25th Annual Vancouver International Privacy & Security Summit
Data Protection & Privacy in a Data-Driven World
February 22-24, 2023, Vancouver, BC

General Information


Presenting the 25th Annual Vancouver International Privacy & Security Summit at the Westin Bayshore Hotel.  This fully in-person summit will offer a platform for 750 security and privacy professionals from around the world to discuss important issues on how we securely live, work, and play as the move to digital platforms accelerates.

Presented by Reboot Communications in partnership with ISACA Vancouver, this three-day summit will provide valuable education and training opportunities for individuals who are responsible for the transformation of the public and private sector into the new digital economy.

We are proud to announce that delegates within local government and professionals in the industry can obtain CPD/CPE credits through our accreditation with:

🛡️The BC Law Society
🛡️ISACA Vancouver
🛡️(ISC)2
🛡️Chartered Professional Accountants of Canada

We acknowledge that gaining approval to attend training conferences can be challenging. As support in your continued privacy and security education, please click here for a sample Justification letter you can customize to build your case in attending. Once you click on the link, select “File” in the upper left corner, and download to edit.

Registration Information

February 22nd – Educational & Training Workshops (Westin Bayshore Hotel) – Only 325 Seats available for these sessions!
February 23rd-24th – VIPSS Summit (Westin Bayshore Hotel)

 

Early Bird Rates (until Dec.31st)

Admission Type Public Sector Private Sector
VIPSS Summit & Educational Training Day $795.00 CAD (plus GST)
$1,145.00 CAD (plus GST)
   
VIPSS Summit Only $500.00 CAD (plus GST) $850.00 CAD (plus GST)
   
Educational Training Day Only $495.00 CAD (plus GST)
$750.00 CAD (plus GST)
   
       

Standard Rates (after Dec.31st)

Admission Type Public Sector Private Sector
VIPSS Summit & Educational Training Day $945.00 CAD (plus GST) $1,290.00 CAD (plus GST)    
VIPSS Summit Only $650.00 CAD (plus GST) $995.00 CAD (plus GST)    
Educational Training Day Only $495.00 CAD (plus GST)
$750.00 CAD (plus GST)
   
       

Registration Includes*:

  • Join us live in Vancouver, B.C for our 2-day summit (February 23-24) – option to include the Educational Training & Workshop Day on February 22nd (valued at $750).
  • Collaborate with senior executives who are changing the privacy & security industry
  • Signature keynotes and concurrent keynotes by international subject matter experts in privacy & security
  • Concurrent panel sessions + interactive in-person Q & A
  • Unparalleled in-person networking via 1:1 meetings and small group conversations
  • Exhibit booths for our top tier sponsors
  • Lunch and coffee breaks (Feb.22-24th)
*Subject to provincial guidelines (masks are currently optional).


Social Media

Stay connected and engaged in the conversation leading up to and during the summit by following along on Twitter @VIPSSummit. Use the event hashtag #VIPSS in your tweets to add to the existing discussions. We would appreciate you sharing your voice with our other followers.

www.vipss.ca

 

 

Keynote Speakers

Evan Anderson

Principal Technologist and Co-founder, Randori

Nikolas Badminton

FRSA; Chief Futurist, Futurist.com

Hansang Bae

Public Sector Chief Technologist, Zscaler

Micki Boland

Cloud Security Architect, Check Point Evangelist

Dan Deganutti

Senior Vice President - Canada, BeyondTrust

Philippe Dufresne

Privacy Commissioner of Canada

Justin Foster

Chief Technology Officer, Forescout

Jason Grimbeek

Chief Executive Officer, Iron Spear

Trey Guinn

Field Chief Technology Officer, Cloudflare

Mani Keerthi Nagothu

Technology Strategist, SentinelOne

Andrew Kirsch

Former Intelligence Officer, CSIS; Founder, Kirsch Group

Derek Manky

Chief Security Strategist & VP Global Threat Intelligence, FortiGuard Labs

Jason Maynard

Field CTO, Cybersecurity, Cisco Canada

Dr. Mike McCleary

PMM Security Services, Arctic Wolf

Antoine Saikaley

Technical Director, Trend Micro Canada

Winn Schwartau

FRSA, Fellow, Royal Society of the Arts; Security Theoretician

Dev Sharma

Senior Manager, Solution Engineering, Virtual Cloud Network, VMware

Aaron Steele

Director of Cybersecurity Products and Services, TELUS

John Weigelt

National Technology Officer, Microsoft Canada

Dale "Dr. Z" Zabriskie

Field CISO, Cohesity

Speakers

Aida P. Abraha

Workplace Lawyer and Data Rights Specialist, Abraha Law

Martin Abrams

Chief Policy Innovation Officer, Information Accountability Foundation

Jeannine Adams

Founder & CEO, s01ve Cyber Solutions

James Armstrong

Senior Vice President & CISO, Shaw Communications

Brent J. Arnold

Partner, Data Breach Coach, Gowling WLG (Canada) LLP

Hansang Bae

Public Sector Chief Technologist, Zscaler

Katherine Benjamin

Chief Digital Officer, Head of Enterprise Digital Credentials, Government of Canada

Dr. Colin Bennett

Professor, Department of Political Science, University of Victoria

Connor Bildfell

Litigator, McCarthy Tetrault LLP

Ben Blakely

National Leader, Security Strategy & Risk, IBM

Kelly Brickley

VP, Global Protect Fusion, TD

Sergey Bukharov

Chief Customer Officer, SkyHive

Dr. Gregory Carpenter

Chief Security Officer, Knowledge Bridge International

Rachael Conover

Lead Intelligence Analyst, Mastercard Fusion Center

Daniel Couillard

Director General of Partnerships and Risk Mitigation, Canadian Centre for Cyber Security

Rob Davidson

Director of Security Services, CISO, Pacific Blue Cross

Valerio De Stefano

Canada Research Chair in Innovation, Law and Society, Osgoode Hall Law School, York University

Elizabeth Denham

Former UK Information Commissioner

Claire Feltrin

Lawyer, Data Privacy & Cybersecurity Group, Deloitte Legal Canada LLP

Cameron Field

Vice President, VIDOCQ

Michelle Finneran Dennedy

CEO, PrivacyCode

Dr. Richard Frank

Associate Professor, School of Criminology, SFU; Director, International CyberCrime Research Centre

