Join us for three days of connecting, discovery, updates from the Council, regional community speakers, merchants, industry experts, and more.
Click here to convert to your local time.
Schedule subject to change – Continue to check back for updates and session details
- Tuesday, September 12
- Wednesday, September 13
- Thursday, September 14
Tuesday, September 12
Registration Open
Vendor Showcase Grand Opening
Community Meeting Kick-off
Presented by: Lance J. Johnson, Executive Director, PCI Security Standards Council
Emcee Welcome Remarks
Presented by: Wenlock Free, Regional VP, North America, PCI Security Standards Council
PCI SSC - Where We Are Going and How We Are Getting There
Presented by: Andrew Jamieson, VP, Solutions, PCI Security Standards Council and Emma Sutcliffe, SVP, Standards, PCI Security Standards Council
Skimming Prevention, Best Practices for Merchants
Presented by: Cameron Wallace, Technical Analyst, Lab Programs, PCI Security Standards Council
KEYNOTE: The Art of the Steal
Presented by: Bob Arno, Professor of Pickpocketry
Networking Break and Vendor Showcase
VIP Meet and Greet Add On Experience Featuring Keynote: Bob Arno, Professor of PickpocketryFor an additional fee, attend this intimate Meet and Greet Reception. This is a great opportunity to engage with our keynote and ask them any lingering questions. To add this experience: Simply go to your registration confirmation email and click “Modify Registration”. You may need to verify your registration first, then navigate to the “Meet and Greet Add-on" option to purchase this great opportunity. If you haven't registered yet, be sure to add on this experience when registering!
A Conversation with Leading Global Retailers: Successfully Working Through PCI DSS v4.0 Challenges - A Panel Discussion
Moderated by: Emma Sutcliffe, SVP, Standards, PCI Security Standards Council
Panelists: Tony James, CISSP, CISA, CRSC, Director of Cybersecurity, Target; Chanda Mafuka, Head of Governance, Risk & Compliance, Block, Inc. and Walker Thompson, Director of Information Security, Walmart
PCI DSS v4.0 Part - 1
What’s New: Top FAQs, Resources, Q&A, Guidance Column, etc.
Presented by: Marc Bayerkohler, Standards Trainer, PCI Security Standards Council; Tom White, Senior Manager, Content Development, PCI Security Standards Council and Kandyce Young, Manager, Data Security Standards, PCI Security Standards Council
PCI DSS v4.0 - Part 2
All About INFI
Presented by: John Bloomfield, Manager, Data Security Standards, PCI Security Standards Council and Matt O’Connor, Director, AQM, PCI Security Standards Council
PCI DSS v4.0 - Part 3
What Do I Need to Do In The Next 6 Months? 15 Months?
Presented by: Emma Sutcliffe, SVP, Standards, PCI Security Standards Council
Generative AI: Your New Secret Weapon or an Insider Threat?
Presented by: Kyle Hinterberg, QSA, CISSP, CISA, Manager, LBMC and Brian Willis, Senior Manager, LBMC
Day 1 Closing Remarks
Wednesday, September 13
Registration Open
Welcome Remarks
Presented by: Wenlock Free, Regional VP, North America, PCI Security Standards Council
When a Hacker Comes Knocking: Vulnerability Disclosure, Bug Bounties, and PCI
Presented by: Ilona Cohen, Chief Legal Officer, Chief Policy Officer, HackerOne, Inc. and Harley Geiger, JD, MA, CIPP/US, Counsel and Senior Director, Venable, LLP
Industry Keynote: Social Engineering and "Hacking the Humans"
Presented by: Jenny Radcliffe, People Hacker and Social Engineer
Networking Break and Vendor Showcase
VIP Meet and Greet Add On Experience Featuring Industry Keynote: Jenny Radcliffe, People Hacker and Social EngineerFor an additional fee, attend this intimate Meet and Greet Reception. This is a great opportunity to engage with our keynote and ask them any lingering questions. To add this experience: Simply go to your registration confirmation email and click “Modify Registration”. You may need to verify your registration first, then navigate to the “Meet and Greet Add-on" option to purchase this great opportunity. If you haven't registered yet, be sure to add on this experience when registering!
