Cyber, Fraud, and Physical Security Conference Presentations

Day One (Physical Security) - March 4


Session Title: When Violence Comes to Work -Through the Eyes of Survivors
Speaker: Jim Rechel, President - The Rechel Group, Inc. & Carol S. Dodgen, CPD - Dodgen Security Consulting
Session Description: This joint session examines workplace violence in the banking industry through both investigative case studies and survivor perspectives. Jim Rechel analyzes three fatal bank incidents to reveal warning signs, response challenges, and institutional decisions, while Carol Dodgen shares survivor-informed insights on preparedness, resilience, and recovery. Together, they deliver practical lessons to help organizations prevent violence, respond effectively, and sustain a culture of safety and compassion.

Session Title: Mastering the Art of De-Escalating Angry Customers, Co-Workers, and More
Speaker: Polly Westcott, PsyD, HSPP - Indiana Health Group
Session Description: Whether you’re on the front line with customers or supporting teams behind the scenes, knowing how to defuse tension is essential. In this engaging session, Dr. Polly Westcott shares how understanding the brain’s anger response helps security, IT, and banking professionals de-escalate conflict, strengthen teamwork, and keep operations running smoothly.

Session Title: Workplace Violence in Banking: Lessons from Those Who Lived It
Speaker: Jim Rechel, President - The Rechel Group, Inc
Session Description: Following the documentary When Violence Comes to Work: An Inside Examination, this moderated panel brings together banking security leadership, law enforcement, and individuals directly impacted by fatal bank workplace violence incidents. Panelists will share firsthand experiences, behind-the-scenes investigative findings, response challenges, and institutional decision-making before, during, and after each event. The discussion is designed to provide bank security professionals with practical, experience-based lessons to strengthen threat recognition, preparedness, response, and recovery.

Session Title: Active Threat Response and Preparedness for Financial Institutions
Speaker: Terry Choate, CEO/President - Blue-U Defense, LLC
Session Description: Blue U Defense Choate’s sessions emphasize proactive employee preparation, policy development, and understanding human responses in active threat situations. Attendees learn how to build security-mindful cultures, improve individual situational awareness, and implement pragmatic practices that bridge the gap between theoretical “run, hide, fight” models and real-world survival outcomes.

Session Title: The Perfect Storm
Speaker: Patrick Dix, Vice President, Client and Association Engagement - SHAZAM
Session Description: This session will examine how converging fraud, cyber, and operational threats—including social engineering, ATM compromise, and ransomware attacks—create high-impact crises for financial institutions. Attendees will gain practical guidance on preparing for, managing, and recovering from these events, with a focus on decisive leadership, coordinated response, and institutional resilience.

 

Day 2 (Cyber/Fraud) - March 5


Session Title: Cybercrime: How to Keep Your Bank Safe from Insider and Outsider Threats
Speaker: Jeff Lanza - The Lanza Group
Session Description: This presentation breaks down the evolving tactics used by both internal and external cybercriminals targeting financial institutions. It highlights real-world attack scenarios, common warning signs, and the organizational blind spots that make banks vulnerable. Attendees walk away with practical strategies to strengthen defenses, reduce human-factor risk, and build a security-aware culture that protects customers, data, and the institution’s reputation.

Session Title: AI in the Vault: Ensuring Confidentiality with Microsoft 365 Copilot
Speaker: Zach Shelton, Principal, Cy Sturdivant, Principal - Forvis Mazars
Session Description: In today’s highly regulated banking environment, generative AI tools like Microsoft 365 Copilot must be leveraged securely and remain in full compliance. This session will show executives how to harness Copilot’s productivity benefits without compromising confidentiality. We will outline clear “dos and don’ts” for Copilot use – from policy-level requirements to practical tips for all institutions. Attendees will learn how Copilot inherits your organization’s access controls, so shared content stays within proper bounds. We’ll discuss how to configure Copilot and train staff so that no confidential information is inadvertently exposed, honoring client confidentiality agreements and regulatory obligations. We’ll highlight internal governance policies alongside real-world scenarios of Copilot’s dos and don’ts in action. By the end of this session, bank leaders will have a list of best practices for using Microsoft Copilot safely – empowering their teams to boost efficiency with AI while protecting sensitive data and staying within the bounds of cybersecurity policy and banking regulations.

Session Title: Using Video Intelligence to Strengthen Security and Improve Service in Financial Institutions
Speaker: Len Harvey, Regional Sales Manager - Verint
Session Description: Banks continue to rely on video data for security, but the role of video is expanding. With the help of modern AI, the same camera infrastructure can reveal patterns, inform staffing decisions, support fraud investigations, and enhance the customer experience — all while promoting safety. This session will explore how financial institutions can create value from video data without replacing existing systems or overhauling operations. The goal is to provide practical approaches that enable bank leaders to enhance efficiency, mitigate risk, and foster more informed decision-making throughout the organization.

Session Title: What Bankers Need to Know About Agentic AI
Speaker: Jim Perry, Senior Strategist - Market Insights, Inc.
Session Description: As artificial intelligence moves beyond copilots and chatbots into autonomous, goal-driven systems, bankers face a new challenge: not whether agentic AI will matter, but how to prepare their institutions for the next frontier in banking’s AI journey—using it responsibly and competitively. 

