Conference Schedule
Thursday, October 22
Morning
| 8:00 AM – 9:00 AM |
|---|
| Blue Ridge Foyer Registration in Main Lobby & Breakfast in Shenandoah Foyer, with Seating in Shenandoah A & B for meals Registration |
| 8:00 AM – 5:00 PM |
|---|
| Expo Area & Board Room Sponsor Exhibit Areas (closed for lunch 11:15 AM – 11:45 AM), Break Refreshments Expo Area |
| 9:00 AM – 5:00 PM |
|---|
| Blue Ridge Room (near/behind registration) Lock Pick Village – Sponsored by ROTAS Lock Pick Village |
| 9:00 AM – 10:00 AM |
|---|
| Shenandoah A & B Keynote Keynote |
| 10:00 AM – 10:15 AM |
|---|
| Expo Area & Board Room Sponsor Expo Break – Meet & Greet Break for All |
| 10:15 AM – 11:15 AM |
|---|
Shenandoah A & BOperationalizing IT Risk Managment at VA Tech, select to show or hide session detailsTrack: GRC Presenter(s): Mary Stewart Wimmer & Jen Ambelang, VA Tech Many institutions have an IT risk assessment standard, but turning that document into a repeatable, operational process is often the real challenge. This presentation shares Virginia Tech’s experience implementing its IT Risk Assessment Standard, including the successes, the obstacles, and the lessons learned along the way. Starting with no formal assessment process or standardized reporting, Virginia Tech built a consistent, risk-based approach for identifying, evaluating, and managing IT risk across the institution. We’ll discuss how this effort has improved collaboration with system owners, helped prioritize limited security resources, and established a foundation for risk-informed decision making. Attendees will also get an early look at Virginia Tech’s next step: developing a centralized enterprise risk register using Isora to track risks, remediation efforts, ownership, and risk mitigation over time. Whether you’re building a new risk management program or looking to mature an existing one, this session offers practical insights into translating policy into an operational risk management program. |
Shenandoah CVulnerability Management is Over, select to show or hide session detailsTrack: Technical Presenter(s): Bobby Burton, Radford A paranoid security guy responds to the changes to the NVD and current events and predicts the future…maybe |
Appalachian A & BAI Agency in Automation: Will we lose our jobs?, select to show or hide session detailsTrack: Topic Specific Presenter(s): Dan Han, VCU The continued rapid advancement of AI has brought forth the agentic promise from 2025 into reality. This talk examines how harness and model relationships function and how they can be used to augment information security work. The talk will also explore the fear many people have, which is “Am I going to be replaced by AI”, and the presenter will share his take on this topic and where we could go next. |
Appalachian CTBD: DLP – VCU’s Journety into DLP, select to show or hide session detailsTrack: Topic Specific Presenter(s): Jessi Castellani, VCU TBD: VCU will share their journey into DLP. VCU recently started to use a DLP solution. We’ll discuss our reasons for deploying DLP, our DLP approach, initial hurdles, and lessons learned at the early stages of DLP deployment. |
Allegheny B & CIAM: The Odd One Out, select to show or hide session detailsTrack: Topic Specific Presenter(s): Gabor Eszes & Kate Rhodes, ODU Identity and Access Management (IAM) sits at the center of every Zero Trust architecture and every mature security program, yet it doesn’t have a dedicated track at VASCAN. This Birds-of-a-Feather session exists to test whether that should change. The topics IAM touches are broad and growing: the lifecycle of accounts and access, authentication assurance, anomaly detection, governance of non-human and delegated actors, and more. Right now, these topics surface scattered across unrelated sessions, with no consistent home from year to year. Join us and let’s explore if there’s enough shared interest to build a dedicated IAM track at VASCAN. We’ll open with a short framing of why IAM would benefit from this approach, then turn the floor over to attendees to share lessons and open questions about IAM-adjacent efforts, and how we could work together to advance our collaboration in this space…If you’ve felt IAM get shortchanged at security conferences, this is the session to turn that around into something concrete. |
| 11:15 AM – 11:30 AM |
|---|
| Expo Area & Board Room Sponsor Meet & Greet with Snacks Break for All |
| 11:30 AM – 12:30 PM |
|---|