Track One
Smart Questions About Cybersecurity: What to Ask at Your Next Board Meeting
Presented by: Nelson Novaes Neto, Research & CTO/Partner, MIT Sloan & C6 Bank
Track Two
Mobile Payments: A Developer’s View
Presented by: Sean Estrada, Head of Industry Engagement, Stripe, Inc. and Roshan Sadanani, Product Lead, Payment APIs, Stripe
PCI Complexities in Higher Education - A Panel Discussion
Moderated by: Elizabeth Terry, Senior Manager, Community Engagement, PCI Security Standards Council
Panelists: Kevin Doar, CIA, CISA, CISM, ISA, Director - Merchant Services, University of Washington; Andrea Hendricks, PCIP, Director of Campus Commerce, Baylor University; Bryan Jurewicz, Chief Operations & Revenue Officer, Arrow Payments and Matthew Moore, ISA, Treasury Consultant, The Ohio State University
PCI SSC and EMVCo Mobile Security and Standards Update
Presented by: Andrew Jamieson, VP, Solutions, PCI Security Standards Council and Oliver Manahan, Director of Engagement and Operations, EMVCo
Track One
What is New for the PCI DSS v4.0 SAQs
Presented by: John Bloomfield, Manager, Data Security Standards, PCI Security Standards Council and Kandyce Young, Manager, Data Security Standards, PCI Security Standards Council
Track Two
Cloudy with a Chance of Breaches: Where CHD May Be Hiding and At Risk
Presented by: Anton Abaya, CISA, CISM, PCI QSA; Professional Services Manager, Converge Technology Solutions
Scaling Your Small Business: Building a Strong Security Framework That Includes PCI DSS Compliance
Presented by: Marc Rubbinaccio, CISSP, CISA, Senior Compliance Manager, Secureframe
Software Security Framework: Explaining the Web Software Module Through Analogy and Music
Presented by: Jake Marcinko, Senior Manager, Solution Standards, PCI Security Standards Council
Scaling 6.4.3 & 11.6.1: Browser Script Management & The Large Enterprise Journey to Compliance
Presented by: Steven Eric Fisher, CISSP, GCPS, Fortune 1 and Jeffrey Zitomer, Senior Director of Product Management, Human Security
The Human Factor in Payment Security: Harnessing Technology and Processes to Fortify the Payment Landscape
Presented by: Dr. Emmanuel Adu-Gyamfi, CISSP, CISA, QSA, PCIP, Sec+, CEO, Eretmis, Inc.
Prilex Evolution and Prevention Techniques
Presented by: Fernando Bucelli, Security Specialist, Cielo
Migration to AES Protected Payments: Current Support and Ongoing Work to Aid Adoption
Presented by: Steven Bowles, Regional Security Officer, NAR, Ingenico, Inc.; Richard Kisley, Chief Engineer, IBM Corporation and Dr. Susan Langford, Senior Cryptographer, Utimaco
Networking Break and Vendor Showcase
Light refreshments served.Track One
You've Been Hacked: Now What?
Presented by: Rob Harvey, CISSP, ISO 27001, QSA, Managing Director - Risk, Security, and Privacy, Online Business Systems and Adam Kehler, Director - Risk, Security, and Privacy, Online Business Systems
Track Two (Tech Demos are sponsored sessions)
SecurityMetrics: How to Protect Your Ecommerce Transactions: An Overview of PCI DSS v4.0 Changes for Ecommerce Sites
Presented by: Gary Glover, CISSP, CISA, QSA, VP Assessments, SecurityMetrics
Understanding Roles in a Breach Scenario
Moderated by: Mark Mrotek, Director, Certification Programs, PCI Security Standards Council
Panelists: David Ellis, VP, Forensic Investigations, SecurityMetrics and Daniel Wright, VP, Merchant Account Data Compromise, Bank of America, N.A
K3DES: Assessments in the Hybrid World of Remote and Onsite
Presented by: Howard Glavin, CISM, CRISC, CDPSE, QSA, CTGA, Executive Vice President, K3DES, LLC
The Ten Habits of Effective PCI DSS v4.0 Compliance Professionals
Presented by: Ralph Villanueva, PCIP, CISA, CISM, ISO27001LA, ISO27701LA, IT Security and Compliance Analyst, Hilton Grand Vacations
27K1 Ltd: A Total, PCI DSS v4.0 Compliance Software Solution
Presented by: Jeremy Martin, Co-Founder and Director, 27k1 Ltd and James Seaman, MSc; CISM; CRISM, Director, IS Centurion Consulting Ltd
Beyond the Contract: Managing Customer/Service Provider Relationships
Presented by: Kara Gunderson, PCIP, Director Payment Card Operations, Citgo Petroleum Corporation; Greg Luna, Senior Legal Counsel, CITGO Petroleum Corporation and Todd McClelland, Attorney at Law, Partner, Head of Global Data Privacy and Cyber Security, McDermott, Will & Emery, L.L.C.
DataStealth: Realtime Content Protection. It's Required. And It's Easy.
