Conference Schedule

Thursday, October 22

Morning
Thursday, October 22 schedule from 8:00 AM to 9:00 AM
8:00 AM – 9:00 AM
Blue Ridge Foyer
Registration in Main Lobby & Breakfast in Shenandoah Foyer, with Seating in Shenandoah A & B for meals
Registration
Thursday, October 22 schedule from 8:00 AM to 5:00 PM
8:00 AM – 5:00 PM
Expo Area & Board Room
Sponsor Exhibit Areas (closed for lunch 11:15 AM – 11:45 AM), Break Refreshments
Expo Area
Thursday, October 22 schedule from 9:00 AM to 5:00 PM
9:00 AM – 5:00 PM
Blue Ridge Room (near/behind registration)
Lock Pick Village – Sponsored by ROTAS
Lock Pick Village
Thursday, October 22 schedule from 9:00 AM to 10:00 AM
9:00 AM – 10:00 AM
Shenandoah A & B
Keynote
Keynote
Thursday, October 22 schedule from 10:00 AM to 10:15 AM
10:00 AM – 10:15 AM
Expo Area & Board Room
Sponsor Expo Break – Meet & Greet
Break for All
Thursday, October 22 schedule from 10:15 AM to 11:15 AM
10:15 AM – 11:15 AM
Shenandoah A & B
Operationalizing IT Risk Managment at VA Tech, select to show or hide session details

Track: GRC

Presenter(s): Mary Stewart Wimmer & Jen Ambelang, VA Tech

Many institutions have an IT risk assessment standard, but turning that document into a repeatable, operational process is often the real challenge. This presentation shares Virginia Tech’s experience implementing its IT Risk Assessment Standard, including the successes, the obstacles, and the lessons learned along the way.

Starting with no formal assessment process or standardized reporting, Virginia Tech built a consistent, risk-based approach for identifying, evaluating, and managing IT risk across the institution. We’ll discuss how this effort has improved collaboration with system owners, helped prioritize limited security resources, and established a foundation for risk-informed decision making. Attendees will also get an early look at Virginia Tech’s next step: developing a centralized enterprise risk register using Isora to track risks, remediation efforts, ownership, and risk mitigation over time.

Whether you’re building a new risk management program or looking to mature an existing one, this session offers practical insights into translating policy into an operational risk management program.

Shenandoah C
Vulnerability Management is Over, select to show or hide session details

Track: Technical

Presenter(s): Bobby Burton, Radford

A paranoid security guy responds to the changes to the NVD and current events and predicts the future…maybe

Appalachian A & B
AI Agency in Automation: Will we lose our jobs?, select to show or hide session details

Track: Topic Specific

Presenter(s): Dan Han, VCU

The continued rapid advancement of AI has brought forth the agentic promise from 2025 into reality. This talk examines how harness and model relationships function and how they can be used to augment information security work. The talk will also explore the fear many people have, which is “Am I going to be replaced by AI”, and the presenter will share his take on this topic and where we could go next.

Appalachian C
TBD: DLP – VCU’s Journety into DLP, select to show or hide session details

Track: Topic Specific

Presenter(s): Jessi Castellani, VCU

TBD: VCU will share their journey into DLP. VCU recently started to use a DLP solution. We’ll discuss our reasons for deploying DLP, our DLP approach, initial hurdles, and lessons learned at the early stages of DLP deployment.

Allegheny B & C
IAM: The Odd One Out, select to show or hide session details

Track: Topic Specific

Presenter(s): Gabor Eszes & Kate Rhodes, ODU

Identity and Access Management (IAM) sits at the center of every Zero Trust architecture and every mature security program, yet it doesn’t have a dedicated track at VASCAN. This Birds-of-a-Feather session exists to test whether that should change. The topics IAM touches are broad and growing: the lifecycle of accounts and access, authentication assurance, anomaly detection, governance of non-human and delegated actors, and more. Right now, these topics surface scattered across unrelated sessions, with no consistent home from year to year. Join us and let’s explore if there’s enough shared interest to build a dedicated IAM track at VASCAN. We’ll open with a short framing of why IAM would benefit from this approach, then turn the floor over to attendees to share lessons and open questions about IAM-adjacent efforts, and how we could work together to advance our collaboration in this space…If you’ve felt IAM get shortchanged at security conferences, this is the session to turn that around into something concrete.

