Security teams are challenged to modernize application security practices in light of accelerating shifts to DevOps delivery models and rapid adoption of cloud-native application designs. Applications built on microservices (e.g. serverless, containers, APIs) and delivered continuously are outpacing application security teams ability to secure them. CISOs need to consider new skills, new touch points and new platforms to maintain a strong security posture in light of these trends and the speed at which they are re-shaping IT.
Application Security in a DevOps, Cloud and API World
CISO Council

Speakers
Karl Mattson
CISO
Noname Security
About Me
Deepak Chebbi
Director of Solution Architecture
AmerisourceBergen
About Me
Eric Staffin
Partner & SVP, CISO
IHS Markit
About Me
Eric has extensive leadership and practical C-suite experience working as a Chief Information Security Officer, Chief Risk Officer, and Risk Policy Committee Chair in regulated and non-regulated companies. He has a proven track record of building high-performance teams and partnering with both clients and colleagues to drive the recognition and treatment of franchise level strategic, cyber, privacy, operational, and regulatory compliance risks within interconnected global companies.
Eric currently serves as the Chief Information Security Officer (CISO) for IHS Markit (INFO), a $45 billion public company that is a global leader in information, analytics, and solutions for the major industries and markets that drive economies worldwide. He is charged with driving the design, implementation and continuous improvement of a global cybersecurity program that supports innovation as an enabler of business and revenue growth establishes a stronger enterprise-wide posture that reduces risk, improves decision-making, and accelerates business priorities, and, cost-effectively mitigates and reduces the risk and impact of the client, market and regional disruptions caused by physical, technology and cybersecurity-related incidents. Previously, Eric held senior leadership team roles at S&P Global (Chief Risk Officer, S&P Global Market Intelligence) and Thomson Reuters (Chief Resiliency and Business Information Security Officer, Wealth Management), and senior product, operational, and risk management roles at Citibank and Bankers Trust.
Eric received his Bachelor of Arts degree in Economics from the University of Michigan and his Master’s Degree in Business Administration in Finance and Management from New York University’s Stern School of Business. He is a co-Chair for the New York CISO Advisory Forum, holds the CISSP certification from (ISC)2, the FBCI (Fellow) certification from the Business Continuity Institute (BCI), and serves as a speaker, trainer, contributor, moderator, and panelist for (ISC)2, the BCI, DCRO, ISACA, and several New York metropolitan area business schools on topics including Operational Risk, Crisis & Incident Management, Data Privacy, Supply Chain Resiliency, and Cybersecurity and Business Resiliency Convergence.
Larry Whiteside
Co-Founder & President
Cyversity
About Me
Larry Whiteside Jr. is a veteran CISO, former USAF Officer, and thought leader in the Cybersecurity field. He has 25+ years’ experience in building and running cybersecurity programs, holding C Level Security executive roles in multiple industries including DoD, Federal Government, Financial Services, Healthcare, and Critical Infrastructure.
Larry currently serves as the Chief Technology Officer and Chief Security Officer at CyberClan, a full service Global Incident Response and Managed Security Services Provider for the small to medium sized business.
Larry is also the Co-Founder, President, and on the Board of Directors at the International Consortium of Minority Cybersecurity Professionals (ICMCP), a 501(c)3 non-profit association that is dedicated to increase the number of minorities and women in the cybersecurity career field through providing workforce development that includes skills assessment, training, education, mentorship, and opportunity.
Since 2009, via Whiteside Security, which he founded, Larry has advised several corporate security executives and companies across the cybersecurity industry on how to make Cyber Security a number one objective to their business. He has helped CEOs and board members of private cybersecurity companies achieve their goals in sales, marketing, and customer retention.
Larry has spoken in front of C Level leadership and Board of Directors of some of the largest private and public sector organizations in America. A thought leader in the industry with extensive experience presenting at conferences such as the Gartner Security Summit, RSA Conference, and SC World Congress, Larry has been featured in many articles relating to information security and risk management.
Larry received his Bachelor of Science degree in computer science at Huston-Tillotson University.