Dr. Robert Fraser

President and CEO, Molecular You

Aarti Gadhia

Board Advisor, WiCyS Western Canada Affiliate; Principal Security Specialist, Microsoft

Michelle Gallant

Law Professor, University of Manitoba

Andrew Geider

Freedom of Information Specialist, City of Burnaby

Rob Goehring

Founder & CEO, Wisr AI; Founding Director, Chief Executive Council on AI, BC Technology Association

Bob Gordon

Executive Director, Canadian Cyber Threat Exchange (CCTX)

Robin Gould-Soil

President, RGS Management Consulting Services; CPO, Pentavere

Gail Hodges

Executive Director, OpenID

Gaétan Houle

CISO Advisor, Cisco

John Jacobson

Former Deputy Minister, Ministry of Technology, Innovation and Citizens’ Services

Sunny Jassal

Director, Cyber Security, British Columbia Institute of Technology

Koleya Karringten

Co-Founder and CEO, Absolute Combustion; Executive Director, Canadian Blockchain Consortium

Derek Keen

Manager of Sales Engineering, Varonis

Tahir Latif

Global Practice Lead, Data Responsibility & Privacy, Cognizant

Brian Lenahan

Founder & Chair, Quantum Strategy Institute

Christian Leuprecht

Class of 1965 Professor in Leadership, Royal Military College and Queen’s University

Jaime Lewis-Gross

Vice President, Solutions Engineering and Strategy, Saviynt

Jay Loder

Privacy Officer, FortisBC

Penny Longman

Director, Information Security and Data Stewardship, Fraser Health

David Loukidelis, QC

Privacy Consultant, former BC Information and Privacy Commissioner

Dr. Alan Low

Clinical Associate Professor, Faculty of Pharmaceutical Sciences, UBC; Exec. Director, MedAccess BC; Primary Care Pharmacist & Pharmacy Lead, BioPro Biologics Pharmacy

Paul Lucier

Chief Revenue Officer and Senior Sales and Business Development Executive, Crypto4A Technologies

Quinn Mah

Executive Director - Information Management, Alberta Health

Amanda Maltby

General Manager, Compliance and Chief Privacy Officer, Canada Post Corporation

Derek Manky

Chief Security Strategist & VP Global Threat Intelligence, FortiGuard Labs

Florian Martin-Bariteau

Associate Professor and University Research Chair in Technology and Society, University of Ottawa

Drew McArthur

Principal, The McArthur Consulting Group

Michael McEvoy

Information and Privacy Commissioner for British Columbia

Hardeep Mehrotara

Director, Information Security, Concert Properties

Dr. Bessma Momani

Senior Fellow, Centre for International Governance and Innovation (CIGI); Professor, University of Waterloo

Suzanne Morin

VP, Enterprise Conduct, Data Ethics & Chief Privacy Officer, Sun Life

Masarah Paquet-Clouston

Assistant Professor in Criminology, University of Montreal

Ruth Promislow

Partner, Co-Head of Privacy, Data Management and Cybersecurity Group, Bennett Jones LLP

Jennifer Quaid

Executive Director ,Canadian Cyber Threat Exchange (CCTX)

Dr. Walid Rjaibi

CTO & Distinguished Engineer, Data Security, IBM Security

Dr. Teresa Scassa

Canada Research Chair in Information Law and Policy, University of Ottawa

Kim Schreader

Director, Cybersecurity Professional Services, TELUS

Pam Simpson

Senior Information Security Analyst, TD Bank

Ayman Siraj

Lead Investigator, Microsoft Detection & Response Team (DART)

Jo-Ann Smith

CISO & Privacy Officer, Long View

Pamela Snively

VP, Chief Data & Trust Officer, TELUS

Aaron Stevens

Data Privacy Evangelist, Anonos

Scott Taylor

VP & Chief Privacy Officer, Merck Global Privacy Office

Po Tea-Duncan

Executive Director, Cyber Security, Treasury Board of Canada Secretariat

Sybila Valdivieso

Executive Director, Information Access Privacy and Technology Development Office, Provincial Health Services Authority

Jeannette Van Den Bulk

Deputy Commissioner, Policy, Adjudication, and Audit, Office of the Information and Privacy Commissioner for British Columbia

John Wunderlich

Senior Advisor, The Privacy Pro
Print Agenda

*Invited Speaker

Click on the date of the agenda you would like to view. Please note the timezone listed on the agenda.

Wednesday, February 22, 2023

9:00 - 9:15am PST Salon ABC

Opening Remarks

9:15 - 10:30am PST Salon ABC

Session 1 - Panel: Fusion Centre Model Panel Sessions: Accelerating convergence underway between cybersecurity, fraud and anti-money laundering.

It is needless to say due to yesterday’s silos between cybersecurity, fraud and anti-money laundering, detection of cybersecurity related fraud requires a special multi-disciplinary and innovative playbook built on convergence of the silos in order to establish a clear strategic enterprise vision. This vision and fusion is tomorrow’s fusion centre model - future ready and resilient!

10:30 - 10:45am PST Grand Ballroom Foyer

Morning Break

10:45 - 12:00pm PST Salon ABC

Session 2 - Workshop: Fusion Centre Model Workshop - Foundation for Developing a Fusion Centre

Starting with a foundational understanding of fusion centres and the fusion process, this workshop will provide a summary of fusion centre guidelines, key elements and provide the attendee with the knowledge and resources to develop a fusion centre model within their own organization. The multi-disciplinary integration of people, systems and technology for seamless communication and collaboration.

12:00 - 1:00pm PST Salon ABC

Lunch Break

1:00 - 2:00pm PST Salon ABC

Session 3 - Emerging Trends: The Art & Science of Metawar

The Fundamentals of Metawar
Metawar is the art of applying science to create alternate realities, so immersive, as to be indistinguishable from our ‘default’ reality; the one we have been born into. When technology can do that, we will have reached the meta point, from which there may well be no escape.

2:00 - 3:00pm PST Salon ABC

Session 4 - Panel: Emerging Issues in Workplace Privacy Law: Understanding Data Collection, Electronic Monitoring, and Employee Data Privacy Rights.

