When: February 4, 2026 1300-1630
Where: Frontier RTP (In-person) / Teams (Remote)
Registration: Teams Registration Link
CPEs: Upto 3
Session 0 - Professional Development / Networking (1230-1300) [In person only]
Session I - Security Validation at the heart of CTEM (1300-1430)
Traditional security is failing due to the rising number of vulnerabilities and cybercrime costs.
• The shift from a vulnerability-centric to an exposure management approach is necessary.
• Exposure management is a continuous process to account for and reduce overall IT risk.
• Continuous Threat Exposure Management (CTEM) follows a five-step, prioritized program.
Speaker: Deb Brown, GTM Enterprise Strategist & Cybersecurity Revenue Leader, Pentera
Debra Brown brings over 25 years of experience working with large enterprise customers, specializing in cybersecurity and emerging technology solutions. Her journey in the cyber space began at Ping Identity, where she supported organizations in strengthening their identity and access management strategies. She later joined Chainalysis, where she played a pivotal role in building out the private sector business across the Americas. There, Debra partnered with major financial institutions and cryptocurrency exchanges to help them navigate the complexities of digital asset risk, compliance, and regulation.
In recent years, Debra has focused on supporting early-stage cybersecurity startups, helping them scale and meet the growing needs of enterprise clients. With a unique blend of strategic insight and frontline experience, Debra is passionate about helping organizations align security innovation with business objectives.
Session II - Proof of Personhood: AI, Deepfakes, and the Next Evolution of Digital Identity Verification (1445-1615)
As AI accelerates the creation of hyper-realistic deepfakes, synthetic voices, and automated impersonation bots, the question isn't just can you verify someone's identity…it is can you prove they're human at all?
This session dives into the rapidly expanding chasm between traditional identity verification methods (KYC, MFA, biometric scans) and the emerging threat landscape driven by generative AI. We'll explore how fraudsters are already bypassing outdated verification systems with low-cost AI tools. Enterprises, governments, and fintechs are rethinking how trust is established in digital interactions.
You'll get a look at the front lines of AI-driven identity verification: from liveness detection and behavioural biometrics to AI-trained identity graphs, multi-modal authentication, and zero-knowledge proof frameworks. We'll compare leading-edge solutions, assess where verification technology is failing in high-stakes use cases (banking, healthcare, government portals), and explore what the future of "personhood-as-a-service" might look like.
Speaker - Christine Dewhurst, Partner, NSC Tech & Shelly Jafry-Biggs
Christine Dewhurst is at the forefront of ushering in a new era of risk management, where governance, risk, and compliance evolve alongside artificial intelligence, automation, and advanced analytics. She is a sought-after speaker and thought leader, regularly presenting to executive, audit, risk, and security audiences on how emerging technologies are reshaping accountability, assurance, and decision-making. Christine actively champions the responsible integration of AI, automation, and statistical analysis into modern risk programs, helping organizations adapt governance models and assurance practices to keep pace with intelligent systems. She epitomizes the future of cyber leadership through blending deep technical expertise with a forward-looking, pragmatic approach that empowers organizations to manage risk in rapidly evolving environments.
With over 30 years of experience, Christine has held senior leadership roles at globally recognized organizations including KPMG, Deloitte, BMO, and Manulife, where she led complex transformation initiatives across business, technology, and cybersecurity. Her expertise spans cybersecurity assurance, identity and access management, vulnerability management, business resiliency, and enterprise risk, with a strong focus on aligning risk strategies to organizational outcomes.
Speaker - Shelly Jafry-Biggs
Shelly has over 30 years of financial industry expertise and risk analytics in banking systems. Shelly has provided leadership and achieved production goals through risk management experience in a broad range of credit topics, including loan underwriting (consumer and commercial), due diligence, appraisal review, portfolio analysis, loan loss modeling, organization of the credit department, development of credit policies and procedures, credit management reporting, and management of complex projects. Shelly has successfully developed over 12 data warehouses in large financial institutions. Her focus is to establish new relationships by growing our existing bank partnerships as well as developing risk analytics opportunities to support of our financial services teams.
Shelly’s expertise includes Allowance for lease and loan losses (Alll), BCBS 239, Credit Risk Analytics, Comprehensive Capital Analysis and Review (CCAR), Dodd Frank Stress Testing (DFAST), Commercial lending (Specialized lending/Wholesale) work flow, Enterprise Risk Management, Capital Markets Analytics, Risk Rating Models, Counterparty Risk and ad-hoc regulatory reporting.
Before joining 4M, Shelly worked for OneWest as senior officer of Credit Risk Analytics, where she implemented risk framework and achieved a successful regulatory audit as it related to risk management. Shelly has attended UClA Anderson Business School and lives in Southern California.
Session III (if time permits) - I Should Know That: APIs (45 minutes max!)
A review of the basic workings of Application Programmable Interfaces (API) following our recent presentation on their security vulnerabilities and solutions. I will illustrate the basic functionality of APIs, API gateways, and control points. I am starting a “I Should Know That” series of technical topics that I should know or remember. In this series, I will illustrate concepts important to audit and cybersecurity in plain English, with pictures, and no math
Speaker: John Fehan
John Fehan has helped clients in the consumer-packaged goods, financial, education, and healthcare industries improve and secure their IT infrastructure. He has worked in data centers, network operations centers, and aboard cruise ships under sail. He is a past Cisco Certified Internetworking Expert (CCIE) and a US Army veteran. He earned his Bachelors of Science in Electrical Engineering from Duke University.