Thursday, October 22 schedule from 11:15 AM to 11:30 AM
11:15 AM – 11:30 AM
Expo Area & Board Room
Sponsor Meet & Greet with Snacks
Break for All
Thursday, October 22 schedule from 11:30 AM to 12:30 PM
11:30 AM – 12:30 PM
Shenandoah A & B
You Can’t Do It All: Building a cyber strategy roadmap as a team sport, select to show or hide session details

Track: GRC

Presenter(s): Kate Rhodes, Luke Watson, Ryan Orren & Jon Kline, ODU

Like most higher ed security programs, ours faces a familiar tension: growing regulatory obligations, an expanding attack surface, and a roadmap of good ideas (and audits) that will always outpace the team’s capacity to execute them. This session tells the story of how our security leadership team turned an independent gap assessment, audit findings, and the want to mature, into a living, prioritized roadmap, and how we’ve kept it alive since.

We’ll walk through our decision to move the program’s foundational framework from a generic ISO/IEC 27001 control model to NIST Cybersecurity Framework (CSF) 2.0, aligned with Zero Trust principles, and why that shift mattered for a higher-education environment supporting research, clinical, and academic missions simultaneously.

We’ll show how our annual gap assessment and audit findings translate directly into roadmap priorities and be candid about the harder part: deciding what doesn’t make the cut this year, and why.

The heart of this session is the “how,” not just the “what.” Our roadmap isn’t built or maintained by one person, it’s a standing collaboration between the CISO, Deputy CISO, Security Architect, and functional leads across Security Engineering, Security Operations, GRC, and Identity & Access Management. We’ll share the actual cadence and mechanics of how this team reviews progress, resolves competing priorities, and reshuffles the roadmap when the organization’s needs shift, including what’s worked, what hasn’t, and what we’d do differently.

Attendees will leave with a practical, adaptable model for translating a framework transition and gap assessment into a roadmap their own leadership team can sustain, or at least understand ours, and not just a plan that looks good in a single presentation to leadership, but one built to survive contact with real institutional constraints.

Shenandoah C
The Expanding Attack Surface: What Higher Education Must Know to Stay Ahead, select to show or hide session details

Track: Vendor

Presenter(s): Nate Parks & Tom Andriola, Dynatrace

Higher education institutions are facing unprecedented pressure. Budget constraints, staffing shortages, growing cybersecurity risks, increasing expectations for digital services, and the rapid adoption of AI are forcing IT organizations to rethink how they operate. For decades, campus IT organizations have relied on highly skilled personnel to manually monitor systems, investigate incidents, manage service tickets, and resolve performance issues. This model is becoming increasingly difficult to sustain as technology environments grow more complex and institutional resources remain constrained. This session explores how universities are leveraging modern observability platforms, integrated with IT Service Management (ITSM) processes, to transform IT operations from reactive and human-intensive workflows into intelligent, automated service delivery models. Real-world examples will illustrate how institutions can improve service reliability, accelerate incident response, strengthen cybersecurity operations, and increase operational efficiency while working within limited budgets and staffing levels. Participants will leave with a practical framework for evolving from traditional monitoring and ticket-driven operations toward intelligent, autonomous campus IT environments that improve user experiences while maximizing institutional resources.

Key Discussion Topics

  • Budget pressures facing higher education IT organizations
  • Workforce shortages and institutional knowledge challenges
  • Observability versus traditional monitoring
  • AI-assisted operations and intelligent automation
  • Integrating observability with ServiceNow and ITSM platforms
  • Automated incident detection and remediation
  • Digital experience monitoring for students, faculty, and staff
  • Cybersecurity and operational resilience
  • Measuring operational efficiency and business value

Appalachian A & B
Supercharging GRC with Generative AI: Lessons, Pitfalls & Breakthroughs, select to show or hide session details

Track: GRC

Presenter(s): Joshua Cole, Assura

How can generative AI transform a governance, risk, and compliance (GRC) program? This session shares Assura’s journey of integrating generative AI into our GRC program, a transformation that facilitates continuous compliance monitoring, allows us to speed up recurring tasks, and improves visibility and outcomes. Attendees will learn real-world lessons and pitfalls from our experience, including the cultural shift and skill retooling required with this approach, without replacing human expertise.

Appalachian C
JMU’s DMARC Journey, select to show or hide session details

Track: Topic Specific

Presenter(s): Elizabeth Martens & Joel Smith, JMU

This presentation will walk through the process we took to achieve DMARC compliance, including our experiences with discovering all senders, communicating with campus, configuring SPF, and continued monitoring. JMU is currently averaging 99% compliance for Fac/Staff email.

Allegheny B & C
Building GRC with Eramba: Our Journery So Far, select to show or hide session details

Track: GRC

Presenter(s): Rebecca Browder & Mayura Patel, VCU

“Building GRC with Eramba: Our Journey So Far” provides an overview of our transition from manual governance processes to a centralized GRC platform, driven by the need for better risk visibility and compliance tracking. The session explores why we chose Eramba and how we implemented its core modules for risk, compliance, and policy management, and how we leverage its API for automation and integration with existing workflows. We’ll also discuss our ongoing effort to build an enterprise risk register in Eramba. Attendees will gain practical insights into implementing Eramba, including the decisions we made, the lessons we’ve learned so far, and where we plan to go next.