This panel brings together privacy, labour, and human rights law experts to examine the state of workplace privacy law in Canada. It will identify emerging privacy issues related to workplace electronic monitoring and other forms of algorithmic management systems. It will also discuss the challenges and pressure points and assess the adequacy of existing employee privacy rights laws. Further, it will discuss recent initiatives undertaken in Canada and abroad to regulate workplace electronic monitoring and AI tools.

3:00 - 3:15pm PST Grand Ballroom Foyer

Afternoon Break

3:15 - 3:45pm PST Salon ABC

Session 5 - Data Privacy, Higher Education - Why Should We Care?

Today’s student’s attitudes toward data privacy will shape the policies and practices that govern the internet. As such, society needs to better understand college student attitudes, expectations, and behaviors regarding data privacy, and take a more active role in shaping behaviours. Universities must demonstrate transparency to marginalized students (LGBQ, undocumented immigrants, and people of colour) to ensure students gain the trust of higher educational institutions.

As students have become more aware of this ongoing data collection and use, they have begun to express their concerns and desires to limit the use of their data to guide institutional decision making. Recommendations will address the collection and use of personal data, and how to gain student’s trust in managing their private information.

Practical Takeaways:
•Higher education institutions must teach data privacy, ethics, and digital literacy courses to encourage college students to think critically about data privacy.
•To foster trust and cooperation, higher education institutions and technology companies must communicate how and why they collect, use, and share students’ personal information.
•Researchers must conduct further studies on college students’ attitudes, expectations, and behaviors regarding data privacy.

3:45 - 4:25pm PST Salon ABC

Session 6 - Business Strategies for Compliance: Utilizing Synthetic Data, Pseudonymization, and Other Privacy Enhancing Techniques to Meet Emerging De-identification Requirements

Bill C27, Bill 64, and EU and US laws are all introducing concepts of de-identification and anonymization, and in different ways. What is this all about and how do you navigate leveraging these tools to enable the rich uses of data? From a safeguarding perspective, how can you use de-identification and anonymization to reduce the risk that your organization's PI isn’t getting out from internal or external sources?

The panel will be looking at the evolution of legislation to the current and anticipated legislation and talking about how technology can enable the enterprise. Technologies like anonymization, tokenization, pseudonymization, and even synthetic data. How to use it, why to use it, and the best applications or use cases for which solution.

By making the data more useful by removing the “identifiable” part of PI, you can help your business -- and even possibly create some ROI from a cost center that classically isn’t a revenue-producing entity, all while doing the right thing.

Takeaways:
1. Examples of de-identification and anonymization under the law
2. Practical uses of de-identification and anonymization
3. Building a business case

4:25 - 4:30pm Salon ABC

Closing Remarks

5:30 - 7:30pm PST

Networking Event @ BCIT Tech Collider

BCIT Tech Collider - 555 Seymour Street, 2nd Floor - Industry networking event.
Light refreshments served.
*Event is included with your training day.

The BCIT Downtown Campus Tech Collider is a new initiative. Dually inspired by a modern sound stage and a Star Trek bridge, the Tech Collider is outfitted with state-of-the-art technology including an immersive gesture-controlled screen to digitized windows. The BCIT Tech Collider will become the central location for industry events and student learning in Vancouver.

Thursday, February 23, 2023

8:15 - 8:20am PST Bayshore Grand Ballroom

Call to Conference & Territorial Acknowledgement

8:20 - 8:40am PST Bayshore Grand Ballroom

Opening Keynote

8:40 - 9:20am PST Bayshore Grand Ballroom

Session 1 - Keynote: Facing our Futures - 5 themes for the next 10 years

2023 has started and the world not only feels different, it feels more uncertain than ever. This is the territory of futurists, social activists, technologists and policy makers. It’s time for us to step up. Nikolas Badminton will explore 5 themes that will shape the thinking about how we plan for our futures together - Geopolitics, Permacrises, Simulation, Utopia, and Longtermism.

9:20 - 10:05am PST Bayshore Grand Ballroom

Session 2 - Keynote by Microsoft

10:05 - 10:35am PST Grand Ballroom Foyer

Morning Break

10:35 - 11:35am PST Salon ABC

Session 3 - Concurrent Panel A: Big Data, Big Complexity, Big Healthcare – Security Challenges and Opportunities. Why is Healthcare Such a Target?

Medical information can be worth up to ten times more than any credit card information stolen on the internet. Large amounts of patient data are stolen every year. Data breaches cost millions, take months to resolve and put patient lives in jeopardy. Healthcare boards and executives need to recognize the duty of case issues and provide dedicated funding as cyber incidents are impacting patient welfare and in some cases putting their lives at risk.

10:35 - 11:35am PST Salon EF

Session 3 - Concurrent Panel B: CISO Discussion on Trending Risks in Cybersecurity (Board Oversight)

With the global situation resulting from the COVID-19 pandemic, increase in state sponsored attacks, and recent financial pressures on companies, the oversight provided by Boards on cyber security is becoming critical. This session will focus on the recent increasing risks and trends in Cybersecurity such as supply chain risks, zero-day vulnerabilities, and rise in ransomware.

Communicating these key concerns, risk and priorities to the Board can be tricky hence this session will discuss:
-Key mechanisms to present information to the board.
-Approaches and techniques to get board buy-in.
-Challenges and approaches on Cyber insurance
-Mechanisms used by organizations to address the constant evolving threat.

10:35 - 11:35am PST Salon D

Session 3 - Concurrent Panel C: International Data Flows

A global privacy accord to facilitate data flows would truly make everyone’s life easier. While Canada is adequate under the EU GDPR there are numerous other countries with adequacy requirements. Furthermore, countries are seeing data as national assets, and enacting data localization rules as a “privacy protection.” Elizabeth Denham, former UK ICO and BC Information Commissioner has led a G7 process to develop such an accord. Should we be optimistic, or are all the political and cultural impediments a barrier? Join this session to find out.

11:40 - 12:10pm PST Salon ABC

Session 4A - Concurrent Keynote by Cisco: Advanced Persistent Defenders (APD)!