Shenandoah A & BYou Can’t Do It All: Building a cyber strategy roadmap as a team sport, select to show or hide session detailsTrack: GRC Presenter(s): Kate Rhodes, Luke Watson, Ryan Orren & Jon Kline, ODU Like most higher ed security programs, ours faces a familiar tension: growing regulatory obligations, an expanding attack surface, and a roadmap of good ideas (and audits) that will always outpace the team’s capacity to execute them. This session tells the story of how our security leadership team turned an independent gap assessment, audit findings, and the want to mature, into a living, prioritized roadmap, and how we’ve kept it alive since. We’ll walk through our decision to move the program’s foundational framework from a generic ISO/IEC 27001 control model to NIST Cybersecurity Framework (CSF) 2.0, aligned with Zero Trust principles, and why that shift mattered for a higher-education environment supporting research, clinical, and academic missions simultaneously. We’ll show how our annual gap assessment and audit findings translate directly into roadmap priorities and be candid about the harder part: deciding what doesn’t make the cut this year, and why. The heart of this session is the “how,” not just the “what.” Our roadmap isn’t built or maintained by one person, it’s a standing collaboration between the CISO, Deputy CISO, Security Architect, and functional leads across Security Engineering, Security Operations, GRC, and Identity & Access Management. We’ll share the actual cadence and mechanics of how this team reviews progress, resolves competing priorities, and reshuffles the roadmap when the organization’s needs shift, including what’s worked, what hasn’t, and what we’d do differently. Attendees will leave with a practical, adaptable model for translating a framework transition and gap assessment into a roadmap their own leadership team can sustain, or at least understand ours, and not just a plan that looks good in a single presentation to leadership, but one built to survive contact with real institutional constraints. |
Shenandoah CThe Expanding Attack Surface: What Higher Education Must Know to Stay Ahead, select to show or hide session detailsTrack: Vendor Presenter(s): Nate Parks & Tom Andriola, Dynatrace Higher education institutions are facing unprecedented pressure. Budget constraints, staffing shortages, growing cybersecurity risks, increasing expectations for digital services, and the rapid adoption of AI are forcing IT organizations to rethink how they operate. For decades, campus IT organizations have relied on highly skilled personnel to manually monitor systems, investigate incidents, manage service tickets, and resolve performance issues. This model is becoming increasingly difficult to sustain as technology environments grow more complex and institutional resources remain constrained. This session explores how universities are leveraging modern observability platforms, integrated with IT Service Management (ITSM) processes, to transform IT operations from reactive and human-intensive workflows into intelligent, automated service delivery models. Real-world examples will illustrate how institutions can improve service reliability, accelerate incident response, strengthen cybersecurity operations, and increase operational efficiency while working within limited budgets and staffing levels. Participants will leave with a practical framework for evolving from traditional monitoring and ticket-driven operations toward intelligent, autonomous campus IT environments that improve user experiences while maximizing institutional resources. Key Discussion Topics
|
Appalachian A & BSupercharging GRC with Generative AI: Lessons, Pitfalls & Breakthroughs, select to show or hide session detailsTrack: GRC Presenter(s): Joshua Cole, Assura How can generative AI transform a governance, risk, and compliance (GRC) program? This session shares Assura’s journey of integrating generative AI into our GRC program, a transformation that facilitates continuous compliance monitoring, allows us to speed up recurring tasks, and improves visibility and outcomes. Attendees will learn real-world lessons and pitfalls from our experience, including the cultural shift and skill retooling required with this approach, without replacing human expertise. |
Appalachian CJMU’s DMARC Journey, select to show or hide session detailsTrack: Topic Specific Presenter(s): Elizabeth Martens & Joel Smith, JMU This presentation will walk through the process we took to achieve DMARC compliance, including our experiences with discovering all senders, communicating with campus, configuring SPF, and continued monitoring. JMU is currently averaging 99% compliance for Fac/Staff email. |
Allegheny B & CBuilding GRC with Eramba: Our Journery So Far, select to show or hide session detailsTrack: GRC Presenter(s): Rebecca Browder & Mayura Patel, VCU “Building GRC with Eramba: Our Journey So Far” provides an overview of our transition from manual governance processes to a centralized GRC platform, driven by the need for better risk visibility and compliance tracking. The session explores why we chose Eramba and how we implemented its core modules for risk, compliance, and policy management, and how we leverage its API for automation and integration with existing workflows. We’ll also discuss our ongoing effort to build an enterprise risk register in Eramba. Attendees will gain practical insights into implementing Eramba, including the decisions we made, the lessons we’ve learned so far, and where we plan to go next. |