Afternoon
Thursday, October 22 schedule from 12:30 PM to 1:15 PM
12:30 PM – 1:15 PM
Shenandoah A & B
LUNCH & Founder’s Award Presentation
Lunch
Thursday, October 22 schedule from 1:15 PM to 2:15 PM
1:15 PM – 2:15 PM
Shenandoah A & B
From Visibility to Action: Using Cybersecurity Metrics to Improve Security Outcomes, select to show or hide session details

Track: GRC

Presenter(s): Brad Sanford, UVA

Cybersecurity is a shared responsibility, but organizations cannot improve what they cannot measure. This session will explore how the University of Virginia developed an enterprise security scorecard that uses objective data to provide consistent visibility into device security risk across a complex, decentralized institution. UVA’s experience illustrates how carefully selected metrics can establish a baseline, reveal strengths and opportunities, support more productive conversations, and inform decisions about cyber risk remediation, operational priorities, and resource investment. The session will also offer practical guidance for organizations interested in developing their own scorecards, including how to select meaningful measures, build confidence in the underlying data, avoid common pitfalls, and present results in a way that encourages accountability, celebrates progress, and helps build a culture of continuous improvement.

Shenandoah C
Virginia’s SLCGP: Assessment-Driven Tool Deployment for Covered Entities, select to show or hide session details

Track: Topic Specific

Presenter(s): Matthew Umphlet, VITA

The Virginia State and Local Cybersecurity Grant Program is focused on translating capabilities assessment data into action. This presentation will explore how Virginia is using capabilities assessment results to prioritize and deploy cybersecurity tools and solutions for in-scope entities. Attendees will gain insight into Virginia’s decision-making approach, implementation strategy, and the practical lessons shaping this more targeted and data-driven phase of the program.

Appalachian A & B
Ghost Accounts: How financial aid can become initial access, select to show or hide session details

Track: Topic Specific

Presenter(s): Daevon Rascoe & Michael Forster, Regent

Every semester, universities create thousands of new student accounts before a single identity has been verified, or a single tuition dollar has been paid. Financial aid fraud is often viewed as the business office’s problem, a matter of compliance and audit trails rather than cybersecurity. Yet every fraudulent enrollment also creates a fully credentialed identity inside the university’s environment. It is initial access hiding in plain sight, disguised as routine student onboarding. This session explores the rise of “ghost students,” fraudulently or loosely verified enrollments that exist only long enough to collect financial aid. While financial loss often receives the most attention, the security implications are frequently overlooked. But what happens when the objective changes? A credential that was originally created to commit financial fraud can quickly become a trusted identity for phishing, persistence, or other forms of unauthorized access. Each ghost student is issued the same trusted identity as a legitimate student, complete with university email, single sign-on, learning management system access, and other institutional resources. Attendees will learn how financial aid fraud can become an initial access vector, what a typical student’s access looks like on day one, how attackers can abuse that trust at scale, and how defenders can identify suspicious enrollment activity before financial fraud becomes a cybersecurity incident.

Allegheny A
Modern Data Security in an AI World, select to show or hide session details

Track: Vendor

Presenter(s): Joshua Linkenhoker, Proofpoint

This presentation will review the key pillars of Modern Data Security and how to adapt them to protect organizations against the potential risks to Data posed by the use of AI in the workplace. Data Exfiltration Protection, Data Governance, and Insider Risk all evolve to incorporate new functionality as necessary to not only keep organizations safe in an AI world but also leverage AI capabilities to enhance the defensive posture of the organization.

Thursday, October 22 schedule from 2:15 PM to 2:30 PM
2:15 PM – 2:30 PM
Expo Area & Board Room
Expo Break
Break for All
Thursday, October 22 schedule from 2:30 PM to 3:30 PM
2:30 PM – 3:30 PM
Shenandoah A & B
Spoof Proofing: Understanding SPF, DKIM and DMARC, select to show or hide session details

Track: Technical

Presenter(s): Brannon Murphy & Michael Forster, Regent

Email domain spoofing is a form of cyberattack where a threat actor impersonates an organization to perform social engineering. For higher education institutions, this style of attack remains a huge problem. Ben Rogers of Allure Security (2026) found that 79% of higher-education institutions in the UK report being impersonated by unauthorized parties, while businesses sat at 28%. Domain spoofing presents a massive reputational, financial, and technical risk to both universities and regular users. Threat actors use the reputation of your organization to make phishing emails more convincing, leading to an increase in successful phishing attacks. The victims of these attacks might not realize your university was spoofed, leading to blame and reduced confidence in your university to keep students safe from phishing attacks. On the other side, your students receiving phishing emails from spoofed organizations can lead to account compromises, financial transactions to the wrong people, and even data breaches.