In this forward-looking session, we explore what it means to become an “agentic bank”—one where intelligent systems work alongside people to orchestrate workflows, operationalize insights, and support better decision-making. Attendees will learn: 

  • The difference between generative AI tools and agentic AI—and why that shift matters
  • A practical four-step readiness playbook focused on leadership, governance, culture, and execution
  • How community-based institutions can build confidence, capability, and trust as AI systems take on greater autonomy

Session Title: ATMs, BlackCats, and IoCs. Oh My!
Speaker: Michael Hartke, Executive Vice President - infotex
Session Description: What does a ransomware attack look like, as it crawls over remote management and monitoring software to our ATMs? A well-known ATM service provider was once the subject of a ransomware attack. This presentation would include a review of the timeline, what the infotex SIEM was able to see, and a rundown not only of the IoCs, but the control structures that worked and did not work to thwart the attack.

Session Title: From Application to Attack: Inside Modern Account-Opening Fraud Rings
Speaker: Steven Gonzalo, CEO/President - American Commercial Bank & Trust
Session Description: Sophisticated criminal organizations are increasingly targeting the largest financial institutions by exploiting weaknesses in account-opening processes. This session explores real cases in which my institution and our customers were attacked through well-orchestrated schemes that began with fraudulent account creation. Attendees will gain insight into how cyber, fraud, IT, and physical security functions must collaborate to identify patterns, shut down access points, and strengthen defenses against these stealth infiltration tactics.

Session Title: Banker Fraud Panel Discussion
Speaker: Panel
Session Description: 3 bank volunteers, come equipped with how you had a significant loss within the last 12 months and how the fraudsters by passed their systems/procedures they had in place. 1 from a larger bank, 1 from a medium bank, 1 from a smaller bank. 1 hour time frame.

Session Title: Fraud Trends for 2026: Perspectives from the US Postal Service
Speaker: Ron Barron, Postal Inspector - United States Postal Inspection Service
Session Description: Postal Inspector, Ron Barron of the Postal Inspection Service will be presenting the trends in robberies and additional threats to the Postal Service employees and to the impacts in mail delivery. Additionally, the presentation will include how the theft of mail is resulting in massive monetary losses to both companies, individual citizens, and the banking companies via check fraud. This will include the tactics used by criminals to steal the mail, solicit account holders via social media, and methods for alteration and cashing of stolen checks.

 

Day 3 (Cyber) - March 6


Session Title: InfraGard Q&A
Speaker: Kyle Johnson, CISSP, Managing Principal Consultant - Mandiant (now a part of Google Cloud)
Session Description: InfraGard is a public–private intelligence-sharing framework that links cybersecurity and risk professionals in critical sectors (including financial services) with the FBI to exchange threat indicators, best practices, and emerging risk insights. In this early bird session, Kyle Johnson, a director on the InfraGard Indiana Board of Directors, will bring us up to speed on InfraGard, its mission, and how to join and participate.

Session Title: Passwordless Networks and FIDO-2
Speaker: Matt Babicz, CISA, Senior Manager, Cybersecurity Consulting - Plante Moran
Session Description: As cyber threats continue to escalate and credential based attacks remain one of the most common entry points for adversaries, financial institutions are rethinking how they authenticate users. This session explores the rapid industry shift toward passwordless networks and the adoption of FIDO 2 authentication standards, which offer phishing resistant and highly secure alternatives to traditional passwords and even legacy MFA.

Attendees will gain an understanding of how passwordless authentication works, why major technology providers and regulators are pushing for it, and what this means for financial institutions navigating evolving compliance expectations. The session will break down key passwordless methods including biometrics, passkeys, and hardware security keys while addressing practical challenges such as legacy system integration, user adoption, recovery processes, and hybrid transition models.

Participants will walk away with a clear sense of the security, operational, and compliance benefits of going passwordless, along with practical steps to begin preparing their institution for a future in which passwords play a much smaller role in protecting data and systems.

Session Title: Why Good People Make Bad Security Decisions
Speaker: Jordan Rosiak, vCISO, Senior Advisor - Bedel Security
Session Description: Even well-trained, well-intentioned employees fall for phishing, click risky links, bypass controls, or delay reporting incidents. This session dives into the psychology behind those decisions—cognitive bias, urgency, habit, and workload—and how they play out in community banks. With relatable scenarios and actionable insights, attendees will learn how to design processes, communication, and reinforcement that guide people toward safer decisions. This is a human conversation, not a technical one.

Session Title: The Critical Path: Your Next Move in the Incident Response Adventure
Speaker: Kyle Johnson, CISSP, Managing Principal Consultant - Mandiant (now a part of Google Cloud)
Session Description: The digital walls are always under threat, but when the worst happens, will your team crumble or command? Stop wondering about your cyber readiness. Join Mandiant for an interactive tabletop exercise where you'll be thrust into the heat of a critical cyber-attack and forced to make real-time, high-stakes response decisions. See exactly how prepared you are against real-world scenarios.