Join us for four days of learning, discovery, updates from the Council, regional community speakers, merchants, industry experts, and more.
The PCI SSC 2020 North America Community Meeting Call for Speakers has Closed.
All session times are in Eastern Standard Time.
Agenda times are subject to change.
All presentations will be available in the General Session. On-Demand content will be released immediately following the Community Experience each day. Attendees can access sessions by navigating to the “Filter By” drop down menu and searching by content type.
- Tuesday 6 October
- Wednesday 7 October
- Thursday 8 October
- Friday 9 October
Tuesday 6 October
Morning Main Sessions
Opening Remarks and Overview
Presented by: Katty Kay, Lead Anchor, BBC World News America
Community Meeting Kick-off
Presented by: Lance J. Johnson, Executive Director, PCI Security Standards Council
PCI DSS v4.0 – Part 1: Evolving Through the Power of Feedback
Presented by: Lauren Holloway, Director, Data Security Standards, PCI Security Standards Council and Emma Sutcliffe, SVP, Standards Officer, PCI Security Standards Council
Wellness Break - Take a moment to get up from your computer, refill your water, stretch your legs, do what you need to do to recharge.
Brand and PCI SSC Offices
Representatives will be available to meet with you and answer questions.
Community Experience - Located in the Community Café
Cooking, Cocktails, or Yoga
Get your ingredients ready and attend a cooking demonstration where you will make Chili Con Carne.
Attendees can follow along to create three delicious cocktails including an Old Fashioned, Classic Margarita, and Rum Runner.
Stretch both the mind and body with some relaxing and mindful stretches.
Sessions are pre-recorded.
On-Demand Sessions - Will be released on the platform immediately following the Café Experience.
Content Disclaimer: The views and opinions expressed in external presentations are those of the external presenters and do not necessarily reflect the official standards or position of the PCI Security Standards Council.
Building a Continuous Risk Assessment Pipeline in DevOps
Presented by: Jake Marcinko, Senior Manager, Emerging Standards, PCI Security Standards Council and Altaz Valani, Director, Insights Research, Security Compass
Challenges of Implementing a New Standard – A Panel Discussion
Moderated by: Tom White, Training Content Manager, PCI Security Standards Council
Panelists: Tanya Deen, Director, External Compliance, Global Payments and Nick Trenc, SSLCA, SSA, SSF, P2PE, PIN, Director, Coalfire
Cloud Initiatives and Efforts
Presented by: Zeal Somani, ISA, Security and Compliance Specialist, Google and Mike Thompson, Senior Manager, Emerging Standards, PCI Security Standards Council
Making PCI DSS Compliance Cloud-Native
Presented by: Travis Powell, Director, Training Programs, PCI Security Standards Council; Zeal Somani, ISA, Security and Compliance Specialist, Google and Ann Wallace, ISA, Security Solutions Manager, Google
PA-DSS/SSF Transition
Presented by: Tracey Harrington, CSCIP/P, Certification Programs Manager, PCI Security Standards Council and Jake Marcinko, Senior Manager, Emerging Standards, PCI Security Standards Council
In this session Jake Marcinko, PCI SSC Sr. Manager, Emerging Standards will share how PA-DSS compares to its successor, the Secure Software Framework and Tracey Harrington, Manager, Certification Programs will provide information on timelines and suggestions on how to prepare your organization to make the transition.
