GovSec,Washington DC

GovSec Summit USA

by GovInfoSecurity


May 5, 2026 | 8:30AM - 5:30PM ET | Washington, DC

Hosted by BankInfoSecurity

GovSec,Washington DC

Event Overview

The 2026 GovSec Summit USA by GovInfoSecurity, brings together 100+ federal and public-sector CISOs and senior cyber leaders to discuss how cyber leadership is changing as disruption becomes routine. Agencies are no longer responding to isolated incidents, but managing ongoing cyber risk amid policy shifts, persistent threats, and operational strain.

The summit focuses on how leaders are adapting governance, operating models, and decision-making to work effectively in this environment. Sessions emphasize practical approaches to balancing compliance, mission needs, speed, and accountability across complex organizations.

Rather than focusing on tools, the event treats cybersecurity as an enterprise risk and governance issue tied to mission delivery, budgets, coordination, and public trust. Attendees will engage with peers and senior leaders who are shaping modern cyber leadership.

Dr. Meghan Hollis-Peel

Data Management Officer, Texas Department of Licensing and Regulation

Greg Tatum

CISO, Businessolver

Jessica Bolton

VP, North Texas ISSA

Danielle Jablanski

OT/ICS SME & Strategy Lead, Cybersecurity and Infrastructure Security Agency

Shuchi Agrawal

CDO - Global Head of Data Tooling Adoption, Automation, Data Provisioning, Citi

Todd Pauley

CISO, Texas Education Agency

Bryce Carter

CISO, City of Arlington

Everett Bates

CISO, Crunchyroll

Zechariah Akinpelu

CISO, Unity Bank Plc

Ravikumar Mukkamala

Executive Director, Cloud, JP Morgan

David Ginn

CISO, Johnson Controls

Joseph Berglund

Director of IT Operations & Cybersecurity, USME Services Center

2025 Speakers

Thought Leaders Leading Deep-Dive Discussions on Stage​

ISMG Summits bring the foremost thought leaders and educators in the security space to the stage at interactive workshops and networking events. Learn from the who’s who in the cybersecurity industry, passionate about the latest tools and technology to defend against threats.

Steering Committee

Guiding Our Summit With Industry Expertise

Our Summit Advisory Committee comprises industry visionaries whose guidance ensures the conference programs remain relevant, cutting-edge, and aligned with the most pressing cybersecurity challenges and opportunities – enabling attendees to apply the insights and learnings to their daily work.

Chris Riotta

Managing Editor, Government Technology, ISMG

Rex Booth

CISO, Sailpoint

Anthony Labbate

Director, Cyber Security | Government Defense & Intelligence, Oracle

Bill Streilein

Vice President and Chief Technology Officer, Noblis

Alison King

VP, Government Affairs, Forescout Tech

Venue

Conrad New York Downtown

102 N End Avenue, New York, NY 10282

NOTE:  All requests to attend will be reviewed by event staff and approved based on professional qualifications and event capacity.

Topic Highlights

  • Identity, Zero Trust, and the Reality of Implementation
  • Governing Cyber Risk in a Fragmented Regulatory Environment
  • People, Budgets, and the Future of Public-Sector Cyber Defense
  • From Compliance to Capability: Making Security Governance Operational
  • Modernization Under Constraint: Securing Legacy and Hybrid Environments

What Attendees Will Gain

  • Insight into how agencies are operationalizing cyber governance under constant disruption
  • Real-world approaches to balancing compliance, mission risk, and speed of execution
  • Lessons learned on adapting cybersecurity strategies to achieve long-term resilience
  • A peer-driven forum focused on decision-making, accountability, and leadership, not just technology

This summit is designed for CISOs who are not just managing cyber programs, but governing risk as a core function of modern government.

Agenda

Given the ever-evolving nature of cybersecurity, the agenda will be continually updated to feature the most timely and relevant sessions.

8:50 AM - 9:00 AM ET

Chair’s Opening Address

8:30 am - 8:35 am et

Opening Comments

9:00 AM - 9:40 AM ET

Panel Discussion: Navigating Regulatory Fragmentation and Compliance Burdens in Government Cybersecurity

As agencies try to implement consistent security controls across networks, cloud environments, and mission-critical systems, the challenge of maintaining compliance without stifling innovation grows ever more pressing. This panel brings together government and industry leaders to discuss practical approaches for streamlining compliance, reducing operational friction, and aligning regulatory priorities with mission needs. Attendees will gain insight into emerging frameworks, successful coordination strategies, and real-world lessons for balancing regulatory adherence with operational agility and risk management.