In this session we discuss the Pyramid of Pain and review each element from an defender and adversarial perspective showcasing the value of defending at the Tactic, Technique, and Procedure level.

We will then shift into Mitre Att&ck and intelligent based defense by understanding frameworks and Mitre Att&ck.

11:40 - 12:10pm PST Salon EF

Session 4B - Concurrent Keynote by Cloudflare: The (Hard) Key to Stop Phishing: How Cloudflare Stopped a Targeted Attack and You Can Too

In July 2022, Cloudflare was targeted in a sophisticated SMS phishing scheme in such a way that we believe most organizations would be likely to be breached. In this session we’ll detail the recent targeted phishing attack we saw at Cloudflare and more importantly, how we stopped it and steps you can take to protect your organization as well. We’ll cover topics like: why not all MFA is created equally, the role of Zero trust network access in rolling out strong authentication, and the importance of a blame-free culture around security.

11:40 - 12:10pm PST Salon D

Session 4C - Concurrent Keynote by SentinelOne: Debunking Common Myths About XDR

There has been a tremendous buzz across the cybersecurity community about the emerging technology known as XDR (eXtended Detection & Response).

Unfortunately for the practitioner, there has yet to be a single definition widely accepted by both analysts and vendors perporting to be knowledgeable on the subject.

What is XDR and why should I consider the technology in my enterprise security stack? What should I expect from vendors who claim to have built the perfect mousetrap? What is reality, and what is just hype?

This session is intended to walk the audience through some generally accepted value statements associated with XDR while attempting to debunk a few common myths that continue to muddy the water for security teams.

12:10 - 1:15pm PST Bayshore Grand Ballroom

Lunch Break (Please visit the exhibit booths)

1:15 - 1:45pm PST Salon ABC

Session 5A - Concurrent Keynote: Out of the Shadows: An Inside Look at Canada’s Spy Service

This session will take an inside look at what Canada’s spy service does and why it’s important you know more about it.

1:15 - 1:45pm PST Salon EF

Session 5B - Concurrent Keynote by Thales

1:15 - 1:45pm PST Salon D

Session 5C - Concurrent Keynote by Cohesity

1:50 - 2:20pm PST Salon ABC

Session 6A - Concurrent Keynote by Fortinet: Disrupting Advanced Persistent Cybercrime

APT and Cybercriminal organizations are converging with shared infrastructure, resources and targets within both the public and private sector. This talk will show some examples of the Advanced Persistent Cybercrime phenomenon, and also discuss a holistic approach to disruption highlighting industry effort underway.

1:50 - 2:20pm PST Salon EF

Session 6B - Concurrent Keynote by Arctic Wolf: Security Operations in the Age of Cybercrime

Cybercrime is big business and attackers have evolved. Today, cybercrime has become a $1.5 Trillion dollar industry and that number is increasing. The barriers for attacks have been lowered, and the rewards have never been higher. So, who are these cybercriminals and how does an organization protect itself? Our discussion will focus on the common motives and methods of cybercriminal groups along with strategies on how to develop an effective security operations program to safeguard your environment.

1:50 - 2:20pm PST Salon D

Session 6C - Concurrent Keynote by Iron Spear: Cyber Security is Now an Essential Part of Environmental, Social and Governance (ESG) Factors

Institutional investors, business partners and suppliers are all looking to an organization’s ESG practices to ensure they align with their own. Cyber security is fast becoming a key component in ESG as it is a concern up and down the supply chain and companies who are not managing it effectively are being seen as a potential investment risk.

This talk will address why cyber security should be part of your organization’s ESG strategy and give you the non-technical approach to ensuring your cyber program meets the demands of social expectations.

2:20 - 2:50pm PST Grand Ballroom Foyer

Afternoon Break

2:50 - 3:50pm PST Salon ABC

Session 7A - Concurrent Panel: Geopolitics: Analyzing the Threats and Opportunities Shaping Global Security

Geopolitics has been playing out through the Internet for years, but the intensity, diversity and impact of this activity is escalating. Formerly the domain of diplomats, operating in hallowed halls using precise language, today statecraft is executed over the Internet by intelligence arms of governments and their proxies such as cyber criminals. The use of proxies and the Internet provide governments a veil of plausible deniability for its actions including theft of intellectual property, sowing disinformation to reduce trust in government institutions, degrading the delivery of essential goods and services. During periods of conflict, the impact of this activity extends beyond the confidentiality, integrity, and availability of data; real world events are impacted.

This panel will examine how geopolitics are shaping the global threat environment, who are the players, and the strategic roles for both private and public sectors in mitigating this threat.

2:50 - 3:50pm PST Salon EF

Session 7B - Concurrent Panel: The Future of Privacy Law in Canada

Bill C-27, also known as the Digital Charter Implementation Act, contains three separate statutes: the Consumer Privacy Protection Act (CPPA), the Personal Information and Data Tribunal Act and the Artificial Intelligence and Data Act. It is now at a critical stage in its parliamentary passage. This panel will focus mainly on the CPPA. Does it “modernize” Canada’s privacy sector privacy legislation, as the government claims? Is it consistent with contemporary international privacy standards? Will it strengthen consumer rights in the face of the enormous power of global internet companies? Does it provide the kind of clarity that Canadian business expects?

2:50 - 3:50pm PST Salon D

Session 7C - Concurrent Panel: Artificial Intelligence & Machine Learning: Why Artificial Intelligence Must Prioritize Data Privacy

Artificial intelligence (AI) and machine learning have the potential to transform many aspects of our lives, from healthcare and transportation to education and finance. However, the increasing use of AI also raises important questions about data privacy. In this panel session, we will discuss why AI must prioritize data privacy, and explore the ways in which AI systems can be designed and used in a responsible and ethical manner. We will examine the potential risks and consequences of data collection and usage, and discuss strategies for protecting personal information and preventing discrimination. This panel will provide insights and guidance for individuals, organizations, and policy makers looking to understand and address the complex issues related to AI and data privacy.

4:00 - 4:40pm PST Bayshore Grand Ballroom

Session 8 - Keynote by TELUS: Cloud Security Expectations vs. Reality: Insights from the TELUS Canadian Cloud Security Study

Is cloud security meeting the expectations of Canadian organizations? Join Aaron Steele, Director of Cybersecurity at TELUS, as he shares insights from the soon-to-be-published TELUS Canadian Cloud Security Study that answer this question.