Presented by: Tracey Harrington, CSCIP/P, Certification Programs Manager, PCI Security Standards Council and Jake Marcinko, Senior Manager, Emerging Standards, PCI Security Standards Council
Payment HSMs As A Service
Presented by: Andrew Hodges, CTO, MYHSM
PCI DSS 4.0: An Evolution or a Revolution
Presented by: Mark Repka, PCIP, QSA, CISM, CISA, CTPRA, Security Consultant, MegaplanIT Holdings, LLC
The Growing Importance of Software Security
Presented by: Troy Leach, Senior Vice President, Engagement Officer, PCI Security Standards Council; Steve Lipner, Executive Director, SAFECode; Tommy Ross, Senior Director for Policy, BSA | The Software Alliance and Kevin Stine, Chief of the Applied Cybersecurity Division, National Institute of Standards and Technology’s Information Technology Laboratory (NIST)
Winning the War on Segmentation
Presented by: and Paul Truitt, CISSP, CISA, CISM, CEH, Chief Information Security Officer, SageNet
You’ve Gone Dark: How Inconsistent Configurations Are Blinding Your Security Team
Presented by: Boyd Clewis, QSA, CISSP, PCIP, CCSK, CISA, Sr. Consultant - Risk, Security, and Privacy, Online Business Systems
Wednesday 7 October
Morning Main Sessions
Opening Remarks and Overview
Presented by: Katty Kay, Lead Anchor, BBC World News America
Global Learning and Local Leading - Why your Participation is Critical to Payment Security Everywhere
Presented by: Troy Leach, Senior Vice President, Engagement Officer, PCI Security Standards Council
Wellness Break - Take a moment to get up from your computer, refill your water, stretch your legs, do what you need to do to recharge.
PCI DSS v4.0 – Part 2: New Customized Approach and Risk Analysis
Presented by: Marc Bayerkohler, Standards Trainer, PCI Security Standards Council
Keynote: Cybersecurity – During the Pandemic and Well into the Future
Presented by: Dr Jessica Barker, Co-Founder, Co-CEO, Cygenta and FC, Co-CEO and Head of Ethical Hacking, Cygenta
Wellness Break - Take a moment to get up from your computer, refill your water, stretch your legs, do what you need to do to recharge.
Brand and PCI SSC Offices
Representatives will be available to meet with you and answer questions.
Community Experience - Located in the Community Café
Casual Conversations
Hosted by some very special and surprise guests, join fellow attendees for interactive conversations about sports, movies, and television. Be sure to arrive early, as space is limited and based on a first-come, first-serve basis.
Sports: Rick Stroud, Tampa Bay Times sports reporter and host of Sports Day Tampa Bay podcast
TV Shows: Clint Worthington, host of More of A Comment, Really… podcast
Movies: Matthew McArdle, Filmmaker & Screenwriter
On-Demand Sessions - Will be released on the platform immediately following the Café Experience.
Content Disclaimer: The views and opinions expressed in external presentations are those of the external presenters and do not necessarily reflect the official standards or position of the PCI Security Standards Council.
Engagement in the PCI Community – What’s In It For Me?
Presented by: James Hamilton, Department Manager – Governance, Risk & Compliance, Enterprise Holdings, Inc. and Elizabeth Terry, PMP, CISSP, CBSA, PCIP, Senior Manager, Community Engagement, PCI Security Standards Council
ATM Cash Out - Learnings and Best Practices
Presented by: Alicia Malone, Senior Manager, Public Relations, PCI Security Standards Council and Yogesh Patel, PCI QSA, P2PE, PCI PIN QPA, VISA SA, Consultant, SISA
How the Leading European Retailer Innovates Payments and Security
Presented by: Tomás Perlines, Head of Payment Security, Schwarz IT GmbH & Co KG
Track One
Learning from PFI Investigations – 2020
Presented by: Gill Woodcock, VP, Global Head of Programs, PCI Security Standards Council
Online Digital Skimming
Presented by: John Bloomfield, Standards Development Manager, Data Security Standards, PCI Security Standards Council and Carlos P. Kizzee, EVP Intelligence Operations and Legal Affairs, Retail and Hospitality ISAC
LIVE DEMO: Catching Criminals in the Act: E-Commerce Skimming and What to Do About It
Presented by: David Ellis, GCIH, PFI, QSA, CISSP, VP of Forensic Investigations, SecurityMetrics and Chad Horton, CISSP, Senior Director of Penetration Testing, SecurityMetrics
Update on POI v6
Presented by: Leon Fell, CPA, CIA, CMA, CISA, CITP, Director of Solutions Standards, PCI Security Standards Council and Lars Hanke, Senior Consultant, Deutsche Telekom Security GmbH
Trends and Evolution of Mobile Payments
Presented by: Berny Goodheart, Device Standards Manager, PCI Security Standards Council
Updates on PCI SSC Mobile Security Standards
Presented by: John Markh, Senior Manager, Emerging Standards, PCI Security Standards Council
Thursday 8 October
Morning Main Sessions
Opening Remarks and Overview
Presented by: Katty Kay, Lead Anchor, BBC World News America
PCI DSS v4.0 – Part 3: Evolving Nature of Authentication Practices
Presented by: Joel Weisz, Emerging Standards Manager, PCI Security Standards Council
Keynote: Preparedness, Crisis Management, and Communications
Presented by: John Volanthen, World Record-Holding British Cave Diver
Wellness Break - Take a moment to get up from your computer, refill your water, stretch your legs, do what you need to do to recharge.