  • How can agencies manage overlapping cybersecurity regulations without overburdening IT and security teams?
  • What strategies are proving effective for aligning compliance efforts with mission priorities and operational realities? Who owns the risk for those and how do you drive strategy?
  • How can leadership balance regulatory adherence with innovation and risk management in rapidly evolving threat environments?
GovSec,Washington DC

Sanjit Ganguli,

VP, CTO in Residence, Zscaler

9:40 AM - 10:20 AM ET

Mitigating Data Breaches: Detection, Response, and Containment in Practice

In this session, we examine real-world breach scenarios, explore what works in practice, and discuss how agencies can strengthen their detection, response, and containment capabilities to reduce risk and protect sensitive data.

  • Tackle common failure points and improve visibility to prevent breaches from going undetected or escalating
  • Strengthen detection, incident response, and containment across hybrid, multi-cloud, and legacy environments
  • Prepare government teams to manage complex breaches involving multiple agencies, contractors, and shared services while preserving mission continuity
GovSec,Washington DC

Vlad Brodsky,

Chief Information Officer & Chief Information Security Officer, OTC Markets Group Inc.

GovSec,Washington DC

Steve Lenderman,

Head of Fraud Prevention, iSolved, CyberEdBoard Member

GovSec,Washington DC

Josh Cigna,

Solutions Architect, Yubico

10:20 AM - 11:00 AM ET

Networking Break

11:00 AM - 11:30 AM ET

Applying Advanced Detection and Identity & Access Management in Government

This session draws on practical insights to highlight how agencies can operationalize these capabilities to strengthen defenses, reduce attacker dwell time, and support mission continuity.

  • Defend government environments by deploying advanced detection to identify and disrupt threats earlier
  • Strengthen identity security by applying modern IAM controls across users, devices, and privileged access
  • Integrate detection and IAM to contain incidents faster and limit attacker movement
GovSec,Washington DC

Chris Wysopal,

Chief Security Evangelist, Veracode

11:30 AM - 12:00 PM ET

Preparing for Cyber Conflict Below the Threshold of War

Government leaders must anticipate and respond to these operations with strategies that combine cyber defense, resilience, and interagency coordination. In this fireside chat, we explore how agencies can prepare for and manage persistent, low-intensity cyber conflict while safeguarding critical missions and public trust.

  • How can we identify where low-level and gray-zone cyber operations pose the greatest risk to government missions?
  • What steps can we take to detect, attribute, and respond to below-threshold threats using effective policy, coordination, and technical capabilities?
  • What leadership lessons from international incidents and evolving threat landscapes can we apply to strengthen cyber resilience?
GovSec,Washington DC

Vincent Stoffer,

Field CTO, Corelight, Inc

12:00 PM - 12:30 PM ET

Beyond Response: Addressing the Aftermath of Ransomware Incident

As attacks grow more targeted and disruptive, agencies must evolve beyond one-time response efforts and adapt their people, processes, and governance in real time and after recovery. This session explores how agencies translate live ransomware incidents into lasting operational improvements, refine decision-making under pressure, and strengthen resilience across technical, legal, communications, and leadership functions, during recovery and well beyond the initial response.

  • Examine how agencies should adapt operational priorities, risk tolerance, and mission delivery after a ransomware incident
  • Understand how to refine response playbooks post-incident to improve coordination across IT, security, legal, public affairs, and executive leadership
  • Identify how agencies can institutionalize lessons learned through after-action reviews, training, exercises, and strengthened external partnerships
GovSec,Washington DC

Chris Young,

Cybersecurity Enterprise Account Executive, OpenText

12:30 PM - 1:30 PM ET

Lunch

1:30 PM - 2:00 PM ET

Modernizing Government Cybersecurity Without Breaking Legacy Systems

This fireside chat explores how government leaders are balancing innovation with stability, incrementally improving security, managing risk, and enabling modernization without disrupting essential operations.