Based on the feedback of over 500 Canadian organizations, the study explores the current state of cloud adoption and security in Canada, discusses the challenges organizations are facing with security in the cloud, and examines how organizations are detecting and responding to cloud security incidents.

4:40 - 4:50pm PST Bayshore Grand Ballroom

Day 1 Closing Remarks

4:50 - 5:00pm PST Bayshore Grand Ballroom

Message from our Founding Sponsor ISACA

Friday, February 24, 2023

8:15 - 8:20am PST Bayshore Grand Ballroom

Administrative Announcements

8:20 - 8:50am PST Bayshore Grand Ballroom

Session 9 - Keynote Address

8:55 - 9:35am PST Bayshore Grand Ballroom

Session 10 - Keynote Address by IBM: Embedding the Attacker’s Perspective

9:40 - 10:20am PST Bayshore Grand Ballroom

Session 11 - Keynote Address by Zscaler: Zero Trust Deconstructed and Why It’s a Lie

Today’s cyber protection must expect and account for zero day vulnerabilities. As history proves, if you’re reachable, you’re breachable and in that world, network-based solutions come up lacking – after all, it’s a network not a security blanket. The key to zero trust means that before any connection is made from the user to an application, the identity and transaction must have been vetted. In addition, the application must never accept connections to unknown users. This allows authorized users to continue to operate even if parts of the network are compromised. In effect, Zero Trust maintains the chain of custody over every user, every transaction, and every app. Thereby verifying the identity and context, controlling the risk, and enforcing policy at scale. A true zero trust solution must be able to disaggregate the user and the application from the network without requiring modification to the existing network infrastructure. Zero Trust implemented at the user and application level is the only way to achieve the Dynamic Need to Know concept: removing or adding privileges in Realtime to protect users and applications from threats. In this session, you will understand:
-Why you can never have true Zero Trust,
-Why Zero Trust can never be implemented using the network – with packet proof, and
-The practical advice on rolling out Zero Trust for the biggest bang for the buck.

10:20 - 10:50am PST Grand Ballroom Foyer

Morning Break

10:50 - 11:50am PST Salon ABC

Session 12A - Concurrent Panel: Quantum Computing: The Good, the Bad and the Ugly. Is Quantum Computing One of the Most Serious Threats to Cybersecurity or Might it be the Solution to a More Secure Internet?

Quantum threats refer to the capabilities of true quantum computers that would allow for the hacking of mass quantities of encrypted data including essentially everything sent on the internet.. The future of the internet relies on Quantum research and is so important its drawing new federal funding. Quantum computing could be one of the most serious threats to cybersecurity but it might also be the solution to a more secure internet. The quantum internet could safeguard financial transactions and healthcare data, prevent identity theft and stop hostile state hackers in their tracks.

10:50 - 11:50am PST Salon EF

Session 12B - Concurrent Panel: Digital ID Platforms for Public Services – “Trust but Verify”

Some might argue that the pandemic has strengthened the case for digital ID cards. They could make it quicker and easier for us to access government services but also could make pandemic track-and-trace systems more effective. For example, if health data were linked to work data, governments might more quickly spot clusters of COVID cases.

What about privacy and security? Can privacy be protected by existing data-protection laws and updated security safeguards, such as two-factor authentication? How could we guard against ID cards being required for other purposes, such as law enforcement?

In addition, creating a digital ID system is complex and expensive. Can digital ID systems be introduced gradually building on existing platforms? What about public trust? If they are reasonably safe, and add convenience for interacting with governments, will citizens sign up for them?

10:50 - 11:50am PST Salon D

Session 12C - Concurrent Panel: Financial Cyber Crimes: The Illicit Uses of Cryptocurrency - Does this Lead to Money Laundering?

New decentralized finance technologies represent a great opportunity for [cyber]theft and money laundering. This panel will discuss how and to what extent cryptocurrencies and their related products, such as NFTs or decentralized derivatives (loans, options, future contracts), are used for illicit purposes. How these uses represent a challenge for law enforcement agencies, policymakers, and anti-money laundering officers in private organizations will also be discussed.

11:55 - 12:25pm PST Salon ABC

Session 13A - Concurrent Keynote by BeyondTrust

11:55 - 12:25pm PST Salon EF

Session 13B - Concurrent Keynote by Forescout: How to Protect Assets by Balancing Proactive Risk with Reactive Threat

Too many security programs focus on layers of compensating controls without understanding the full perspective. Cyber security starts with an understanding of the assets under your control. You then need to balance resource between a proactive approach to exposure management, with the reactive approach to threats facing your environment. Join us to look at creating a holistic and balanced approach to cyber security.

11:55 - 12:25pm PST Salon D

Session 13C - Concurrent Keynote by ServiceNow

12:25 - 1:30pm PST Bayshore Grand Ballroom

Lunch Break (Please visit the exhibit booths)

1:30 - 2:30pm PST Salon ABC

Session 14A - Concurrent Panel: Ransomware and the Public Sector: What Can Be Done To Strengthen Our Defense Against Ransomware?

The public sector is at increasing risk of experiencing ransomware attacks, and the time to act is now. Studies have shown that municipalities, government agencies, and other public sector organizations - many of which Canadians rely on every day - are reporting attempted ransomware attacks at alarming rates.

Join our moderator and industry expert panelists as they tackle tough questions like, how are public sector organizations being targeted? Once faced with an incident, are they paying ransoms? Are they getting their data back? How are ransomware incidents impacting the populations these organizations support? How can public sector organizations better protect themselves from the ever-present threat of ransomware?

1:30 - 2:30pm PST Salon EF

Session 14B - Concurrent Panel: Women in Cybersecurity: Diversity 2023 and Beyond

Diversity as we have come to know it has had its challenges. Engaging the vast number of groups that have been left out is a challenge for many companies. While larger businesses may have the breadth of roles to accommodate diversity, there is still a struggle to achieve this. As for small businesses, the powerhouse of our economies, there is little doubt that hiring for something beyond the skills you need is extremely difficult to do. Add to this the fact that with rapidly changing technologies, the skills sets needed are increasingly hard to find, diversity seems to have hit a very tall barrier.