Domain-based Message Authentication, Reporting, and Conformance (DMARC) is a solution to help mitigate domain spoofing. DMARC is a protocol that allows organizations to define what happens to emails if they fail authentication, including quarantining and rejecting them. Unfortunately, DMARC adoption across the board is not in a good spot. According to Meysam Azad (2026), only 30.4% of around 5.5 million domains have implemented DMARC; of those, only 42% of them enforce policies (quarantine or reject) that act against potential spoofing emails. The DMARC implementation problem is particularly prominent in higher-education institutions. In 2025, Dmarcian reported that 77% of parent domains in the top 500 higher-education institutions in the US are not protected from domain spoofing due to malformed, non-existent, or unenforced DMARC records.

In this presentation, I hope to help other IT professionals in the higher-education industry understand DMARC and its components, showcase the business risks that can be reduced and/or mitigated with its adoption, and provide a methodology that can be used to adopt it.

Our university, Regent University, adopted a p=reject DMARC policy for our domain and a sister organization, and have seen considerable positive impact in both. Implementing DMARC has made such a huge impact for us, and I hope to help other universities begin their journey to realize these benefits as well.

Shenandoah C
Living Off Legitimate Tools: How Phishing is Evading Detection in Higher Education, select to show or hide session details

Track: Technical

Presenter(s): Serenity Smile, UVA

Phishing hasn’t gone away — it’s gotten quieter. At the University of Virginia’s Security Operations Center, we’re seeing attackers increasingly abandon obvious red flags in favor of infrastructure that looks, and often is, completely legitimate. This session walks through real, de-identified case studies from our SOC illustrating this shift:

  • Credential harvesting via Google Forms — no suspicious login page required, just a form hosted on a domain everyone already trusts.
  • PDF-to-Google-Drive-to-malware chains — phishing emails that lead to hosted PDFs, which in turn link to Google Drive downloads delivering malware payloads.
  • Abuse of legitimate remote access tools — attackers deploying software like Zoho Assist post-compromise to remotely control victim machines, harvest banking and login credentials, exfiltrate data, and even launch mass phishing campaigns from the compromised device — all while blending in with traffic your EDR may whitelist by default.
  • Piggybacking on trusted notification platforms — attackers abusing legitimate services like Zoom to send phishing lures through real notification emails, exploiting the fact that these messages come from verified, trusted sending domains that both users and security tools are conditioned to trust.

We’ll also cover the compounding damage cycle we’ve observed: even after a compromised account is disabled, malware on the endpoint can capture the new password, allowing attackers to regain access and continue their campaign. In our most serious cases, attackers have used stolen credentials to redirect victims’ direct deposit to attacker-controlled debit cards, resulting in thousands of dollars in losses — sometimes unrecoverable.

A key focus of the talk is why these lures work: emails spoofed or sent from genuinely compromised internal accounts, including colleagues and supervisors, and abuse of trusted third-party platform notifications exploit institutional and platform trust in ways external phishing never could. We’ll also examine a notable case involving fake birthday invitations used to specifically target VIPs and executives with malware downloads — showing how attackers tailor social engineering to their target’s role and social context.

Attendees will leave with concrete detection strategies for phishing that uses legitimate SaaS, communication, and remote access infrastructure, practical guidance for incident response when “disable the account” isn’t enough, and talking points for user awareness training that address why these attacks succeed — not just what to look for.

Appalachian A & B
Invisible Until You Need It: The Rise of Self-Healing Endpoints Description, select to show or hide session details

Track: Vendor

Presenter(s): Eric Ellis, Lenovo

The best security technologies often work silently in the background. Explore how self-healing capabilities, persistent endpoint connections, and automated recovery mechanisms help organizations recover from attacks faster while reducing operational burden on IT teams. Real-world examples illustrate why resilience is becoming just as important as prevention.

Appalachian C
From Pilot to Program: One Year of the Student SOC, Growth, Impact and What’s Next, select to show or hide session details

Track: Topic Specific

Presenter(s): Luke Watson & Jonathan Morales, ODU

A year ago, we introduced Old Dominion University’s student Security Operations Center, a partnership between the University Information Security Office and the School of Cybersecurity built to give students real operational experience while strengthening the university’s security posture. This session picks up where that story left off. We’ll share how the program has matured from an internship into a structured academic pathway, the results that have followed, from student outcomes to growing demand to greater visibility across the university, and how one of our own students now leads the team as our Lead Student SOC Analyst and co-presenter. We’ll close with where the program is headed for Fall 2027, including plans to grow the cohort, onboard students continuously, and introduce specialization tracks. Attendees will leave with a practical, field-tested model for turning a pilot SOC into a lasting academic program.