Brand and PCI SSC Offices
Representatives will be available to meet with you and answer questions.
Community Experience - Located in the Community Café
Magic and Mindreading
Prepare to be entertained by a digital illusionist with a highly interactive virtual magic and mentalist show like no other. Be sure to arrive early as space is limited and based on a first-come, first-serve basis.
On-Demand Sessions - Will be released on the platform immediately following the Café Experience.
Content Disclaimer: The views and opinions expressed in external presentations are those of the external presenters and do not necessarily reflect the official standards or position of the PCI Security Standards Council.
Better Living Through Better Passwords
Presented by: Hoyt Kesterson, QSA, CISSP, CISA, Senior Security & Risk Architect, Avertium
Airlines Rethinking Payment Solutions to Meet the Challenge of PCI Compliance
Presented by: Leonardo Polvora, PCI QSA, ISO/IEC, ISACA CRISC, Principal Security Consultant, SecureTrust, a Trustwave division
Cryptography Evolves
Presented by: Ralph Poore, Director, Emerging Standards, PCI Security Standards Council
P2PE - So Much More than an Acronym
Presented by: Matt O’Connor, AQM Manager, PCI Security Standards Council and Mike Thompson, Senior Manager, Emerging Standards, PCI Security Standards Council
Healthcare Provider PCI Challenges and Insight
Presented by: Carl Angeloff, QSA, CISM, ISO 27001 Auditor, Director, Security Risk Advisors; Andrew Hardie, Assessor Quality Management (AQM) Analyst, PCI Security Standards Council and Ben Smith, VP, Chief Information Security Officer, Nuvance Health
Getting the Most From Your Membership
Presented by: Jeremy King, Vice President, Regional Head for Europe, PCI Security Standards Council
Leveraging ISA's: A Faster Approach to PCI Compliance and Remote Assessments
Presented by: Walid Barakat, Vice President - Governance, Risk and Compliance, Global Payments Inc.; Stacy Hughes, CPA, CITP, CRISC, CISM, Chief Information Security Officer, Global Payments Inc. and Gill Woodcock, VP, Global Head of Programs, PCI Security Standards Council
How Bears, Cows and One Organization Continuously Secure the Environment - A Panel Discussion
Moderated by: Monica LaCroix, MCSE, CRISC, CISA, CISSP, QSA, Principal, Product Development & Innovation, Coalfire
Panelists: Nathan Beerbower, IT Security Analyst, Sheetz, Inc.; Eric Kitchens, PCI QSA, CISSP, CISA, PCI QPA, Managing Principal, Payments Assurance, Coalfire and Mark Mrotek, Director, PCI Security Standards Council
Merchants' Journey Through a Global Pandemic – A Panel Discussion
Moderated by: Lindsay Goodspeed, Senior Manager, Corporate Communications, PCI Security Standards Council
Panelists: Jacob Ansari, CISSP, QSA/PA-QSA (P2PE), Senior Manager, Schellman & Company, LLC; Andy Kirkland, CISO, Starbucks Coffee Company and Marie-Christine Vittet, VP Compliance, ACCOR
PIN Points—Cryptographic Standards
Presented by: Ralph Poore, Director, Emerging Standards, PCI Security Standards Council and Jeff Stapleton, X9F4 Chair, ASC X9 Financial Services
Friday 9 October
Morning Main Sessions
Opening Remarks and Overview
Presented by: Katty Kay, Lead Anchor, BBC World News America
PCI DSS v4.0 – Part 4: Third-Party Relationships and Cloud Services
Presented by: John Bloomfield, Standards Development Manager, Data Security Standards, PCI Security Standards Council and Lauren Holloway, Director, Data Security Standards, PCI Security Standards Council
Keynote: The Perils of IoT When Working From Home
Presented by: Ken Munro, Partner and Founder, Pen Test Partners
Looking Towards The Future
Presented by: Lance J. Johnson, Executive Director, PCI Security Standards Council
Wellness Break - Take a moment to get up from your computer, refill your water, stretch your legs, do what you need to do to recharge.
