look forward to it.




Friday, February 2, 2018

Upcoming Conferences in early 2018

There are several local security conferences coming up in my general area, some of which I'll be speaking at.

Here are the ones over the next few months:

* SecureMiami 2018, co-located with BrewMiami.  Organized by DigitalEra, this is the second time for this half day event at the main campus of Florida International University.  Held on Saturday, February 10th.  Registration is open NOW and I encourage people to attend.

* ISACA South Florida Chapter's 11th WOW Event is coming up on Friday, February 16th at FIU's Biscayne Bay campus.  The theme: The InfoSec of Things: Emerging issues in Privacy and Security, and have great lineup of speakers.  So register NOW.

* BSides Tampa 2018 is coming up Saturday, February 17th again at Stetson Law in Tampa.  I will be speaking here on the topic of "SOC for Cybersecurity".  I think they are sold out, but check anyway.

* BSides Orlando 2018 is coming up on Saturday, April 7th.  Location this year will be Full Sail Live Venue in Winter Park.  CFP is open, and I've submitted some proposals, and registration is open NOW.

* HackMiamiCon6 is coming up May 18-20.  This year they will be at Sea Coast Suites in Miami Beach.  I will be speaking there on protecting your organization with resilience and disaster recovery.  Registration is open NOW.

So, there are more coming down the road.  Stuff in the summer and stuff coming up in the Fall, especially in October do to Cybersecurity Awareness Month.

Check back for more.  I will be doing postings reporting on these events after they are done.



Sunday, November 5, 2017

Cyber Resilience- what I've found (Part 1)

A year or so ago I came upon the idea of "cyber resilience", which is a general concept of 'hardening' or toughing, or making more resilient, our IT/cyber systems.  I started seeing the terms used a lot, and many of the times I've seen it has been in use of ideas that we need to focus MORE on resilience then cybersecurity, or that cyber resilience is the next step beyond cybersecurity.

Here are some of the articles I read:  one, two, three.

I have a lot of problems with this idea.  This lead me to do research on the topic and I developed a presentation which I've given twice, most recently at the 2017 ISSA International Conference.  Below you'll find my research.

Now, this is not to say I'm not in agreement with the idea of cyber resilience.  What I have a problem is that its separate from or a next step from cybersecurity.  If people think this, I think they don't understand what cybersecurity SHOULD be.

Sunday, October 15, 2017

2017 ISSA International Conference Report

This past week, ISSA held their 2017 International Conference in San Diego.  I've attended the last 4 conferences (not sure when they started doing them), and this was one pretty good.  Full disclosure: I am a member of the conference steering committee, so had some involvement in the planning of it.

On the 9th was the all day Chapter Leaders Summit, which brings chapter leaders around the country (and world) to a day of training and sharing of information.  A change this year was the Summit was live streamed to those who couldn't attend.  I thought this was a good summit, with some good sessions.  I think attendance was pretty decent as well.  My chapter, the South Florida Chapter, had 4 officers in attendance.

Thursday, October 12, 2017

2017 ISSA International Conference

Well, I just returned from the 2017 ISSA International Conference which was held Oct 9-11 in San Diego.  This was the 4th conference I attended.  I have been on the conference steering committee the last couple of times, and this time spoke on cyber resilience.

I'll be posting more on the conference shortly, as well as a posting on my presentation to provide people with the references and resources I used in my presentation.  I hope to get this all up by this weekend.

The 2018 Conference will be in Atlanta, but uncertain about the date. 


Monday, September 18, 2017

"Hacker Summer Camp" 2017

This past July I went out to Las Vegas for the first to attend some of the events referred to as "hacker summer camp": Black Hat, BSides, and Defcon.

Now, I did not attend Black Hat as the event was pretty expensive.  I did want to drop by the exhibit hall, but couldn't get in.  I did attend the ISSA and ISC(2) receptions tied to the event.  I was a little disappointed that ISACA made a big deal about being at Black Hat but didn't do a reception of some kind.

I mainly came to attend BSides and Defcon and stayed at the Tuscany Suites where BSides was being held, which I recommend.  This guaranteed you a ticket for BSides.  I also got the meal ticket deal (breakfast & lunch) at BSides, which made me a sponsor and got me earlier checking at the sponsor table.  I also pre-ordered a t-shirt (recommended).

There were a lot of interesting sessions I attended.  I'll need to do another posting on some of the sessions I went thru and give more info on them.

Once BSides was over I attended Defcon.  This event was a bit overwhelming.  There was a big line for the trading post (cash only!), and I mainly wanted to get a t-shirt.  I was a little disappointed that the badge this year was a rubber badge, not an electronic one.  But many others had their own badge and I got a few.

Defcon is almost a collection of conferences.  There are main Defcon sessions, which are in HUGE rooms, four at a time.  Then there are a half dozen or so "villages" which have activities and their own sessions.  Skytalks was a good one, but there are villages for privacy & crypto, car hacking, IoT, and many others.  There was also a vendor area (but not open the first day).  There were many interesting vendors.  One I had met at BSides is HackerBoxes

As I noted, a lot of groups, including some of the villages, had their own electronic badges.  I really wanted a few, but they were cash only.  I didn't consider that and didn't bring a lot of cash with me.  And using ATMs was expensive.  So next time I will bring a lot more cash. 

I did some fun things, like solider a small badge at the Hardware Hacking Village (wasn't their big electronic badge they had, missed out on that).  Had some interesting conversations with several people. Met a few interesting people and groups.

Not sure if I'll go back next year or when I'll go back.  I would probably want to submit some talk proposals to BSides (I had thought of doing some this year, but wasn't certain if any I do would get accepted, but after seeing the sessions I should have submitted some).  I would again get a room at the Tuscany and had debated getting one just in case I decided to go.  Just don't know at this point.

I'll post some pics soon.