Allegheny A
Modernizing SecOps to Counter AI-Driven Threats with AI and Automation, select to show or hide session details

Track: Vendor

Presenter(s): Trevor Stuart, Palo Alto Networks

Adversaries are utilizing frontier AI to execute hyper-automated, machine-speed attacks. To keep pace, security operations must evolve. Join Palo Alto Networks to explore how an AI-driven, automation-first approach transforms SOC performance—empowering teams to counter complex AI threats with real-time autonomous defense..

Thursday, October 22 schedule from 3:30 PM to 3:45 PM
3:30 PM – 3:45 PM
Expo Area & Board Room
Expo Break
Break for All
Thursday, October 22 schedule from 3:45 PM to 4:45 PM
3:45 PM – 4:45 PM
Shenandoah A & B
Security Analysis Lead, select to show or hide session details

Track: GRC

Presenter(s): Dan Crompton & James Squire, Liberty

Never Waste a Crisis: Implementing Email Security During an Active Phishing Campaign. We had planned a thoughtful, tested, and deliberate roll-out of a new email security solution from Check Point to help us combat phishing. A sudden and major phishing campaign forced Liberty University to change our approach and rapidly deploy enhanced email security on the fly. This session examines the technical, operational, and leadership challenges of making major security changes under pressure. Attendees will gain practical guidance on evaluating risk, obtaining stakeholder support, managing end-user expectations, and measuring success when time is limited and threats are immediate. Real-world lessons learned will help security and IT leaders prepare for similar situations at their own institutions.

Shenandoah C
Email Security – JMU’s Implementation of Sublime, select to show or hide session details

Track: Technical

Presenter(s): Elizabeth Martens, Joel Smith & Chris Lanier, JMU

JMU implemented Sublime AI for email security in the Summer/Fall of 2026. This presentation will describe our reasons for pursuing a solution beyond that which was offered by M365, the vendor selection process, and our experience so far with the product.

Appalachian A & B
Understanding Cyber Resilience in the Context of Agentic AI, select to show or hide session details

Track: Technical

Presenter(s): Paul Kinder, CDW

Agentic AI is introducing new considerations for cybersecurity and risk management, influencing how organizations approach governance, security operations, and incident response. This presentation explores the potential impacts of autonomous and semi-autonomous AI systems on organizational resilience, including emerging risks, operational challenges, and evolving security practices. Attendees will gain an understanding of current trends, key considerations for oversight and preparedness, and approaches organizations are evaluating as they adapt existing cybersecurity programs to an increasingly AI-enabled environment.

Appalachian C
Phishing Without a License, select to show or hide session details

Track: Topic Specific

Presenter(s): Ryan Nielson, VCU

We built and deployed a self-hosted GoPhish platform to support internal phishing awareness and security training initiatives. The solution leveraged our own hosted infrastructure, custom domains managed through GoDaddy, and F5 load balancing to securely host landing pages and manage traffic. This approach provided greater control, flexibility, and alignment with our internal security goals. This presentation will walk through our technical stack as well as some of the challenges we faced along the way.

Allegheny A
Defending the Modern Inbox: A Smarter Approach to Email Security, select to show or hide session details

Presenter(s): Travis Bertolino, Abnormal AI

The widespread adoption of AI has boosted productivity across organizations, but it has also supercharged cybercriminals. Attackers can now craft highly convincing, large-scale email threats that are free of usual red flags. As a result, credential phishing and business email compromise (BEC) attacks are becoming more frequent, more sophisticated, and harder for humans to spot. In this session, you’ll learn how generative AI is reshaping the threat landscape and why humans alone can’t keep up with the speed of AI-driven attacks. We’ll explore how defensive AI can detect and stop malicious AI in real time, and you’ll leave with clear, practical actions to strengthen your defenses against AI-enabled email attacks.

Evening
Thursday, October 22 schedule from 5:00 PM to 6:30 PM
5:00 PM – 6:30 PM
Shenandoah A & B (seating)
Welcome Dinner & Founder’s Award
Dinner & Award

Friday, October 23

Morning
Friday, October 23 schedule from 8:00 AM to 9:00 AM
8:00 AM – 9:00 AM
Blue Ridge Foyer
Registration in Main Lobby & Breakfast in Shenandoah Foyer, with Seating in Shenandoah A & B for meals
Registration
Friday, October 23 schedule from 8:00 AM to 2:00 PM
8:00 AM – 2:00 PM
Expo Area & Board Room
Sponsor Exhibit Areas (closed for lunch 11:15 AM – 11:45 AM), Break Refreshments
Expo
Friday, October 23 schedule from 9:00 AM to 5:00 PM
9:00 AM – 5:00 PM
Shenandoah A & B
Training (will have same breaks & lunch)
Training Registration Required
Friday, October 23 schedule from 9:00 AM to 10:00 AM
9:00 AM – 10:00 AM
Shenandoah C
The Moving Target: Our Journey to CMMC Through Shifting Standards, Staff and Accessors, select to show or hide session details

Track: GRC

Presenter(s): EJ Corpus & Brandon Freshcorn, ODU

Supporting research that involves Controlled Unclassified Information (CUI) requires more than implementing technical security controls. It requires a coordinated program that brings together people, processes, technology, research needs, and compliance responsibilities.