Afternoon
| 12:30 PM – 1:15 PM |
|---|
| Shenandoah A & B LUNCH & Founder’s Award Presentation Lunch |
| 1:15 PM – 2:15 PM |
|---|
Shenandoah A & BFrom Visibility to Action: Using Cybersecurity Metrics to Improve Security Outcomes, select to show or hide session detailsTrack: GRC Presenter(s): Brad Sanford, UVA Cybersecurity is a shared responsibility, but organizations cannot improve what they cannot measure. This session will explore how the University of Virginia developed an enterprise security scorecard that uses objective data to provide consistent visibility into device security risk across a complex, decentralized institution. UVA’s experience illustrates how carefully selected metrics can establish a baseline, reveal strengths and opportunities, support more productive conversations, and inform decisions about cyber risk remediation, operational priorities, and resource investment. The session will also offer practical guidance for organizations interested in developing their own scorecards, including how to select meaningful measures, build confidence in the underlying data, avoid common pitfalls, and present results in a way that encourages accountability, celebrates progress, and helps build a culture of continuous improvement. |
Shenandoah CVirginia’s SLCGP: Assessment-Driven Tool Deployment for Covered Entities, select to show or hide session detailsTrack: Topic Specific Presenter(s): Matthew Umphlet, VITA The Virginia State and Local Cybersecurity Grant Program is focused on translating capabilities assessment data into action. This presentation will explore how Virginia is using capabilities assessment results to prioritize and deploy cybersecurity tools and solutions for in-scope entities. Attendees will gain insight into Virginia’s decision-making approach, implementation strategy, and the practical lessons shaping this more targeted and data-driven phase of the program. |
Appalachian A & BGhost Accounts: How financial aid can become initial access, select to show or hide session detailsTrack: Topic Specific Presenter(s): Daevon Rascoe & Michael Forster, Regent Every semester, universities create thousands of new student accounts before a single identity has been verified, or a single tuition dollar has been paid. Financial aid fraud is often viewed as the business office’s problem, a matter of compliance and audit trails rather than cybersecurity. Yet every fraudulent enrollment also creates a fully credentialed identity inside the university’s environment. It is initial access hiding in plain sight, disguised as routine student onboarding. This session explores the rise of “ghost students,” fraudulently or loosely verified enrollments that exist only long enough to collect financial aid. While financial loss often receives the most attention, the security implications are frequently overlooked. But what happens when the objective changes? A credential that was originally created to commit financial fraud can quickly become a trusted identity for phishing, persistence, or other forms of unauthorized access. Each ghost student is issued the same trusted identity as a legitimate student, complete with university email, single sign-on, learning management system access, and other institutional resources. Attendees will learn how financial aid fraud can become an initial access vector, what a typical student’s access looks like on day one, how attackers can abuse that trust at scale, and how defenders can identify suspicious enrollment activity before financial fraud becomes a cybersecurity incident. |
Allegheny AModern Data Security in an AI World, select to show or hide session detailsTrack: Vendor Presenter(s): Joshua Linkenhoker, Proofpoint This presentation will review the key pillars of Modern Data Security and how to adapt them to protect organizations against the potential risks to Data posed by the use of AI in the workplace. Data Exfiltration Protection, Data Governance, and Insider Risk all evolve to incorporate new functionality as necessary to not only keep organizations safe in an AI world but also leverage AI capabilities to enhance the defensive posture of the organization. |
| 2:15 PM – 2:30 PM |
|---|
| Expo Area & Board Room Expo Break Break for All |
| 2:30 PM – 3:30 PM |
|---|