Brand and PCI SSC Offices
Representatives will be available to meet with you and answer questions.
Community Experience - Located in the Community Café
Conversations with the Council
These “Birds of a Feather" live conversations will be led by PCI SSC staff and focus on the themes listed below. Be sure to arrive early as space is limited and based on a first-come, first-serve basis.
Acquirers: Marc Bayerkohler
PCI Software Security Framework: Tom White & Jake Marcinko
Security when working from home: Jeremy King & Josh Koepsell
Challenges for PCI DSS remote assessments: Gill Woodcock & Emma Sutcliffe
Vendor/Labs: Tim Cormier & Mark Mrotek
On-Demand Sessions - Will be released on the platform immediately following the Café Experience.
Content Disclaimer: The views and opinions expressed in external presentations are those of the external presenters and do not necessarily reflect the official standards or position of the PCI Security Standards Council.
HackEDU Secure Coding Training: Tyler Pratte, Global Strategic Account Manager, HackEDU
Cyberthreats, Accidental Risk and the Shift Towards Continuous Compliance in the Cloud: Mike Annand, Director of Customer Compliance, Armor Defense Inc.
Leveraging SAINT Security Suite to Meet PCI DSS Requirements: Sam Kline, CTO and Jane Laroussi, Senior IT Security Specialist, Carson & SAINT
How Security Orchestration, Automation and Response tools can be leveraged to better defend your PCI infrastructure: Dominick Vitolo, VP of Security Services, MegaplanIT Holdings LLC
Navigating the PCI Journey with CIS: Susan Lindquist, Cybersecurity Solutions Engineer, Center for Internet Security
Verizon Tech Demo: Sean Sweeney, Global PCI Lead, MCI Communications, Inc. dba Verizon Business Services
Global Executive Assessor Roundtable Update
Presented by: Jacob Ansari, CISSP, QSA/PA-QSA (P2PE), Senior Manager, Schellman & Company, LLC; Gary Glover, Vice President of Assessments, SecurityMetrics and Lance J. Johnson, Executive Director, PCI Security Standards Council
Mapping the MITRE ATT&CK® Framework to the PCI DSS
Presented by: Jeff Man, Information Security Evangelist, Online Business Systems
PCI SSC Council and Standards Update – Assessing PTS Devices
Presented by: Tim Cormier, Senior Manager, Device Standards, PCI Security Standards Council
Petrol Taskforce Update
Presented by: Kara Gunderson, PCIP, Manager, Payment Card Operations, CITGO Petroleum Corporation and Elizabeth Terry, PMP, CISSP, CBSA, PCIP, Senior Manager, Community Engagement, PCI Security Standards Council
QA @ PCI: How the Council Ensures Integrity in its Programs
Presented by: Nikki Billman, AQM Manager, Operations, PCI Standards Security Council and Brandy Cumberland, Director of Assessor Quality Management (AQM) Programs, PCI Security Standards Council
Small Merchant Task Force – 2020 Efforts
Presented by: Natasja Bolton, Strategic Partner Support Engagement Manager, Cyber Risk Services, Sysnet Global Solutions and Lauren Holloway, Director, Data Security Standards, PCI Security Standards Council