This session will provide an overview of our secure research program and the Regulated Research Computational Environment (RRCE), including how the environment supports researchers working with sensitive and regulated data. We will discuss the teams and organizational roles involved in operating the environment and how collaboration between cybersecurity, information technology, research administration, leadership, and researchers helped move the program forward.

We will also share how we used project planning to organize security and compliance activities, assign responsibilities, track documentation and remediation efforts, and maintain progress as CMMC requirements, timelines, and guidance continued to change. Rather than focusing on a single standard or revision, the session will highlight how structured planning and clearly defined roles can help an organization adapt to changing expectations.

Finally, we will discuss our general approach to assessment readiness and working with a Certified Third-Party Assessment Organization (C3PAO), including preparing documentation, reviewing control implementations, identifying gaps, and determining when the organization is ready to proceed with an external assessment.

Attendees will gain practical insight into developing a secure research environment, organizing a multidisciplinary team, managing compliance work through a project plan, and preparing for an external assessment in an evolving regulatory landscape.

Appalachian A & B
Did you read the EULA?, select to show or hide session details

Track: Topic Specfic

Presenter(s): Randy Marchany, VA Tech

Abstract: That customers must patch, monitor, segment, and defend a system does not erase the fact that the original security weakness was built into the product by the vendor. That observation is the starting point for this series. The SANS Top 10 Internet Threats (2000), SANS Top 10 Security Mistakes Individuals Make (2001), the OWASP Top 10 (2003) listed the top vulnerabilities for software. Yet. nine of the ten vulnerability classes identified in 2000, 2001, 2003 remain active causes of major breaches in 2026. Why haven’t they been addressed?

This series documents why the answer is economic, not technical. Cybersecurity’s original sin is not insecure code. It is a single legal instrument, the End User License Agreement, that made insecure code economically acceptable by capturing the market in which accountability would otherwise have operated. By shifting from ‘the user doesn’t negotiate’ to ‘the user CANNOT negotiate,’ the EULA seized the liability standard, the remedy, and the alternative from every user simultaneously. From the 1990s that set up this environment. Even the Federal Government was not able to negotiate EULA terms.

This talk reviews the court findings. This talk will show examples of attacks from 2007-2026 where the initial vector was one of those 10. We’ll also review specific clauses in a number of well known vendor EULAs and show some surprising elements in them.

Appalachian C
That’s my token, I don’t know you!, select to show or hide session details

Track: Technical

Presenter(s): Jared Karnes & Dean Johnson, VITA

A deep dive into the process of threat actors utilizing phishing and token endpoint polling to steal Microsoft authentication tokens, which leads to unauthorized access and potential rogue device registration.

Allegheny C & B
The Path to a Passwordless Campus, select to show or hide session details

Track: Vendor

Presenter(s): Stuart E. Trafford, Ed.D & Jeremey Benedict, Okta

Traditional passwords are a higher-ed liability, driving sophisticated phishing attacks and skyrocketing cyber-insurance premiums. This session delivers a practical framework for transitioning to a passwordless campus using modern, Identity and Access Management (IAM) strategies. We will explore how to balance frictionless student and faculty access with strict “zero-trust” security requirements. Drawing on lessons from a major university’s rollout to nearly 50,000 active monthly users, we will share hard-won strategies for overcoming cultural pushback, accessibility hurdles, and shared-device challenges. From FIDO2 to passkeys, learn how to build a security roadmap that eliminates the credential vulnerability.

Learning Objectives:

  • Assess the Roadmap: Identify the technical and cultural milestones needed to move from traditional MFA to a fully passwordless environment.
  • Balance UX and Security: Learn how phishing-resistant authenticators (biometrics and passkeys) simultaneously reduce help desk volume and harden campus defenses.
  • Architect for Diverse Users: Design flexible identity policies tailored to researchers, transient students, and alumni.
Friday, October 23 schedule from 10:00 AM to 10:15 AM
10:00 AM – 10:15 AM
Expo Area & Board Room
Sponsor Expo Break – Meet & Greet
Break for All
Friday, October 23 schedule from 10:15 AM to 11:15 AM
10:15 AM – 11:15 AM
Shenandoah C
The Watcher of Birds & Viking Boy present an unforgettable cybersecurity experience unlike anything you’ve seen at a conference…, select to show or hide session details

Track: GRC

Presenter(s): Beth Lancaster & Caeland Garner, VA Tech

This isn’t another slide deck.

