John Abella
Richard Aldrich
Rebecca Bace
Chris Blask
Eric Cole
Josh Corman
Paul De Graaf
Rocky DeStefano
Brandon Dunlap
Allen Harper
Christofer Hoff
Matthew Keogler
Peter Kuper

David Meunier
Elizabeth A. Nichols, Ph.D.
Angela Orebaugh
Ray Potter
Marcus Ranum
David Rice
Ron Ritchey
Randy V. Sabett
Nick Selby
Glen Sharlun
Aaron Turner
Stephen Windsor


John Abella
Industry Experience: Mr. Abella has over 10 years of experience in IT with a recent focus on security auditing, policy development, and incident handling. He was interviewed as part of the SANS “What Works” series of webcasts, and has participated as a SANS Mentor at Rutgers University. He has given a number of talks on Regulatory Compliance, Enterprise Defense, PCI Auditing and Compliance, and is also a member of the New Jersey Infragard.

Expertise: • Network security • Log management • PCI compliance

http://www.abella.net


Richard Aldrich
Industry Experience: Mr. Aldrich has been awarded several grants by the Institute for National Security Studies to study the legal and policy implications of cybercrime and information warfare. He served as the Deputy Staff Judge Advocate for the Air Force Office of Special Investigations, specializing in the cybercrime and information operations portfolios. He was a co-author of DoD’s award-winning CyberLaw 1 and CyberLaw 2 computer-based training.

Expertise: • Cybercrime • Information warfare • Network defense


Rebecca Bace
Industry Experience: Ms. Bace led the Computer Misuse and Anomaly Detection research program at the National Security Agency, where she instigated early research in intrusion detection and related technology. She is a noted author on topics in intrusion detection and network security, and recently co-authored A Guide to Forensic Testimony: The Art and Practice of Presenting Testimony As An Expert Technical Witness.

Expertise: • Intrusion detection • Network security • Network IDS • Network operations


Chris Blask
Industry Experience: Mr. Blask’s 15 years of experience have spanned several successful startups as well as Cisco Systems. He conceived the BorderWare Firewall Server, one of the first commercial firewall products, and served as that company’s VP of Marketing and Business Development. He was a member of the founding team of Protego Networks, filling marketing, sales, and business development roles. He was also Firewall Product Line Manager at Cisco Systems.

Expertise: • Critical infrastructure/government • Data leakage • Engineering and marketing information technologies • Firewalls • Log management • Management issues • Network architecture • Network operations • PCI compliance • Risk management • Security awareness • SIM/SIEM


Eric Cole
Industry Experience: Dr. Cole has over a decade of experience in information technology and is the author of several books including Hackers Beware, Hiding in Plain Site, Network Security Bible, and Insider Threat. He is the holder of over 20 patents and is a researcher, writer, and speaker for SANS Institute. He is an advisor to Cyberwatch and Purdue University CERIAS, and is a Lockheed Martin Fellow.

Expertise: • Application security • Critical infrastructure/government • Data leakage • Encryption • Insider threat • Intrusion detection systems • Mobile security • Network access control • Network architecture • Network operations • PCI compliance • Penetration testing • Perimeter defense • Secure network design • Vulnerability discovery • Vulnerability management


Josh Corman
Industry Experience: Mr. Corman has more than ten years of experience in security and networking software development, and is currently leading an industry charge to evolve defenses against the latest generations and innovations of malicious code. He has been Product Manager at vCIS Technology, Inc., worked with the SPECTRUM network management platform for Cabletron Systems, and served as QA manager and design specialist for Computer-Human Interactions.

Expertise: • Host protection solutions • Information protection • Network security • Virtualization • Threat management • Insider threat


Paul De Graaf
Industry Experience: Mr. De Graaff has extensive experience in information technology, with a distinct specialty in information security. He led the IT Security effort at Depository Trust & Clearing Corporation (DTCC) for a number of years. He is a sought-after speaker and panelist on a variety of information security areas.

Expertise: • Management of security • Risk management • IAM/identification • Data leakage • Policy


Rocky DeStefano
Industry Experience: Mr. DeStefano has over fifteen years of experience in information security and holds several industry certifications. He has been an intelligence analyst for the US Air Force, worked on the Air Force Computer Emergency Response Team (AFCERT), founded and managed a global security operations center at EDS, and managed a global team of security consultants at ArcSight.