Shenandoah A & BSpoof Proofing: Understanding SPF, DKIM and DMARC, select to show or hide session detailsTrack: Technical Presenter(s): Brannon Murphy & Michael Forster, Regent Email domain spoofing is a form of cyberattack where a threat actor impersonates an organization to perform social engineering. For higher education institutions, this style of attack remains a huge problem. Ben Rogers of Allure Security (2026) found that 79% of higher-education institutions in the UK report being impersonated by unauthorized parties, while businesses sat at 28%. Domain spoofing presents a massive reputational, financial, and technical risk to both universities and regular users. Threat actors use the reputation of your organization to make phishing emails more convincing, leading to an increase in successful phishing attacks. The victims of these attacks might not realize your university was spoofed, leading to blame and reduced confidence in your university to keep students safe from phishing attacks. On the other side, your students receiving phishing emails from spoofed organizations can lead to account compromises, financial transactions to the wrong people, and even data breaches. Domain-based Message Authentication, Reporting, and Conformance (DMARC) is a solution to help mitigate domain spoofing. DMARC is a protocol that allows organizations to define what happens to emails if they fail authentication, including quarantining and rejecting them. Unfortunately, DMARC adoption across the board is not in a good spot. According to Meysam Azad (2026), only 30.4% of around 5.5 million domains have implemented DMARC; of those, only 42% of them enforce policies (quarantine or reject) that act against potential spoofing emails. The DMARC implementation problem is particularly prominent in higher-education institutions. In 2025, Dmarcian reported that 77% of parent domains in the top 500 higher-education institutions in the US are not protected from domain spoofing due to malformed, non-existent, or unenforced DMARC records. In this presentation, I hope to help other IT professionals in the higher-education industry understand DMARC and its components, showcase the business risks that can be reduced and/or mitigated with its adoption, and provide a methodology that can be used to adopt it. Our university, Regent University, adopted a p=reject DMARC policy for our domain and a sister organization, and have seen considerable positive impact in both. Implementing DMARC has made such a huge impact for us, and I hope to help other universities begin their journey to realize these benefits as well. |
Shenandoah CLiving Off Legitimate Tools: How Phishing is Evading Detection in Higher Education, select to show or hide session detailsTrack: Technical Presenter(s): Serenity Smile, UVA Phishing hasn’t gone away — it’s gotten quieter. At the University of Virginia’s Security Operations Center, we’re seeing attackers increasingly abandon obvious red flags in favor of infrastructure that looks, and often is, completely legitimate. This session walks through real, de-identified case studies from our SOC illustrating this shift:
We’ll also cover the compounding damage cycle we’ve observed: even after a compromised account is disabled, malware on the endpoint can capture the new password, allowing attackers to regain access and continue their campaign. In our most serious cases, attackers have used stolen credentials to redirect victims’ direct deposit to attacker-controlled debit cards, resulting in thousands of dollars in losses — sometimes unrecoverable. A key focus of the talk is why these lures work: emails spoofed or sent from genuinely compromised internal accounts, including colleagues and supervisors, and abuse of trusted third-party platform notifications exploit institutional and platform trust in ways external phishing never could. We’ll also examine a notable case involving fake birthday invitations used to specifically target VIPs and executives with malware downloads — showing how attackers tailor social engineering to their target’s role and social context. Attendees will leave with concrete detection strategies for phishing that uses legitimate SaaS, communication, and remote access infrastructure, practical guidance for incident response when “disable the account” isn’t enough, and talking points for user awareness training that address why these attacks succeed — not just what to look for. |
Appalachian A & BInvisible Until You Need It: The Rise of Self-Healing Endpoints Description, select to show or hide session detailsTrack: Vendor Presenter(s): Eric Ellis, Lenovo The best security technologies often work silently in the background. Explore how self-healing capabilities, persistent endpoint connections, and automated recovery mechanisms help organizations recover from attacks faster while reducing operational burden on IT teams. Real-world examples illustrate why resilience is becoming just as important as prevention. |
Appalachian CFrom Pilot to Program: One Year of the Student SOC, Growth, Impact and What’s Next, select to show or hide session detailsTrack: Topic Specific Presenter(s): Luke Watson & Jonathan Morales, ODU A year ago, we introduced Old Dominion University’s student Security Operations Center, a partnership between the University Information Security Office and the School of Cybersecurity built to give students real operational experience while strengthening the university’s security posture. This session picks up where that story left off. We’ll share how the program has matured from an internship into a structured academic pathway, the results that have followed, from student outcomes to growing demand to greater visibility across the university, and how one of our own students now leads the team as our Lead Student SOC Analyst and co-presenter. We’ll close with where the program is headed for Fall 2027, including plans to grow the cohort, onboard students continuously, and introduce specialization tracks. Attendees will leave with a practical, field-tested model for turning a pilot SOC into a lasting academic program. |