It’s a live performance that blends original music, storytelling, real-world cyber threats, and practical security education into an immersive experience that keeps audiences engaged from beginning to end.

Through original songs spanning electronic dance music, country, rock, and modern country-rap, attendees will experience the human side of cybersecurity—from phishing attacks and spam campaigns to zero-day vulnerabilities, ransomware, and the everyday decisions that protect organization.

Each song introduces a cybersecurity concept before transitioning into live demonstrations, real attack stories, and actionable defensive strategies that security professionals, executives, and everyday users can immediately apply.

Whether you’re a seasoned security practitioner or brand new to cybersecurity, you’ll leave entertained, inspired, and better prepared for the threats waiting beyond the firewall.

Get ready for a presentation that feels less like a conference session and more like a live concert—where every beat teaches a lesson and every lyric strengthens cyber resilience.

Appalachian A & B
Cirrus Identity SAML Bridge Implementation – JMU’s Story, select to show or hide session details

Track: Topic Specific

Presenter(s): Mamata Biswal & V Kagey, JMU

JMU implemented Okta in 2025 and used Cirrus Identity’s SAML Bridge to maintain access to InCommon federated and bilateral applications while retiring Shibboleth. The session covers implementation and testing strategy, redirecting authentication traffic, lessons learned, challenges, and outcomes.

Appalachian C
Smoke, Mirrors, and SPNs: The Art of Deception in Defensive Security, select to show or hide session details

Track: Technical

Presenter(s): Trey Richardson & Daevon Rascoe, Regent

Alerts can be overwhelming. Cyber deception offers high-fidelity alerting with a near-zero false positive rate. The result: frustrated attackers who think they’ve found an easy win, only to discover what they found is useless, or that they’ve stumbled into a trap that expels them from the environment. It buys defenders more time while causing attackers and penetration testers alike to waste theirs on unusable targets.

This presentation covers the types of deception we use at Regent University: decoy accounts, honey credentials, Kerberoastable accounts with SPNs set as bait, and deceptive “admin” and super-user groups designed to alert on specific tool usage, along with the best practices we’ve discovered. We’ll share how we repurpose soon-to-be-decommissioned accounts as lures that blend into the environment, looking like any other account but existing solely to detect and contain threats. We’ll cover the automation we built to take action the moment a decoy trips, and close with success stories showing how these detections caught and contained real threat actors (and pentesters) early.

Allegheny C & B
Third-Party Risk Management in Practice: A Conversation with Regent University, select to show or hide session details

Track: Third Party Risk Management in Practice: A Conversation with Regent University

Presenter(s): McKay Lasko, SaltyCloud & Mike Forster, Brannon Murphy, Regent

Third-party risk is one of the most resource-intensive parts of any higher ed security program, yet institutions operationalize it very differently even within the same state. This session brings two members of Regent University’s information security team into a moderated conversation about how they run their third-party risk program, from the leadership level down to the day-to-day mechanics of reviewing vendors, scoring risk, and keeping an inventory current. The session is structured as a prepared Q&A: the moderator poses questions shared with panelists in advance, with a small number of screenshots used only when they help illustrate a specific workflow. The goal is for attendees managing third-party risk at their own institutions to leave with best practices they can borrow or adapt.

Friday, October 23 schedule from 11:15 AM to 11:30 AM
11:15 AM – 11:30 AM
Expo Area & Board Room
Expo Break
Break for All
Friday, October 23 schedule from 11:30 AM to 12:30 PM
11:30 AM – 12:30 PM
Shenandoah C
Applying CIS Benchmarks – JMU IT, select to show or hide session details

Track: GRC

Presenter(s): Josh Dameron & Greg Hackbarth, JMU

A group presentation from various team leads on planning for and applying CIS Benchmarks in AD/M365, servers, endpoints, and collaboration tools such as Zoom.

Appalachian A & B
NSU’s COP (Cloud Oversight Process), select to show or hide session details

Track: Topic Specific

Presenter(s): Ron King & Chirag Dobariya, NSU

As we all know, third-party risk management has become even more important. We will be sharing the audit friendly Cloud Oversight Process (COP) NSU has implemented to manage information security needs around third party and SaaS providers.

Appalachian C
Using the SUPER script and Jamf Pro to manage OS updates and upgrades, select to show or hide session details

Track: Technical

Presenter(s): Frank Pereira, JMU

Demonstrate how JMU uses a modified version of the SUPER script with Jamf Pro policy to manage both our minor and major OS updates with a built-in deferral system to allow users flexibility on when to perform the updates.