This panel will talk about how to deliver on the diversity promise. Discussion questions will include what is a diversity mindset? What are the fundamental challenges of businesses when implementing a diversity program? How would diversity of thought change how you approach a traditional diversity program? How has diversity impacted your development of products, services and processes?

1:30 - 2:30pm PST Salon D

Session 14C - Concurrent Panel: Unlocking Health Data Access to Empower Health Innovation. Individual’s Hold the Key and Blockchain Provides a Solution

Across Canada and the world, we are experiencing a crisis in our healthcare. The need for innovation in healthcare has never been greater. However, for innovation to occur health innovators need access to wellness and health data to enable AI / ML algorithms to solve these large problems. Health data is siloed in a fragmented health system and wellness data is under individual control. Many researchers and industry experts recognize that the most effective way to overcome the siloed data problem would be to give individuals control over the access to their data enabled through blockchain based technologies. Designing and implementing such solutions currently have poor user experience and are hard to universally deploy. Our panel of experts will address this challenge sharing their own experiences and knowledge in discussing how we can move forward in providing individuals’ control of health and wellness data, the technologies that provide for this and how this needs to align with business, privacy and security considerations to enable data access to power innovation in healthcare.

2:30 - 3:00pm PST Grand Ballroom Foyer

Afternoon Break

3:00 - 3:30pm PST Salon ABC

Session 15A - Concurrent Keynote by VMware: Enforcing a Strong Zero-Trust Ransomware Defense

In a zero-trust world, you have to assume that attackers are already in your network. These threat actors are living off the land, using legitimate pathways to start and progress their attacks. Increasingly, the attacker’s goal is to get into your network and stay there to explore, probe, eventually ransomware, and exfiltrate data. Join this session to learn about the strong and highly differentiated lateral security defense that sees more and therefore stops more, finding and evicting threat actors before they can do damage. Built on the principles of the cloud operating model, this solution delivers better security.

3:00 - 3:30pm PST Salon EF

Session 15B - Concurrent Keynote by Check Point: Cyber Warfare 2023: AI, ChatGPT, and Beyond

Emerging technology is rapidly developing especially OpenAI, with AI ethics policy and governance for Human Centered AI trailing far behind and threat actors/groups rarely concern themselves with ethical use of technology. With the exciting advent of ChatGPT and Microsoft's $1b investment in OpenAI, cybersecurity professionals need to know about utilization of OpenAI by cyber criminals on the Dark Web to develop malicious code and launch automated campaigns. And prepare for battle of the AIs.

3:00 - 3:30pm PST Salon D

Session 15C - Concurrent Keynote by Trend Micro: Mapping the Digital Attack Surface

There’s a simple but powerful dynamic driving cyber risk for most organizations today. The more they invest in digital infrastructure and tooling to drive sustainable growth, the more they may expose themselves to attack. According to experts, digital transformation during the pandemic pushed many organizations over a technology “tipping point” from which they will never return. In short, the future of business is digital—from hybrid working to cloud-powered customer experiences. That creates a challenge for CISOs. This challenge is often articulated in terms of the digital attack surface—that is, the collection of applications, websites, cloud infrastructure, on-premises servers, operational technology (OT) and other elements which are often exposed to remote threat actors. The risks associated with attack can be mitigated if organizations have visibility into all of these assets, calculate their risk exposure accurately and then take steps to secure the attack surface. Yet many struggle to do so. This presentation will provide insights (from a Trend Micro commissioned survey of 6,297 IT security decision makers in 29 countries) into why organizations are struggling to manage cyber risk and how to build a more risk-aware organization.

3:40 - 4:20pm PST Bayshore Grand Ballroom

Session 16 - Closing Keynote Speaker: Security and Privacy in the Metaverse

A long time ago, on June 27, 1991, I testified before the US Congress and warned that the then-emerging internet was ripe for Cyberterrorism, Cyberwar, Cybercrime, the loss of privacy, and a potential Electronic Pearl Harbor. I called it Information Warfare.

A Congressman asked me that day, “Mr. Schwartau, why would the bad guys ever want to use the internet?” Today, “Mr. Schwartau, why would the bad guys ever want to use the metaverse?”

Tens of billions of dollars and euros are being spent by global technology giants to digitally terraform the first generation of simulations; multi-user interactive virtual worlds with varying degrees of immersion, meant to captivate hundreds of millions of people.

Yet, is anyone talking about Security & Privacy with the to-be-developed technologies, highly granular and enhanced surveillance capitalism, behavioural monitoring and influence and all the other issues that make a lot of folks very uncomfortable?

Policy-makers and citizens alike need to address complex issues sooner than later:
- The Death of PII and Birth of Behavioral Identity Capitalism
- Is Murder legal in the Metaverse?
- What is ‘Good’ versus ‘Bad’ metaverse experiences?
- Should Meta-Anonymity be allowed?
- Securing the ODDA-Loops of Perception
- Geo- vs. Virtual Localization & Law Enforcement

What has Schwartau come up with this time, 30 some years later?

4:20 - 5:20pm PST Salon ABC

Session 17A - Concurrent Panel: Tribute to David Flaherty

David Flaherty passed away in October 2022. This panel of the current, and former BC Commissioners, pays tribute to David’s life and service by discussing his legacies as BC’s first Information and Privacy Commissioner. We discuss his role in establishing the Office in the early 1990s, as well as his overall impact on information and privacy rights in BC, Canada and globally.

4:20 - 5:20pm PST Salon DEF

Session 17B - Concurrent Panel: Financial Crime in Canada: Launch of the 2022 Edition of The State of the Federation Book Series

Financial crime in Canada remains a mystery: omnipresent, but we know little about its operation. Transactions are cloaked with apparent legality, which makes tracking criminal activity through economic or financial statistics a complex undertaking. A web of clandestine processes disguises its scale and location. As a result, financial crime is difficult to detect, disrupt, deter, and prosecute. This distinctive volume, authored by leading scholars and practitioners, opens the black box of financial crime in the Canadian federation. Its findings will help to inhibit the in-, out-, and through-flows of vast sums of dirty money by enhancing the capacity to investigate and prosecute financial criminals.

