Venue
Conrad New York Downtown
102 N End Avenue, New York, NY 10282
NOTE: All requests to attend will be reviewed by event staff and approved based on professional qualifications and event capacity.
ISMG’s 2025 Financial Services Cybersecurity Summit will tackle the sector’s most urgent cyber challenges. A keynote panel of leading CISOs will discuss how InfoSec leaders’ responsibilities now span IT, data, communications and operations, underscoring cybersecurity’s strategic role. Sessions will deliver insights on advanced threat intelligence, payment fraud prevention, AI’s impact on attackers and defenders, and leveraging cyber insurance in risk management.
The event concludes with the interactive Solution Room, a hands-on incident response workshop where participants face a high-stakes deepfake scenario to strengthen crisis planning and response.



102 N End Avenue, New York, NY 10282
NOTE: All requests to attend will be reviewed by event staff and approved based on professional qualifications and event capacity.
ISMG Summits bring the foremost thought leaders and educators in the security space to the stage, interactive workshops and networking events. Learn from the “who’s who” in Cybersecurity passionate about the latest tools and technology to defend against threats

CSO, Robinhood Markets

CISO, MassMutual

Field CTO, Corelight, Inc

AI Risk & Security Expert, 3x CISO, Board Advisor, Author, CISSP, CISM, AWS Security, PCI QSA

Global Head of Risk and Regulatory Compliance, JPMorganChase
This includes implementing a modern zero trust architecture to protect data and users, embracing AI while managing its risks, and handling the technical and financial implications of ever-expanding environments. A risk-based approach to security ensures CIOs and CISOs deliver a secure, phased transformation.
Join this session to:

VP, CTO in Residence, Zscaler
The goal has been common to the financial industry for several years: What will it take to achieve it? This session will explore advances in biometrics, hard tokens, passkeys and also consider how these advances can improve – or impede – customer UX, and where more friction could be a requirement. Panelists will also discuss the implications of password-free security within financial organizations.
Session highlights:

Chief Information Officer & Chief Information Security Officer, OTC Markets Group Inc.

Head of Fraud Prevention, iSolved, CyberEdBoard Member

Solutions Architect, Yubico
The report analyzed 1.3 million applications to find the most significant risks that this sector faces.
Highlights include:
Join us to learn more about the key findings, best practices to fix them, and a discussion on where the industry will go next.

Chief Security Evangelist, Veracode

Field CTO, Corelight, Inc

Cybersecurity Enterprise Account Executive, OpenText

Founder & CEO, Replica Cyber
Join this session to address the unique challenges of critical system security within the framework of 23 NYCRR 500, including the latest November 1 deadline. We’ll break down each regulatory requirement, highlight why critical systems must be a central focus, and explore the tangible costs of non-compliance. From vulnerability management and penetration testing to MFA and surgical data recovery, we’ll provide actionable insights and a readiness checklist to help you take immediate steps toward compliance.
You will learn:
Don’t miss this opportunity to gain clarity, reduce noise, and take control of your critical system security strategy.

VP, Software Engineering, Rocket Software
More resources? Not likely. Sound familiar? You’re not alone. We’ve been at this for years, yet the process continues to become more burdensome for your team and for the people in your company who rely on your third parties. It doesn’t have to be that way.
The newest risk exchange models are eliminating up to 80% of questionnaire requests by leveraging validated data. In this session, we’ll show you how to transform your third-party risk management program by incorporating smarter workflows and better data access.
What you’ll learn:

VP Product Management, ProcessUnity
Today, lawsuits can follow within days of a breach, insurers are tightening terms, and underwriters want proof of governance maturity and supply chain visibility — not just policies on paper.
This session explores how CISOs, legal teams, and insurers are redefining the economics of cyber risk. We’ll examine how financial institutions are quantifying exposures across data breaches, business interruption, privacy practices, and third-party dependencies — and how cyber insurance is evolving to keep pace with new forms of liability, litigation, and regulatory oversight.
We’ll discuss:

Head of Claims, North America, Resilience

CIPP/US, Vice President, Cyber, Woodruff Sawyer - A Gallagher Company

Counsel, Thompson Hine LLP

Field CTO, Corelight, Inc
This expertly designed session challenges participants to respond to cascading disruptions across IT and operational systems, unraveling the role of AI-augmented tactics in exploiting insider vulnerabilities. With a multi-phase simulation highlighting the cross-industry impact of AI-augmented insider threats on IT and operational systems, attendees will collaborate to develop actionable strategies for containment, detection, and long-term defense.
What You Will Gain From This Experience:

Supervisory Special Agent Group 06, U.S. Department of the Treasury/Cyber Investigations Unit

VP Cyber Security Transformation Lead, BNP Paribas

Field CTO, Corelight, Inc
But what about the other 80% of enterprise data that resides in non-production environments like development, testing, analytics, and AI/ML? These environments are rich with sensitive data, yet frequently underprotected, creating a massive blind spot for CISOs and cyber leaders.
Join Aaron Jensen, Director of Solutions Engineering at Delphix, as he unveils insights from the 2025 State of Data Compliance and Security Report, which found that 54% of organizations have already experienced data breaches in non-production environments, and 84% allow compliance exceptions that increase risk. With AI accelerating data sprawl and regulatory scrutiny intensifying, the stakes have never been higher.
This session will explore how Delphix helps financial institutions eliminate data risk without slowing innovation—using automated data masking, secure replication, and continuous compliance across hybrid and cloud environments. Learn how to secure the data that fuels development while meeting the demands of regulators, auditors, and your board.
Key Takeaways:

Director of Solutions Engineering, Delphix
In this session, we address the critical challenge of third-party and supply chain risk management in the financial sector. We’ll explore real-world case studies and cover best practices for due diligence, continuous monitoring, and incident response planning.
Key Takeaways:

VP Cyber Security Transformation Lead, BNP Paribas

Chief Information Officer & Chief Information Security Officer, OTC Markets Group Inc.
#ISMGSummit
@ISMG_News
ISMG Summits offer Continuing Professional Education Credits. Learn informative and engaging content created specifically for security professionals.