Expertise: • Incident management • Network operations • Security management • Log management • SIM/SIEM

Link to http://blog.decurity.com/index.php/dec_template/C5


Brandon Dunlap
Industry Experience: Mr. Dunlap has over 13 years of experience managing business technology risk. He was a Senior Project Manager at a large security products company and led the Information Protection Unit of a Fortune 200 energy company. Serving in roles across a variety of highly regulated industries, he has successfully led all aspects of IT security programs: policies and procedures, oversight and controls, strategy, architecture development, and training.

Expertise: • Business technology risk • Compliance and regulations • Configuration management • IAM/Authentication • IT security programs • Management of security • Messaging security • Network access control • Patch management • Security awareness • Policy • Vulnerability management


Allen Harper
Industry Experience: Mr. Harper has 17 years of IT experience and 10 years of information security experience with the Marine Corps. He has also taught penetration testing for the Navy and has worked in his spare time as a Security Analyst for the IRS. He has a BS in Computer Engineering from North Carolina State and an MS in Computer Science from the Naval Post Graduate School. He is a co-author of Gray Hat: the Ethical Hackers Handbook.

Expertise: • Critical infrastructure/government • PCI compliance


Christofer Hoff
Industry Experience: Mr. Hoff served as Crossbeam Systems’ chief security strategist and was CISO and Directory of Enterprise Security Services for WesCorp. He also founded and served as CTO of a national security consulting company that provided services to Fortune 500 and service provider customers. He holds several security credentials – including CISSP, CISA, CISM, and IAM – and is an accomplished and accredited technical instructor.

Expertise: • Innovation in information assurance • Resilience • Rational risk management • Data leakage • Virtualization • Network security • Network architecture • Network operations

Link to http://rationalsecurity.typepad.com/


Matthew Keogler
Industry Experience: Mr. Keogler has over 10 years experience in information technology. He has been nominated for several Information Security awards, has conducted a SANS What Works webinar, and has been a SANS mentor since 2001. He served as Senior Security and Network Engineer for AutoTrader.com, and also led the team that built the company's network and provided help with the system architecture.

Expertise: • Perimeter defense • Wireless defense • Intrusion detection • Application assessments • Database assessments • Proactive security practices • Application security


Peter Kuper
Industry Experience: Mr. Kuper has been covering the software industry for over a decade. He was the lead software analyst at Morgan Stanley where he wrote a number of industry-defining reports and market-moving stock calls. Previously, he was a director and equity analyst at SG Cowen, where he covered the software sector with a particular focus on security. He has also been an equity analyst and vice president at FAC/Equities and a research analyst at Keefe, Bruyette & Woods.

Expertise: • Information security • Content management • Data leakage


David Meunier
Industry Experience: Mr. Meunier’s career has spanned various roles in the financial, insurance, healthcare, and manufacturing industries. He was the Vice President/CISO for CUNA Mutual Group and its affiliates, and also served as Senior IT/Global Acquisitions Security Manager at GE Healthcare. He has authored whitepapers and articles on Information Risk Management & Security, is Six Sigma Green Belt certified, and is a guest lecturer at UW Madison.

Expertise: • Risk management • IAM/Authentication • Compliance and regulations • Standards • Metrics • Policy


Elizabeth A. Nichols, Ph.D.
Industry Experience: Dr. Nichols has founded multiple software companies. Digital Analysis Corporation (DAC) implemented network and systems management software. ClearPoint Metrics was the first company dedicated to implementing software products for security metrics. She is author of five textbooks on microprocessor programming and interfacing as well as numerous articles in both the trade press and academic journals.

Expertise: • Industrial process control • Enterprise systems • Network management • Security metrics


Angela Orebaugh
Industry Experience: Ms. Orebaugh has 15 years of hands-on experiences within industry, academia, and government. She is an adjunct professor at George Mason University, where she performs research and teaching in intrusion detection and forensics. She is the author of Nmap in the Enterprise, Wireshark and Ethereal Network Protocol Analyzer Toolkit, and Ethereal Packet Sniffing, as well as co-author of several other texts.

Expertise: • Assurance strategy and management • Intrusion detection and prevention • Data mining • Attacker profiling • Network forensics


Ray Potter
Industry Experience: Mr. Potter is the former Manager of the Security Assurance Program at Cisco Systems, where he was responsible for the direction and strategy of Cisco’s global security certification and assurance initiatives. Prior to that, Mr. Potter was a consultant with a global management consulting firm, assisting Fortune 500 companies and government agencies to implement IT solutions and process improvement initiatives.