With a primary focus on money laundering, Canada: The State of the Federation 2022 identifies federal and provincial trends - including regulatory, legislative, political, institutional, and enforcement trends - that have inadvertently enabled the proliferation of this illicit activity. Showcasing an array of the best multidisciplinary research and experience, the volume demystifies financial crime, thus raising the level of awareness and public debate.

5:20 - 5:30pm PST Bayshore Grand Ballroom

Closing Remarks & Announcements

Title Sponsor

Platinum Sponsors

Gold Sponsors

Silver Sponsors

Summit Sponsors & Marketing Partners

Westin Bayshore Hotel - Vancouver, BC

If you are attending the 25th Annual Vancouver International Privacy & Security Summit and need to make a hotel reservation we have a room block at the Westin Bayshore Hotel with room rates starting at $219. The room block ends January 24th. To book a room within this room block please click here.

With lush and serene Stanley Park at its doorstep, water lapping the Coal Harbour Shores, snow-capped North Shore mountains in sight, and the vibrant city centre just around the corner, The Westin Bayshore, Vancouver is in perfect balance with its breathtaking surroundings. An elegant base from which to explore Vancouver, this resort-style property is a hub for well-being, whether travelling for leisure or business. A variety of year-round signature wellness programs promote feeling your best, while premier food and beverage offerings recharge the body and mind. Over 71,000 sq. ft. of flexible meeting space, one of Western Canada’s largest hotel ballrooms, and customizable catering options make this iconic hotel an ideal destination for conferences and social events. The Westin Bayshore, Vancouver is your gateway to inspired revitalization.

Call for Speakers

Please note that the call for speakers is now closed.

The Advisory Board for the 25th Annual Vancouver International Privacy and Security Summit is pleased to announce that the Call for Speakers is now closed and we are reviewing all of the submissions.

Subject matter experts working within the privacy and information security communities are invited to submit papers on their area of expertise. Of particular interest are briefs on cutting-edge subjects and themes suitable for presentation in either a panel session or keynote address. This three-day conference draws an international audience focused on policy, programs, law, research and technologies aimed at the protection of privacy and security.

Date: February 22-24, 2023
Location: Westin Bayshore Hotel, Vancouver, British Columbia

2023 Summit – Suggested Topics:

  • Artificial Intelligence and Machine Learning
  • Blockchain & Crypto Currencies
  • Data Exfiltration
  • Digital ID
  • Financial Cyber Crimes
  • Healthcare Cyber Attacks & Privacy Breaches
  • Hybrid Workplace
  • Internet of Everything
  • Privacy Legislation
  • Quantum Computing
  • Ransomware
  • Smart Cities
  • State Sponsored Terrorism
  • The Metaverse

Deadline:

All entries must be received by midnight of October 31, 2022. Invited speakers will be notified by November 30, 2022.

Submissions:

Submissions will be accepted electronically using the form below.

Have Questions or Need More Information?

Recommended Books

Please find below a list of recommended books that we suggest you check out (all written by various speakers from our events).

Title:  Facing Our Futures: How foresight, futures design and strategy creates prosperity and growth
Author:  Nikolas Badminton
Description:  A fascinating insight into how professionals and businesses can develop their foresight and strategy to ensure that they are prepared for an unpredictable future. In Facing Our Futures, Nikolas Badminton draws upon his decades of experience as a consultant and futurist to provide readers with the skillset and outlook they need to prepare their organization, team and themselves for whatever obstacles the future may hold. CEOs, executive teams, government leaders and policy makers need to gain a broader perspective and a firmer grasp on how their relevant industry, society or community is evolving and changing. Once they have acquired this foresight, they need to then discover how to fully harness it – by strengthening their foundations, forecasting and establishing a resilient and adaptable strategy. Facing Our Futures acts as a primer on the value of seeing how bad things can get and the power in imagining these futures. It also provides a proven strategic planning and foresight methodology – the Positive Dystopia Canvas (PDC) – that allows leaders to supercharge their teams to build evocative visions of futures that strengthen planning today.

(Canadian Delegates – Use code FUTURIST at checkout to save 30% when pre-ordering)
(US Delegates – Use code FUTURES at checkout to save 30% when pre-ordering)

Order Here in Canada
Order Here in the US


Title:  Canada: The State of the Federation 2022 – Financial Crime in Canada
Edited By:  Christian Leuprecht & Jamie Ferrill
Description:  Uncovering the hidden flows of dirty money into, out of, and throughout Canada.

Canada: The State of the Federation 2022 identifies federal and provincial trends that have inadvertently enabled the proliferation of this illicit activity. Showcasing an array of the best multidisciplinary research and experience, the volume demystifies financial crime, thus raising the level of awareness and public debate.

Contributors include Sanaa Ahmed, John Cassara, Garry Clement, Arthur J. Cockfield, Caroline Dugas, Jamie Ferrill, Cameron Field, Michelle Gallant, Peter German, Todd Hataley, Christian Leuprecht, David Mainmon, Katarzyna McNaughton, Denis Meunier, Pierre-Luc Pomerlau, Stephen Schneider, Pamela E. Simpson, and Jeffrey Simser.

(Use code MQTS for a 30% pre-publication discount-  Forthcoming December 2022)

Order Here


Title:  I Was Never Here:  My True Canadian Spy Story of Coffees, Code Names, and Covert Operations in the Age of Terrorism
Author:  Andrew Kirsch
Description:  Andrew Kirsch didn’t grow up watching spy movies, or dreaming about being a real-life James Bond. He was hardly aware that Canada even had its own intelligence service – let alone knew what its officers did. But when a terrorist attack occurred near the office of his financial services job, all of a sudden fighting terrorism meant a lot more to him than the markets. Within 18 months he had landed a job with the Canadian Security Intelligence Service (CSIS) – where he spent the next decade of his life.

In I Was Never Here, Kirsch (now an in-demand security consultant) spills the secrets of what life as an intelligence officer is really like, and dispels a few myths along the way. With humour, honesty, and candour, Kirsch shares his on-the-ground experience (or as much of it as he’s allowed to) of becoming a member of CSIS: from his vetting and training, to his initial desk job as a policy analyst, to his rise up the ranks to leading covert special operations missions. If you’ve ever wondered whether spies can have real dating lives, how they handle family responsibilities, or how they come up with cover stories or aliases, you’re in luck.

