Session

Speed vs. Security: Who Owns the Outcome When Everything Is on the Line?

Tech Theater 1

Starts: October 14, 2026 9:00 am
Ends: 10:00 am
Sponsored by
More info

Abstract:

Enterprise transformation is accelerating—but so is exposure. As organizations push for speed, scale, and innovation, the traditional boundaries between IT, cybersecurity, and the business are collapsing. The question is no longer whether CIOs and CISOs are aligned—it’s whether they can jointly deliver outcomes in an environment where the cost of failure is immediate and visible.

Boards are demanding growth and resilience at the same time. Business units are bypassing controls to move faster. Threat actors are exploiting complexity faster than organizations can reduce it. In this environment, hesitation creates risk—but so does unchecked acceleration.

This keynote panel brings together CIOs and CISOs who are operating in this tension every day. The conversation will confront the hard realities: where alignment breaks down, how accountability is shared (or avoided), and what it actually takes to lead when innovation and risk are on a collision course.

Panelists will share how they are making high-stakes decisions with incomplete information, redefining ownership between IT and security, and building organizations that can move fast without losing control. This is a candid discussion about trade-offs, consequences, and what leadership looks like when there is no margin for error.

Key Takeaways:

  • The Ownership Question: Who is accountable when speed introduces risk—and risk slows the business
  • Breaking the Alignment Myth: Where CIO–CISO alignment fails in practice and how to fix it
  • Risk in Real Time: Making defensible decisions when threats, technology, and business demands are all moving simultaneously
  • Control vs. Acceleration: How leading organizations are enabling speed without creating unacceptable exposure
  • The Cost of Complexity: Why modern environments increase both opportunity and vulnerability—and what to do about it
  • Leadership Under Pressure: Operating effectively when expectations are high and certainty is low

 

Speakers

Mario Villatoro

Chief Information Security Officer, Jamf

I bring over 15 years of global security leadership experience from Fortune 500 organizations, where I’ve successfully driven organizational improvements and excellence in security strategy, operations, product security, risk management, and compliance. My expertise includes a deep understanding of regulatory requirements and business acumen, with a focus on compliance frameworks such as FedRAMP, ISO, GDPR, and NIST. I hold a master’s degree in information security and several prestigious security certifications, positioning me to effectively navigate the complexities of today’s security landscape. I am passionate about leveraging my experience to foster robust security environments and support organizational goals.

Jake Hammock

Chief Information Security Officer & Assistant CTO, City of Seattle

For 15+ years I’ve led at the intersection of national security, enterprise and emerging tech, and civic infrastructure. After serving as a U.S. Army Military Intelligence and Cyber Warfare Officer with U.S. Cyber Command, and leading technical operations and R&D teams at the National Security Agency, I now serve as the Chief Information Security Officer & Assistant CTO of Security & Infrastructure for the City of Seattle. Along the way I’ve guided telecom, enterprise-SaaS, energy, and fintech organizations through zero-trust transformations, enterprise cloud migrations, development modernizations, and high-stakes incident response programs. What I’m known for: Strategic technical leadership | Built and mentored cross-functional teams of 150+ across defense, telecom, and city government; cut critical-vulnerability dwell time and vastly improved MTTR/MTTD. Regulatory mastery | Guided 90+ FedRAMP, HITRUST, PCI-DSS, SOX, GDPR, SOC 2, ISO 27001, and CMMC assessments, harmonizing control artifact repositories with automations to reduce assessment time. Innovation & IP | Inventor on multiple patents spanning distributed-ledger technologies, environmental systems, and telecommunication services; Leader in R&D to market readiness pathways, routinely translate emerging R&D into deployable safeguards. Enterprise resilience & governance | Re-architected disaster-recovery and business-continuity programs for global telecom and municipal networks, sustaining RTO/RPO target availability and protecting multimillion-dollar enabling infrastructure. Current civic focus: Post-quantum readiness | Researching lattice-based cryptography and hybrid QKD overlays to future-proof critical data processing and control systems. Trusted & responsible AI | Operationalizing secure generative-AI services that align with NIST AI Risk Management Framework and ISO 42001, and map to MITRE ATLAS while enforcing data-sovereignty and security controls city-wide. Public-private cyber coalitions | Convening government CISOs, utilities, tech vendors, and regional agencies to create a unified threat-intelligence and incident-coordination framework that boosts community resilience. Digital equity & secure modernization | Driving cloud migrations, fiber consortiums, broadband expansion, and smart-city initiatives that deliver inclusive services without compromising security or privacy.

Thanh Thai

VP & Chief Information Security Officer, Constellis

Developed, implemented and optimized a comprehensive information security strategy aligned with organizational objectives, security frameworks, and policies. Led the development and maintenance of the organization's security architecture, ensuring alignment with customer needs, regulatory requirements, and industry best practices. Assessed and managed security risks associated with third-party vendors and partners, establishing and maintaining contracts, service-level agreements, and ongoing vendor performance evaluations. Prepared Board of Director level reports, delivered presentations, and provided recommendations to executive management, collaborating with stakeholders to develop strategic initiatives. • Spearheaded vendor management contract negotiations, optimizing service delivery, eliminate low value & redundant solutions; reducing costs by 25%, while maintaining a robust security program. • Represented the organization's security posture during contract negotiation with federal & state agencies and commercial customers. • Ensured adherence to local, state and federal regulatory compliance, implementing frameworks such as GDPR, CCPA, Cyber Essentials Plus, CMMC and NIST CSF to bolster the organization's compliance requirements. • Cultivated strong relationships with stakeholders across the organization, utilizing excellent interpersonal skills to influence decisions and drive collaborative efforts of shared objectives. • Communicated complex cybersecurity concepts to diverse audiences, including executive leadership and technical teams, fostering a culture of security awareness across the organization. • Managed a multi-million dollar budget for cybersecurity initiatives, demonstrating expertise in financial planning, workforce management and ensuring optimal resource allocation.