Kevin Morrison
Managing Director, CISO
Alaska Airlines
About Me
Deepak Uniyal
Head of Risk Domains
BNP Paribas
EVENT DETAILS
October 19, 2021
CouncilAgenda
3:00 PM-4:15 PM
Application Security in a DevOps, Cloud and API World
Panelists
Chair
Larry Whiteside
Co-Founder & President
Cyversity
Larry Whiteside Jr. is a veteran CISO, former USAF Officer, and thought leader in the Cybersecurity field. He has 25+ years’ experience in building and running cybersecurity programs, holding C Level Security executive roles in multiple industries including DoD, Federal Government, Financial Services, Healthcare, and Critical Infrastructure.
Larry currently serves as the Chief Technology Officer and Chief Security Officer at CyberClan, a full service Global Incident Response and Managed Security Services Provider for the small to medium sized business.
Larry is also the Co-Founder, President, and on the Board of Directors at the International Consortium of Minority Cybersecurity Professionals (ICMCP), a 501(c)3 non-profit association that is dedicated to increase the number of minorities and women in the cybersecurity career field through providing workforce development that includes skills assessment, training, education, mentorship, and opportunity.
Since 2009, via Whiteside Security, which he founded, Larry has advised several corporate security executives and companies across the cybersecurity industry on how to make Cyber Security a number one objective to their business. He has helped CEOs and board members of private cybersecurity companies achieve their goals in sales, marketing, and customer retention.
Larry has spoken in front of C Level leadership and Board of Directors of some of the largest private and public sector organizations in America. A thought leader in the industry with extensive experience presenting at conferences such as the Gartner Security Summit, RSA Conference, and SC World Congress, Larry has been featured in many articles relating to information security and risk management.
Larry received his Bachelor of Science degree in computer science at Huston-Tillotson University.
Speaker
Karl Mattson
CISO
Noname Security
Speaker
Deepak Chebbi
Director of Solution Architecture
AmerisourceBergen
Speaker
Eric Staffin
Partner & SVP, CISO
IHS Markit
Eric has extensive leadership and practical C-suite experience working as a Chief Information Security Officer, Chief Risk Officer, and Risk Policy Committee Chair in regulated and non-regulated companies. He has a proven track record of building high-performance teams and partnering with both clients and colleagues to drive the recognition and treatment of franchise level strategic, cyber, privacy, operational, and regulatory compliance risks within interconnected global companies.
Eric currently serves as the Chief Information Security Officer (CISO) for IHS Markit (INFO), a $45 billion public company that is a global leader in information, analytics, and solutions for the major industries and markets that drive economies worldwide. He is charged with driving the design, implementation and continuous improvement of a global cybersecurity program that supports innovation as an enabler of business and revenue growth establishes a stronger enterprise-wide posture that reduces risk, improves decision-making, and accelerates business priorities, and, cost-effectively mitigates and reduces the risk and impact of the client, market and regional disruptions caused by physical, technology and cybersecurity-related incidents. Previously, Eric held senior leadership team roles at S&P Global (Chief Risk Officer, S&P Global Market Intelligence) and Thomson Reuters (Chief Resiliency and Business Information Security Officer, Wealth Management), and senior product, operational, and risk management roles at Citibank and Bankers Trust.
Eric received his Bachelor of Arts degree in Economics from the University of Michigan and his Master’s Degree in Business Administration in Finance and Management from New York University’s Stern School of Business. He is a co-Chair for the New York CISO Advisory Forum, holds the CISSP certification from (ISC)2, the FBCI (Fellow) certification from the Business Continuity Institute (BCI), and serves as a speaker, trainer, contributor, moderator, and panelist for (ISC)2, the BCI, DCRO, ISACA, and several New York metropolitan area business schools on topics including Operational Risk, Crisis & Incident Management, Data Privacy, Supply Chain Resiliency, and Cybersecurity and Business Resiliency Convergence.
Speaker
Kevin Morrison
Managing Director, CISO
Alaska Airlines
Speaker
Deepak Uniyal
Head of Risk Domains
BNP Paribas