From the time he tried to get the code names “Burgundy” and “Anchorman” assigned to human sources (with no luck), to the night a covert operation was almost thwarted by a flyer delivery man, Kirsch takes you behind the scenes with an authentic view of Canada’s spy agency, and the intricate intelligence-sharing apparatus that works day and night to keep us safe. I Was Never Here is also a testament to one man’s drive to serve his country, and the sacrifices, big and small, that he made along the way.

Order Here


Title:  Time Based Security: Adding Measurement, Detection, and Reaction Time to Cybersecurity.
Author:  Winn Schwartau
Description:  Time Based Security in a Nutshell

The model for Time Based Security (TBS) originated with conversations with Bob Ayers, formerly of the Defense Information Systems Agency (DISA) over a period of years.

As a result of many napkin drawings, especially in Warsaw, Poland, TBS was born. In the two years since we spent hours and days arguing over the principles, I have had the opportunity to develop TBS into a workable mathematical model for quantification of security.

I have always maintained that to offer a reasonable defense, one has to know how to attack networks. So, TBS, here we go.

Defensive Products Do Not and Cannot Work.

The current and prevalent methods to defend networks against attack is an approach 10,000 years old based upon classic military strategy: build your defensive walls as high as you can to keep the bad guys out. This is also known as Fortress Mentality. However, it hasn’t worked since the dawn of time and still doesn’t work.

This fundamental error in historical judgement, though, was what modern defensive information security was based on: how can we build the walls around our networks high enough to keep the bad guys out. Oops! Wrong again. They began with the false premise that they could in fact keep the bad guys out and them compounded the error in the erroneous belief that everyone who had access to the networks was already cleared as a good guy; a pro-US gung-ho Marine-like good guy..

When the Trojans let the drawbridge to their city descend to admit the horse, they were networking with the outside world. When the Germans bypassed the Maginot Line, they created a network with the French – right or wrong. When people sailed over or around the Berlin Wall, the network connection was made. Thus, the principle of Fortress Mentality began to collapse as a viable defensive posture.

Order Here


Title:  Reverse Deception:  Organized Cyber Threat Counter-Exploitation
Authors:  Gregory Carpenter, Sean Bodmer, Dr. Max Kilger and Jade Jones
Description:  In-depth counterintelligence tactics to fight cyber-espionage

Expose, pursue, and prosecute the perpetrators of advanced persistent threats (APTs) using the tested security techniques and real-world case studies featured in this one-of-a-kind guide. Reverse Deception: Organized Cyber Threat Counter-Exploitation shows how to assess your network’s vulnerabilities, zero in on targets, and effectively block intruders. Discover how to set up digital traps, misdirect and divert attackers, configure honeypots, mitigate encrypted crimeware, and identify malicious software groups. The expert authors provide full coverage of legal and ethical issues, operational vetting, and security team management.

  • Establish the goals and scope of your reverse deception campaign
  • Identify, analyze, and block APTs
  • Engage and catch nefarious individuals and their organizations
  • Assemble cyber-profiles, incident analyses, and intelligence reports
  • Uncover, eliminate, and autopsy crimeware, trojans, and botnets
  • Work with intrusion detection, anti-virus, and digital forensics tools
  • Employ stealth honeynet, honeypot, and sandbox technologies
  • Communicate and collaborate with legal teams and law enforcement

Order Here


Title:  Analogue Network Security:  Time, Broken Stuff, Engineering, Systems, My Audio Career, and Other Musings on Six Decades of Thinking About it All
Author:  Winn Schwartau.  Design by Kayley Melton
Description:  Why Analogue Security?

The Best Cybersecurity Book of all Time:  Analogue Network Security by Winn Schwartau
https://www.cyberdefensemagazine.com/top-100-cybersecurity-books/

In 1972, the Anderson reference monitor security model was introduced. Static fortress mentality was, (and still is), fundamentally how information security is implemented. Along came Bell, LaPadula, and Biba a few years later, with some enhancements, notably for MLS, multi-level security systems.

In 1987, the U.S. Department of Defense published the Red Book, The Trusted Network Interpretation of the lauded 1983-85 Orange Book that set forth many of the principles for information security. The results were, essentially, “We have no earthly idea how to secure a network.”

Today, we now assume our networks are P0wn3d– already infiltrated by hostiles.
We know that by adding more technology, our security problems will go away. We think of the network as a single thing and attempt to protect it as such. It isn’t, and we can’t.

TCP/IP. It was just an experiment. Today, it is the inter-infrastructural foundation of civilization. The Internet of Things is adding so-called intelligence to some 50+ billion endpoints and trillions of sensors. Where’s the security? The privacy?

Massive new projects, using next generation products, from quarterly profit-incented vendors, promise the same old stuff all over again. The ultimate déjà vu epic fail of security.  Is this any way to run a planet?

C’mon, fifty years of practice and we’re still…? Well, screw it. You’ll see.
Security requires a single, interdisciplinary metric for the cyber, physical, and human domains. Digital is not binary.

Then, for me, things fell into place. I have a few ideas I’d like to share.

Order Here


Title:  BREACHED! Why Data Security Law Fails and How to Improve It
Author:  Daniel J. Solove & Woodrow Hartzog
Description:  A novel account of how the law contributes to the insecurity of our data and a bold way to rethink it.

Digital connections permeate our lives and so do data breaches. It is alarming how difficult it is to create rules for securing our personal information. Despite the passage of many data security laws, data breaches are increasing at a record pace. In Breached!, Daniel Solove and Woodrow Hartzog, two of the world’s leading experts on privacy and data security, argue that the law fails because, ironically, it focuses too much on the breach itself.

Drawing insights from many fascinating stories about data breaches, Solove and Hartzog show how major breaches could have been prevented or mitigated through a different approach to data security rules. Current law is counterproductive. It pummels organizations that have suffered a breach but doesn’t address the many other actors that contribute to the problem: software companies that create vulnerable software, device companies that make insecure devices, government policymakers who write regulations that increase security risks, organizations that train people to engage in risky behaviors, and more.

Order Here