Allegheny AModernizing SecOps to Counter AI-Driven Threats with AI and Automation, select to show or hide session detailsTrack: Vendor Presenter(s): Trevor Stuart, Palo Alto Networks Adversaries are utilizing frontier AI to execute hyper-automated, machine-speed attacks. To keep pace, security operations must evolve. Join Palo Alto Networks to explore how an AI-driven, automation-first approach transforms SOC performance—empowering teams to counter complex AI threats with real-time autonomous defense.. |
| 3:30 PM – 3:45 PM |
|---|
| Expo Area & Board Room Expo Break Break for All |
| 3:45 PM – 4:45 PM |
|---|
Shenandoah A & BSecurity Analysis Lead, select to show or hide session detailsTrack: GRC Presenter(s): Dan Crompton & James Squire, Liberty Never Waste a Crisis: Implementing Email Security During an Active Phishing Campaign. We had planned a thoughtful, tested, and deliberate roll-out of a new email security solution from Check Point to help us combat phishing. A sudden and major phishing campaign forced Liberty University to change our approach and rapidly deploy enhanced email security on the fly. This session examines the technical, operational, and leadership challenges of making major security changes under pressure. Attendees will gain practical guidance on evaluating risk, obtaining stakeholder support, managing end-user expectations, and measuring success when time is limited and threats are immediate. Real-world lessons learned will help security and IT leaders prepare for similar situations at their own institutions. |
Shenandoah CEmail Security – JMU’s Implementation of Sublime, select to show or hide session detailsTrack: Technical Presenter(s): Elizabeth Martens, Joel Smith & Chris Lanier, JMU JMU implemented Sublime AI for email security in the Summer/Fall of 2026. This presentation will describe our reasons for pursuing a solution beyond that which was offered by M365, the vendor selection process, and our experience so far with the product. |
Appalachian A & BUnderstanding Cyber Resilience in the Context of Agentic AI, select to show or hide session detailsTrack: Technical Presenter(s): Paul Kinder, CDW Agentic AI is introducing new considerations for cybersecurity and risk management, influencing how organizations approach governance, security operations, and incident response. This presentation explores the potential impacts of autonomous and semi-autonomous AI systems on organizational resilience, including emerging risks, operational challenges, and evolving security practices. Attendees will gain an understanding of current trends, key considerations for oversight and preparedness, and approaches organizations are evaluating as they adapt existing cybersecurity programs to an increasingly AI-enabled environment. |
Appalachian CPhishing Without a License, select to show or hide session detailsTrack: Topic Specific Presenter(s): Ryan Nielson, VCU We built and deployed a self-hosted GoPhish platform to support internal phishing awareness and security training initiatives. The solution leveraged our own hosted infrastructure, custom domains managed through GoDaddy, and F5 load balancing to securely host landing pages and manage traffic. This approach provided greater control, flexibility, and alignment with our internal security goals. This presentation will walk through our technical stack as well as some of the challenges we faced along the way. |
Allegheny ADefending the Modern Inbox: A Smarter Approach to Email Security, select to show or hide session detailsPresenter(s): Travis Bertolino, Abnormal AI The widespread adoption of AI has boosted productivity across organizations, but it has also supercharged cybercriminals. Attackers can now craft highly convincing, large-scale email threats that are free of usual red flags. As a result, credential phishing and business email compromise (BEC) attacks are becoming more frequent, more sophisticated, and harder for humans to spot. In this session, you’ll learn how generative AI is reshaping the threat landscape and why humans alone can’t keep up with the speed of AI-driven attacks. We’ll explore how defensive AI can detect and stop malicious AI in real time, and you’ll leave with clear, practical actions to strengthen your defenses against AI-enabled email attacks. |
Evening
| 5:00 PM – 6:30 PM |
|---|
| Shenandoah A & B (seating) Welcome Dinner & Founder’s Award Dinner & Award |
Friday, October 23
Morning
| 8:00 AM – 9:00 AM |
|---|
| Blue Ridge Foyer Registration in Main Lobby & Breakfast in Shenandoah Foyer, with Seating in Shenandoah A & B for meals Registration |