Allegheny C & B
Beyond Detection: A Five-Step Exposure-to-Remediation Playbook, select to show or hide session details

Track: Technical

Presenter(s): Sam Kinch & Joel Maxfield, Tanium

What if the disclosure-to-exploit window suddenly collapses from days to hours? How prepared are you? How will you respond? What will be the impact to your organization… and more importantly, to the constituents, citizens, students/faculty, internal staff you support? In April 2026, Anthropic disclosed Project Glasswing — an AI agent that found thousands of zero-days and wrote working exploits 72 percent of the time. The CVE pipeline doubled between 2024 and 2025. A 30-day patch cycle is now a pre-AI artifact, and most public-sector IT shops are still running one. This session is for IT and Security Operations teams.

We will walk through five practical areas — Identify, Patch, Update, Renew, and Enforce — that close the exposure-to-remediation loop and bring patch cadence inside the new disclosure-to-exploit window.

During this session, you will see how to:

  • Prioritize CVEs by exploitability rather than severity
  • Build ring-based automated remediations that will not break production systems
  • Automate certificate renewal ahead of the 47-day cliff
  • Replace GPO sprawl with real-time policy enforcement
  • Attendees will walk away with a:

    • Five-step, exposure-to-remediation framework
    • Tuesday-morning, three-step action list
    • Yardstick to measure their current patch cadence against the new adversary timeline
    • Bring your most stubborn patching war story — the Q&A is where the playbook gets sharpened
Afternoon
Friday, October 23 schedule from 12:30 PM to 1:45 PM
12:30 PM – 1:45 PM
Shenandoah A & B (seating)
LUNCH & Prizes – MUST Be Present To WIN!
Lunch & Prizes
Friday, October 23 schedule from 1:45 PM to 2:45 PM
1:45 PM – 2:45 PM
Shenandoah C
Bridging the Gap: How Security Liaisons Advance Cybersecurity Governance, Risk and Compliance in Higher Education, select to show or hide session details

Track: GRC

Presenter(s): James Baker & Stacy Sties, UVA

Higher education institutions struggle to implement consistent cybersecurity across decentralized IT environments. The Information Security Liaison model places trusted advisors between central governance and departmental IT teams to improve communication, translate policy into actionable guidance, and strengthen compliance through partnership.

Appalachian A & B
JMU’s Passwordless Journey with Okta FastPass, select to show or hide session details

Track: Topic Specific

Presenter(s): Jordan Leaman & William Case, JMU

Following James Madison University’s implementation of Okta in 2025, JMU introduced Okta FastPass as an optional passwordless authenticator for students, faculty, and staff. While enabling the technology was relatively straightforward, JMU quickly discovered that a successful passwordless deployment required careful consideration of authenticator enrollment sequencing and authentication policy design. This session examines how JMU developed custom enrollment and authentication policies to ensure users established a portable authentication method before enrolling a device-bound FastPass credential, reducing account lockouts and computing support. Attendees will learn how JMU addressed security concerns with default FastPass authentication policies through the use of Okta’s Authentication Methods Chain, evaluated the risks and benefits of supporting passwordless authentication on personal devices, and drove adoption by emphasizing convenience and a simplified user experience rather than security-focused messaging.

Appalachian C
Whitebox Pentesting: Using “Kali w/ Vulnerable Know Targets” on the Cyber Range, select to show or hide session details

Track: Technical

Presenter(s): Thomas “Tweeks” Weeks & Dominik Borkowski, VT/ Virginia Cyber Range

In this demo-workshop, attendees get to power-up their skill-sets on Kali Linux! First you get to watch us compromise multiple, well known CVEs, from the safety of the Cyber Range’s cool, new “Kali w/vulnerable targets” VM environment. We then give you all the documentation and step by step directions that you need to use tools like netcat, nmap, and msfconsole (Metasploit) to do it all yourself! You’ll get a Cyber Range login to pop root shells on vulnerable telnetd (CVE-2026-24061), compromise a SambaCry file server (CVE-2017-7494), extract private RSA keys on a Heartbleed/web server (CVE-2014-0161), and more! Come to our demo you’ll get a 48 hour Cyber Range account in the cloud that you can use to then do it all yourself.. all while learning several powerful network scanning, enumeration and pentest tools in the process!/p>

Allegheny C & B
Program Manager – Lessons Learned from REN-ISAC, select to show or hide session details

Track: Topic Specific

Presenter(s): Kyle Enlow, REN-ISAC

Lessons learned and common findings from a years worth of penetration test conducted by REN-ISAC penetration testing team.