Session

Cutting Through the Noise—Defining Cyber Risk Priorities in a High-Threat Landscape
CISO Roundtable Panel

VIP Theater

Starts: April 16, 2026 1:00 pm
Ends: 2:00 pm
Sponsored by
More info

Cutting Through the Noise—Defining Cyber Risk Priorities in a High-Threat Landscape

Abstract
In today’s relentless threat environment, CISOs are inundated with signals—new vulnerabilities, evolving attack vectors, regulatory pressure, and constant vendor noise—all competing for attention and investment. The challenge is no longer awareness, but prioritization. This panel brings together security leaders to cut through the complexity and focus on what truly matters: aligning cyber risk with business impact, making defensible decisions under uncertainty, and driving measurable security outcomes. Panelists will share how they are filtering noise, communicating risk to the board, and focusing resources on the controls and strategies that reduce real-world exposure—not just theoretical risk. Expect a candid discussion on what’s working, what’s not, and how leading organizations are redefining cyber priorities in a high-threat, high-stakes landscape.

Key Takeaways

  • Frameworks for prioritizing cyber risk based on business impact, not volume of threats
  • How CISOs are effectively communicating risk and tradeoffs to boards and executive teams
  • Practical approaches to cutting through vendor and tool sprawl
  • Where leading organizations are focusing investments for maximum risk reduction
  • Balancing proactive defense with detection and response in a resource-constrained environment
  • Lessons learned from real-world incidents and evolving threat trends
  • Strategies for aligning cybersecurity priorities with enterprise resilience and business objectives

 

Host

Kathleen Mullin

Former CISO, American Cancer Treatment Centers of America & Founder, My Virtual CISO

Kathleen Mullin is an influential information security practitioner and international speaker with over twenty-five years of experience. She has been CISO or CIO|CISO at various organizations, focusing primarily on healthcare in the hospital, financial, insurance, and cloud-based services. She started her career in Accounting and Internal Audit before moving into Information Technology and Cybersecurity. Throughout her career, Kate has volunteered and contributed to information security as a profession, including serving on multiple board and advisory positions. Currently she is a Board member of the SABSA Institute (TSI), Deputy Chair of TSI EMEA Liaison Group and Treasurer of West Florida ISACA. She holds a BSBA from St Joseph’s College, Maine, an MBA from Florida Metropolitan University and her current credentials include CISSP, CDPSE, SABSA SCF, and NACD.DC.

Speakers

Derek Stephenson

Chief Information Security Officer, Mural

Derek Stephenson is the Chief Information Security Officer and VP of IT at Mural, where he leads the Security, Compliance, and IT teams. He holds extensive expertise in risk management, compliance, and technology strategy from a career in highly regulated B2B and B2C industries such as 911 Emergency Services, Gaming & Casino, and SaaS. His unique perspective, shaped by experience as both a buyer and provider of enterprise technology solutions, enables him to drive product strategy that resonates with CIOs and CISOs. His collaborative approach balances risk management, technology investments, and product influence to exceed business and customer expectations.

Bruce W. Beam

Chief Information Security Officer, Galway Holdings

At Galway Holdings, leading the charge in cybersecurity has been a thrilling journey where I have fortified the digital framework of a dynamic, rapidly evolving enterprise. My role as Chief Information Security Officer has allowed me to harness my expertise in cybersecurity, and cyber defense to advance compliance and safeguard our many subsidiaries. My strategic approach weaves together a robust security posture with business acumen, focusing on cost-effectiveness and risk management to support long-term growth. Driving innovation within our security practices, my leadership is not just about defense but also about empowering a culture of resilience and accountability, which is essential for our continuous success in this digital age.

Michael Rogers

Chief Information Security Officer, Markmonitor Group

Michael Rogers is Chief Information Security Officer at Markmonitor Group, the world's best known corporate domain registrar and a global expert in domain portfolio management and online brand protection. He leads the company's information security program, setting security strategy, driving internal risk posture, and partnering with product leadership to shape a security-driven product strategy that solves real problems for clients. Michael brings 16 years of cybersecurity experience, including more than 100 incident response engagements across nearly every industry, much of it on the front lines negotiating, investigating, and recovering from breaches in real time. That experience was built at a leading incident response firm, where he served as Managing Director of Resilience Advisory, advising executive teams on crisis readiness and board-level risk communication. Before that, he spent nearly eight years at a global leader in security operations, where he built and scaled the company's SOC from 2 to more than 50 analysts and engineers in support of some of the world's largest enterprises. Beyond Markmonitor Group, Michael is an active voice in the security community. He chairs BSides Tampa and leads the ISC2 Tampa Bay Chapter, and has spoken from stages including RSA, SANS Institute, ISC2, BSides, NetDiligence, and Fal.Con, with his work published in Dark Reading.