| 8:00 AM – 2:00 PM |
|---|
| Expo Area & Board Room Sponsor Exhibit Areas (closed for lunch 11:15 AM – 11:45 AM), Break Refreshments Expo |
| 9:00 AM – 5:00 PM |
|---|
| Shenandoah A & B Training (will have same breaks & lunch) Training Registration Required |
| 9:00 AM – 10:00 AM |
|---|
Shenandoah CThe Moving Target: Our Journey to CMMC Through Shifting Standards, Staff and Accessors, select to show or hide session detailsTrack: GRC Presenter(s): EJ Corpus & Brandon Freshcorn, ODU Supporting research that involves Controlled Unclassified Information (CUI) requires more than implementing technical security controls. It requires a coordinated program that brings together people, processes, technology, research needs, and compliance responsibilities. This session will provide an overview of our secure research program and the Regulated Research Computational Environment (RRCE), including how the environment supports researchers working with sensitive and regulated data. We will discuss the teams and organizational roles involved in operating the environment and how collaboration between cybersecurity, information technology, research administration, leadership, and researchers helped move the program forward. We will also share how we used project planning to organize security and compliance activities, assign responsibilities, track documentation and remediation efforts, and maintain progress as CMMC requirements, timelines, and guidance continued to change. Rather than focusing on a single standard or revision, the session will highlight how structured planning and clearly defined roles can help an organization adapt to changing expectations. Finally, we will discuss our general approach to assessment readiness and working with a Certified Third-Party Assessment Organization (C3PAO), including preparing documentation, reviewing control implementations, identifying gaps, and determining when the organization is ready to proceed with an external assessment. Attendees will gain practical insight into developing a secure research environment, organizing a multidisciplinary team, managing compliance work through a project plan, and preparing for an external assessment in an evolving regulatory landscape. |
Appalachian A & BDid you read the EULA?, select to show or hide session detailsTrack: Topic Specfic Presenter(s): Randy Marchany, VA Tech Abstract: That customers must patch, monitor, segment, and defend a system does not erase the fact that the original security weakness was built into the product by the vendor. That observation is the starting point for this series. The SANS Top 10 Internet Threats (2000), SANS Top 10 Security Mistakes Individuals Make (2001), the OWASP Top 10 (2003) listed the top vulnerabilities for software. Yet. nine of the ten vulnerability classes identified in 2000, 2001, 2003 remain active causes of major breaches in 2026. Why haven’t they been addressed? This series documents why the answer is economic, not technical. Cybersecurity’s original sin is not insecure code. It is a single legal instrument, the End User License Agreement, that made insecure code economically acceptable by capturing the market in which accountability would otherwise have operated. By shifting from ‘the user doesn’t negotiate’ to ‘the user CANNOT negotiate,’ the EULA seized the liability standard, the remedy, and the alternative from every user simultaneously. From the 1990s that set up this environment. Even the Federal Government was not able to negotiate EULA terms. This talk reviews the court findings. This talk will show examples of attacks from 2007-2026 where the initial vector was one of those 10. We’ll also review specific clauses in a number of well known vendor EULAs and show some surprising elements in them. |
Appalachian CThat’s my token, I don’t know you!, select to show or hide session detailsTrack: Technical Presenter(s): Jared Karnes & Dean Johnson, VITA A deep dive into the process of threat actors utilizing phishing and token endpoint polling to steal Microsoft authentication tokens, which leads to unauthorized access and potential rogue device registration. |
Allegheny C & BThe Path to a Passwordless Campus, select to show or hide session detailsTrack: Vendor Presenter(s): Stuart E. Trafford, Ed.D & Jeremey Benedict, Okta Traditional passwords are a higher-ed liability, driving sophisticated phishing attacks and skyrocketing cyber-insurance premiums. This session delivers a practical framework for transitioning to a passwordless campus using modern, Identity and Access Management (IAM) strategies. We will explore how to balance frictionless student and faculty access with strict “zero-trust” security requirements. Drawing on lessons from a major university’s rollout to nearly 50,000 active monthly users, we will share hard-won strategies for overcoming cultural pushback, accessibility hurdles, and shared-device challenges. From FIDO2 to passkeys, learn how to build a security roadmap that eliminates the credential vulnerability. Learning Objectives:
|
| 10:00 AM – 10:15 AM |
|---|
| Expo Area & Board Room Sponsor Expo Break – Meet & Greet Break for All |
| 10:15 AM – 11:15 AM |
|---|
Shenandoah CThe Watcher of Birds & Viking Boy present an unforgettable cybersecurity experience unlike anything you’ve seen at a conference…, select to show or hide session detailsTrack: GRC Presenter(s): Beth Lancaster & Caeland Garner, VA Tech This isn’t another slide deck.It’s a live performance that blends original music, storytelling, real-world cyber threats, and practical security education into an immersive experience that keeps audiences engaged from beginning to end. Through original songs spanning electronic dance music, country, rock, and modern country-rap, attendees will experience the human side of cybersecurity—from phishing attacks and spam campaigns to zero-day vulnerabilities, ransomware, and the everyday decisions that protect organization. Each song introduces a cybersecurity concept before transitioning into live demonstrations, real attack stories, and actionable defensive strategies that security professionals, executives, and everyday users can immediately apply. Whether you’re a seasoned security practitioner or brand new to cybersecurity, you’ll leave entertained, inspired, and better prepared for the threats waiting beyond the firewall. Get ready for a presentation that feels less like a conference session and more like a live concert—where every beat teaches a lesson and every lyric strengthens cyber resilience. |
Appalachian A & BCirrus Identity SAML Bridge Implementation – JMU’s Story, select to show or hide session detailsTrack: Topic Specific Presenter(s): Mamata Biswal & V Kagey, JMU JMU implemented Okta in 2025 and used Cirrus Identity’s SAML Bridge to maintain access to InCommon federated and bilateral applications while retiring Shibboleth. The session covers implementation and testing strategy, redirecting authentication traffic, lessons learned, challenges, and outcomes. |
Appalachian CSmoke, Mirrors, and SPNs: The Art of Deception in Defensive Security, select to show or hide session detailsTrack: Technical Presenter(s): Trey Richardson & Daevon Rascoe, Regent Alerts can be overwhelming. Cyber deception offers high-fidelity alerting with a near-zero false positive rate. The result: frustrated attackers who think they’ve found an easy win, only to discover what they found is useless, or that they’ve stumbled into a trap that expels them from the environment. It buys defenders more time while causing attackers and penetration testers alike to waste theirs on unusable targets. This presentation covers the types of deception we use at Regent University: decoy accounts, honey credentials, Kerberoastable accounts with SPNs set as bait, and deceptive “admin” and super-user groups designed to alert on specific tool usage, along with the best practices we’ve discovered. We’ll share how we repurpose soon-to-be-decommissioned accounts as lures that blend into the environment, looking like any other account but existing solely to detect and contain threats. We’ll cover the automation we built to take action the moment a decoy trips, and close with success stories showing how these detections caught and contained real threat actors (and pentesters) early. |
Allegheny C & BThird-Party Risk Management in Practice: A Conversation with Regent University, select to show or hide session detailsTrack: Third Party Risk Management in Practice: A Conversation with Regent University Presenter(s): McKay Lasko, SaltyCloud & Mike Forster, Brannon Murphy, Regent Third-party risk is one of the most resource-intensive parts of any higher ed security program, yet institutions operationalize it very differently even within the same state. This session brings two members of Regent University’s information security team into a moderated conversation about how they run their third-party risk program, from the leadership level down to the day-to-day mechanics of reviewing vendors, scoring risk, and keeping an inventory current. The session is structured as a prepared Q&A: the moderator poses questions shared with panelists in advance, with a small number of screenshots used only when they help illustrate a specific workflow. The goal is for attendees managing third-party risk at their own institutions to leave with best practices they can borrow or adapt. |
| 11:15 AM – 11:30 AM |
|---|
| Expo Area & Board Room Expo Break Break for All |
| 11:30 AM – 12:30 PM |
|---|
Shenandoah CApplying CIS Benchmarks – JMU IT, select to show or hide session detailsTrack: GRC Presenter(s): Josh Dameron & Greg Hackbarth, JMU A group presentation from various team leads on planning for and applying CIS Benchmarks in AD/M365, servers, endpoints, and collaboration tools such as Zoom. |