Expertise: • Software development assurance • Security operations management • Facilitation of public policy and end-user education • Critical infrastructure/government • Encryption • Compliance • Management issues • Risk management

Link to http://www.apexassurance.com/blog/


Marcus Ranum
Industry Experience: Mr. Ranum has been consistently recognized as one of computer security’s innovators and creative thinkers. Since 1989 he has held every position that is possible within a high-tech business – from junior system administrator and software engineer to CEO, CTO, and marketing director. He is the principal author of several major Internet security products, including firewalls, VPNs, and intrusion detection systems.

Expertise: • Intrusion detection • Virtual private networks • Firewalls • Data leakage • Host IDS • Network architecture • Network IDS • Application security • Log management • Vulnerability management

http://www.ranum.com/security/computer_security/


David Rice
Industry Experience: For a decade, Mr. Rice has advised, counseled, and defended global IT networks for government and private industry. David has been awarded by the U.S. Department of Defense for "significant contributions" advancing security of critical national infrastructure and global networks. He is author of Geekonomics: The Real Cost of Insecure Software.

Expertise: • Identity and access management • Software security • Management issues


Ron Ritchey
Industry Experience: Dr. Ritchey has over 20 years experience working within the IT industry. He is an active researcher in the IA field and is widely published on network security topics including co-authoring the well-regarded book Inside Network Perimeter Security. He has authored courses on computer security that have been taught across the country and is a faculty member of the SANS Institute, the Institute for Applied Network Security, and George Mason University (GMU).

Expertise: • Application security • IAM/Authentication • Encryption • Messaging security • Network architecture • Network IDS • Wireless security • Log management • Insider threat • Patch management • Vulnerability management • Compliance and regulations • Awareness


Randy V. Sabett
Industry Experience: As co-chair of the Information Security Committee of the Section of Science and Technology of the American Bar Association, Mr. Sabett edited for Information Security: A Legal, Business, and Technical Handbook and The Digital Signature Guidelines. He was also Co-Rapporteur for the PKI Assessment Guidelines and author of several other publications. Admitted to practice before the USPTO, he is a member of the Maryland, Virginia, and D.C. bars. He is also part of the Commission on Cyber Security for the 44th Presidency.

Expertise: Compliance and regulations • Data classification • eDiscovery • PCI compliance • Risk management • IT licensing


Nick Selby
Industry Experience: Mr. Selby has worked as an IT security consultant to small and midsized firms subject to regulatory compliance and strict confidentiality, and covered emerging technologies such as open source, wireless, and software piracy when based in Eastern Europe and Europe. He was Editor at Large for Amsterdam-based Tornado Insider/Tornado Investor, and reported for the International Herald Tribune. He is also an avid Linux hacker and a PHP/MySQL enthusiast.

Expertise: Data classification • Data leakage • Information protection

href="http://nickselby.com/yak/"


Glen Sharlun
Industry Experience: Mr. Sharlun’s career has included founding an advanced intrusion and deception lab at a DoD Research Center, leading the Marine Corps’ global monitoring and emergency response team, and being a lead investigator of a DoD IT outsourcing program. He has also been responsible for all defensive network operations, budgeting, and acquisition for a global and mobile DoD enterprise.

Expertise: Critical infrastructure/government • Data leakage • Log management • Network architecture • SIM/SIEM • Data classification • Management of security • Incident management • Network operations • Risk management


Aaron Turner
Industry Experience: Before joining INL as the Cybersecurity Strategist for the National & Homeland Security division, Mr. Turner worked in several of Microsoft’s security divisions. He was also the Security Readiness Manager for Microsoft’s Sales, Marketing, and Services Group where he led the development of information security curriculum. He has designed security solutions and responded to incidents in more than 25 countries around the world.

Expertise: Information protection • Intellectual property protection • Critical infrastructure/government • Encryption • Host IDS • Network architecture • Network IDS • Data classification • Mobile security • Wireless security • Threat management


Stephen Windsor
Industry Experience: Mr. Windsor previously managed the forensics training at the Department of Defense’s Cyber Investigations Training Academy, where he led a team of instructors that developed and delivered incident response and digital forensics training. He is currently an adjunct professor at a university in Baltimore, MD, where he develops and teaches incident response and digital forensics courses at the graduate level.

Expertise: Incident management • Threat management • Insider threat • Forensic analysis