Presented by: Derek Schenk, CTO, DataStealth
Achieving and Maintaining PCI Compliance In An Acquisition Model
Presented by: Heidi Babi, PCIP, ISA, PCI Security Assurance & Compliance Sr. Lead, Mars, Incorporated and Jeffrey Moy, PCIP, ISA, PCI Security Assurance & Compliance Sr. Lead, Mars, Incorporated
Total Compliance Tracking, LLC: Streamlining Complex Compliance Engagements
Presented by: Todd Coshow, Head of Business Development, Total Compliance Tracking and Jon Dotson, Head of Product, Total Compliance Tracking
Compliance is a Program, Not a Project
Presented by: Michael Aminzade, QSA, PCIP, CISSP, C|CISO, CISM, CRISC, CDPSE, ISO LA27001 Vice President, Managed Compliance Services, VikingCloud and Chelsea Lopez, CIA, CISA, CRISC, CISSP, PCI-ISA Enterprise Risk Director, FIS
- Why compliance should be viewed as a program.
- World view on regulatory compliance.
- Synergies between compliance programs.
- Developing a mature compliance program.
- Impediments to success.
A-LIGN: Get Audit-Ready In A Fraction Of The Time By Leveraging Powerful Automation
Presented by: Chris Lamm, PCI Managing Consultant, A-LIGN and Dustin Rich, PCI Practice Lead, A-LIGN
Networking Reception and Vendor Showcase
Thursday, September 14
Welcome Remarks
Presented by: Wenlock Free, Regional VP, North America, PCI Security Standards Council
Registration Open
Unleashing the Power of Participation with PCI SSC
Presented by: Lindsay Goodspeed, Senior Manager, Corporate Communications, PCI Security Standards Council and Elizabeth Terry, Senior Manager, Community Engagement, PCI Security Standards Council
Keynote: Above All Else - The Power of Passion
Presented by: Jamie Clarke, Professional and Olympic-Level Performance Coach, Expedition Leader
Networking Break and Vendor Showcase
VIP Meet and Greet Add On Experience Featuring Keynote: Jamie Clarke, Professional and Olympic-level Performance Coach, Expedition Leader, Business Builder, and Master MotivatorFor an additional fee, attend this intimate Meet and Greet Reception. This is a great opportunity to engage with our keynote and ask them any lingering questions. To add this experience: Simply go to your registration confirmation email and click “Modify Registration”. You may need to verify your registration first, then navigate to the “Meet and Greet Add-on" option to purchase this great opportunity. If you haven't registered yet, be sure to add on this experience when registering!
PCI SSC Special Interest Group Update
Presented by: Kristine Harper, PCI DSS QSA, Principal Assurance Consultant, AWS Security Assurance Services, LLC.; Steve Porter, CISSP, QSA, QPA, GPEN, GWAPT, GICSP, GMOB, GCIH, GSNA, GSEC, CEO/ Founder, Secured Net Solutions Inc. and Kandyce Young, Manager, Data Security Standards, PCI Security Standards Council
Making the Payments Industry Stronger – A Panel Discussion
Moderated by: Mark Meissner, SVP, Education & Engagement, PCI Security Standards Council
Panelists: Fernando Bucelli, Security Specialist, Cielo; John Elliot, Security Advisor, Jscrambler; Wenlock Free, Regional VP, North America, PCI Security Standards Council and Timothy Thomas, PCIP, Senior Product Manager, Bank of America N.A.
Bridge the Gap: Speak the Same Language As Your Assessor - A Panel Discussion
Moderated by: Elizabeth Terry, Senior Manager, Community Engagement, PCI Security Standards Council
Panelists: Boyd Clewis, CISSP, CISA, CCSK, PCIP; CEO, Genesis Security and Compliance; Brittany George, QSA, CISA, CISM, PCIP, Partner, Weaver and Tidwell, L.L.P.; Richard Haag, QSA, QSA-P2PE, QPA, VP Compliance Services, Intersec Worldwide and Phyllis Woodruff, PCI ISA, CISM, PMP, VP IT Risk & Compliance, Global Payments Direct
Closing Remarks
Presented by: Wenlock Free, Regional VP, North America, PCI Security Standards Council
Assessor and Payment Vendor Lunch
Assessor Session (QSAs, ISAs, ASVs, PFIs, QPAs, CPSAs only)
Presented by: Matt O’Connor, Director, AQM, PCI Security Standards Council; Travis Powell, Director, Training Programs, PCI Security Standards Council; Elizabeth Terry, Senior Manager, Community Engagement, PCI Security Standards Council and Kandyce Young, Manager, Data Security Standards, PCI Security Standards Council
Payment Vendor Session (PCI Recognized Labs; CPoC, MPoC, and SPoC Product Vendors; and P2PE and SSF Assessors and Vendors)
Presented by: Leon Fell, Director, Device Standards, PCI Security Standards Council; Andrew Jamieson, VP, Solutions, PCI Security Standards Council; Jake Marcinko, Senior Manager, Solution Standards, PCI Security Standards Council and Mike Thompson, Director, Solutions Standards, PCI Security Standards Council