  • Where do legacy systems introduce the greatest cybersecurity and operational risks for government missions?
  • How can agencies prioritize modernization while maintaining continuity and applying effective security controls?
  • How are agencies leveraging cloud, zero trust, and automation without destabilizing systems, and what leadership approaches support this?
GovSec,Washington DC

Kristopher Schroeder,

Founder & CEO, Replica Cyber

2:00 PM - 2:30 PM ET

Defending AI Systems Against Emerging Cyber Attacks

This session explores how government leaders can protect AI systems throughout their lifecycle while enabling responsible innovation and mission impact.

  • Identify where AI systems pose the greatest risk to government missions and public trust
  • Assess and classify AI systems as mission-critical assets to prioritize protection
  • Mitigate AI-specific threats including data poisoning, model theft, and adversarial attacks
GovSec,Washington DC

Tim Hill

VP, Software Engineering, Rocket Software

2:30 PM - 3:00 PM ET

From Compliance to Capability: Making Governance Actionable

This case study session examines how one organization moved beyond checkbox compliance to make governance actionable, aligning policy, risk management, and day-to-day security operations. Attendees will gain practical insight into how clear ownership, measurable outcomes, and integrated decision-making can turn governance from an obligation into a force multiplier for resilience and mission success.

  • Why compliance alone fails to reduce real-world cyber risk
  • How governance can be embedded into day-to-day mission operations
  • What metrics truly reflect security effectiveness rather than audit readiness
  • Where we are seeing measurable improvement
GovSec,Washington DC

Sandeep Bhide

VP Product Management, ProcessUnity

3:00 PM - 3:30 PM ET

Zero Trust After the Hype: What Actually Works in Government

In this session, we cut through the hype to share real-world lessons learned, highlight what has proven effective, and discuss how agencies can mature Zero Trust implementations to better reduce risk and support mission objectives.

  • How to prioritize Zero Trust capabilities that deliver immediate security value in government environments
  • How to apply Zero Trust principles realistically across legacy systems, mission-critical applications, and modern infrastructure
  • How to balance investments and measure Zero Trust effectiveness using outcomes beyond compliance
GovSec,Washington DC

Scott Tenenbaum

Head of Claims, North America, Resilience

GovSec,Washington DC

David Anderson

CIPP/US, Vice President, Cyber, Woodruff Sawyer - A Gallagher Company

GovSec,Washington DC

Kimberly Pack

Counsel, Thompson Hine LLP

3:30 PM - 4:00 PM ET

Networking Break

4:00 pm - 4:40 pm ET

Breakout Discussions

T1. How can agencies manage third-party cyber risk more effectively?

T2. What threats are hiding in plain sight?

T3. What does it take to be a cybersecurity leader of the future?

T4. What cyber threats will define cyber risk in the public sector by 2030?

GovSec,Washington DC

Vincent Stoffer,

Field CTO, Corelight, Inc

4:40 pm - 5:20 pm Et

Securing U.S. Government Networks Amid Budget Constraints and the Skills Gap

This closing panel brings together government and industry leaders to discuss practical, cost-effective strategies to secure government networks while addressing today’s most urgent workforce and resource challenges.

  • How can agencies prioritize cybersecurity investments, including workforce development, when budgets and resources are constrained?
  • What cost-effective strategies, technologies, and operating models help mitigate cyber risk while addressing the cybersecurity skills gap?
  • How can leaders optimize people, tools, and processes to maintain resilience and mission continuity in a resource-limited environment?

 

GovSec,Washington DC

Seth Rose,

Supervisory Special Agent Group 06, U.S. Department of the Treasury/Cyber Investigations Unit

GovSec,Washington DC

Imran Khan

VP Cyber Security Transformation Lead, BNP Paribas

5:20 PM - 5:30 PM ET

Chair’s Closing Address

Don’t miss your chance to attend this dynamic impactful event

@ ISMG_News    #ISMGSummits

Past Summit Sponsors

GovSec,Washington DC
GovSec,Washington DC

Register

CPE Credits

Our Summits offer Continuing Education Credits. Learn informative and engaging content created specifically for security professionals.

The Summit Experience

Upcoming ISMG Events

CS4CA ANZ

February 10 - 11, 2026

EspanaSec

February 10 - 11, 2026

Implications of AI

February 24, 2026 | Virtual

Nullcon GOA

February 25 - March 1, 2026

ManuSec Europe

February 26 - 27, 2026

Upcoming ISMG Events

CS4CA ANZ

February 10 - 11, 2026

EspanaSec

February 10 - 11, 2026

Implications of AI

February 24, 2026 | Virtual