Appalachian A & BNSU’s COP (Cloud Oversight Process), select to show or hide session detailsTrack: Topic Specific Presenter(s): Ron King & Chirag Dobariya, NSU As we all know, third-party risk management has become even more important. We will be sharing the audit friendly Cloud Oversight Process (COP) NSU has implemented to manage information security needs around third party and SaaS providers. |
Appalachian CUsing the SUPER script and Jamf Pro to manage OS updates and upgrades, select to show or hide session detailsTrack: Technical Presenter(s): Frank Pereira, JMU Demonstrate how JMU uses a modified version of the SUPER script with Jamf Pro policy to manage both our minor and major OS updates with a built-in deferral system to allow users flexibility on when to perform the updates. |
Allegheny C & BBeyond Detection: A Five-Step Exposure-to-Remediation Playbook, select to show or hide session detailsTrack: Technical Presenter(s): Sam Kinch & Joel Maxfield, Tanium What if the disclosure-to-exploit window suddenly collapses from days to hours? How prepared are you? How will you respond? What will be the impact to your organization… and more importantly, to the constituents, citizens, students/faculty, internal staff you support? In April 2026, Anthropic disclosed Project Glasswing — an AI agent that found thousands of zero-days and wrote working exploits 72 percent of the time. The CVE pipeline doubled between 2024 and 2025. A 30-day patch cycle is now a pre-AI artifact, and most public-sector IT shops are still running one. This session is for IT and Security Operations teams. We will walk through five practical areas — Identify, Patch, Update, Renew, and Enforce — that close the exposure-to-remediation loop and bring patch cadence inside the new disclosure-to-exploit window. During this session, you will see how to:
Attendees will walk away with a: |
Afternoon
| 12:30 PM – 1:45 PM |
|---|
| Shenandoah A & B (seating) LUNCH & Prizes – MUST Be Present To WIN! Lunch & Prizes |
| 1:45 PM – 2:45 PM |
|---|
Shenandoah CBridging the Gap: How Security Liaisons Advance Cybersecurity Governance, Risk and Compliance in Higher Education, select to show or hide session detailsTrack: GRC Presenter(s): James Baker & Stacy Sties, UVA Higher education institutions struggle to implement consistent cybersecurity across decentralized IT environments. The Information Security Liaison model places trusted advisors between central governance and departmental IT teams to improve communication, translate policy into actionable guidance, and strengthen compliance through partnership. |
Appalachian A & BJMU’s Passwordless Journey with Okta FastPass, select to show or hide session detailsTrack: Topic Specific Presenter(s): Jordan Leaman & William Case, JMU Following James Madison University’s implementation of Okta in 2025, JMU introduced Okta FastPass as an optional passwordless authenticator for students, faculty, and staff. While enabling the technology was relatively straightforward, JMU quickly discovered that a successful passwordless deployment required careful consideration of authenticator enrollment sequencing and authentication policy design. This session examines how JMU developed custom enrollment and authentication policies to ensure users established a portable authentication method before enrolling a device-bound FastPass credential, reducing account lockouts and computing support. Attendees will learn how JMU addressed security concerns with default FastPass authentication policies through the use of Okta’s Authentication Methods Chain, evaluated the risks and benefits of supporting passwordless authentication on personal devices, and drove adoption by emphasizing convenience and a simplified user experience rather than security-focused messaging. |
Appalachian CWhitebox Pentesting: Using “Kali w/ Vulnerable Know Targets” on the Cyber Range, select to show or hide session detailsTrack: Technical Presenter(s): Thomas “Tweeks” Weeks & Dominik Borkowski, VT/ Virginia Cyber Range In this demo-workshop, attendees get to power-up their skill-sets on Kali Linux! First you get to watch us compromise multiple, well known CVEs, from the safety of the Cyber Range’s cool, new “Kali w/vulnerable targets” VM environment. We then give you all the documentation and step by step directions that you need to use tools like netcat, nmap, and msfconsole (Metasploit) to do it all yourself! You’ll get a Cyber Range login to pop root shells on vulnerable telnetd (CVE-2026-24061), compromise a SambaCry file server (CVE-2017-7494), extract private RSA keys on a Heartbleed/web server (CVE-2014-0161), and more! Come to our demo you’ll get a 48 hour Cyber Range account in the cloud that you can use to then do it all yourself.. all while learning several powerful network scanning, enumeration and pentest tools in the process!/p> |
Allegheny C & BProgram Manager – Lessons Learned from REN-ISAC, select to show or hide session detailsTrack: Topic Specific Presenter(s): Kyle Enlow, REN-ISAC Lessons learned and common findings from a years worth of penetration test conducted by REN-ISAC penetration testing team. |