2009 San Francisco CISO Executive Summit
October 15, 2009 | Parc 55 Hotel-
Joshua Corman
Research Director, Enterprise Security Practice
The 451 Group
Joshua Corman serves as Principal Security Strategist for IBM Internet Security Systems. With more than a decade of experience in security and networking software, Corman is responsible for driving the strategy for emerging technologies including secure virtualization and secure cloud computing. Network World magazine recently chose to recognize Corman as a “Top 10 Infl uencer of IT for 2009.”
Previously, Corman was in product development at vCIS Technology, Inc. until IBM Internet Security Systems acquired the company in 2002. Striving to educate and challenge the industry, his thought leadership includes ‘7 Dirty Secrets of the Security Industry’ and the ‘Evolving Threat’ education and awareness campaign. Corman received a Bachelor’s degree in Philosophy, Phi Beta Kappa, Summa Cum Laude, from the University of New Hampshire.
-
Michelle Dennedy
Chief Governance Officer, Cloud Computing
Sun Microsystems, Inc.
Michelle Dennedy, Chief Governance Offi cer, Cloud Computing works with Sun Microsystems’ business, technical and legal teams to develop and adhere to the best data governance policies and processes possible for cloud computing. Prior to this role, Dennedy was Sun’s Chief Privacy Offi cer where she was responsible for the development and implementation of Sun’s data privacy policies and practices. She co-founded Sun’s internal Privacy Council, which is dedicated to promoting privacy practices to protect Sun’s relationships with its customers and employees. Dennedy has a J.D. from Fordham University School of Law.
-
Eran Feigenbaum
Director of Google Apps Security
Google Inc.
As the Director of Security for Google Apps, Eran Feigenbaum defi nes and implements security strategy for Google Apps. Prior to joining Google, Feigenbaum was the U.S. CISO for PricewaterhouseCoopers (PwC). At PwC, he led a team responsible for all aspects of network, server, application and desktop computer security, including security policies, standards and enforcement. Earlier, Feigenbaum spent several years designing and implementing cryptosystems for eCommerce solutions for Fortune 1000 clients and government agencies.
-
Malcolm Harkins
CISO & GM, Enterprise Capabilities, IT Grp.
Intel Corporation
Malcolm Harkins is responsible for Intel's IT infrastructure & application security, data privacy & protection, Sarbanes Oxley, and overall IT controls & compliance activities. He is also responsible for corporate business continuity. His overall mission within Intel is to drive the adoption and continued operation of controls to mitigate information risks to acceptable business levels. Harkins has been with Intel since 1992 and has had responsibility for Information Security since 2002.
Harkins' prior roles include positions in finance, procurement and operations. He also program managed IT benchmarking and Sarbanes Oxley systems compliance efforts and he was the profit and loss manager for Intel's Flash Product Group in the late 90's. He also co-authored an IT services business plan that lead to the creation of Intel Online Services, an external e-commerce hosting company.
Harkins has an MBA in Finance and Accounting from the University of California at Davis and a BA in Economics from the University of California at Irvine. Harkins is an active and accomplished speaker and whitepaper author.
-
Richard Jackson
General Manager Information Risk Management
Chevron
Richard Jackson is the General Manager of Global Information Risk Management for Chevron Corporation and is responsible for the identification and management of risks relative to Chevron’s business information and information technology assets. In this capacity, Jackson is responsible for the security of Chevron’s worldwide computing infrastructure and information assets. Other areas of responsibility include data privacy, records management, information technology intellectual property rights and information technology export compliance. He also serves as Corporate Champion and provides information risk management consultation services to Chevron’s operating companies worldwide.
Jackson formerly served as Chairperson of the American Petroleum Institute’s Information Technology Security Forum and Executive Director of the FBI’s San Francisco Bay Area InfraGard Chapter. Jackson earned a Bachelor’s degree in Mechanical Engineering from Howard University and a Master’s degree in Business Administration from Pepperdine University.
-
Arthur Lessard
CISO
Mattel, Inc.
Arthur Lessard is the Chief of Information Security for Mattel, responsible for protection of company assets and digital intellectual property as well IT Security Architecture and Governance. Arthur's organization develops and coordinates implementation of security policy and standards for Mattel business units, ensures compliance with PCI and S/Ox, and drives development of new security-oriented services and projects.
Prior to joining Mattel Arthur was VP of Worldwide Security for Technicolor, responsible for protection of customer content and intellectual property throughout the various Technicolor services organizations. His role encompassed managing both physical and information security in the production environments, and interfacing with the IT organization for network and business security. Arthur engaged external auditors for site visits and worked with various law enforcement agencies, the MPAA, FACT and other organizations related to the control of movie piracy activities.
In past years Arthur led Disney's IT Security Policy and Strategy organization, served as head of IT Security Architecture for Disney, and was Director of Security and Network Infrastructure for Questia Media Inc.
-
Jack Phillips
CEO & Co-Founder
IANS
Jack Phillips is CEO & Co-Founder of IANS (http://www.ianetsec.com), a peer-based research firm supporting the information security profession located in Boston, MA. In this role, he leads all executive leadership research, and frequently moderates discussions among senior information security executives for IANS.
Mr. Phillips has helped launch four start-up ventures in the media and information publishing industry over the past 15 years. He has been focused on the information security profession since founding IANS in 2001. Mr. Phillips is a graduate of Harvard Business School and Williams College, and lives with his family in Boston, MA.
-
Nils Puhlmann
CISO
Cloud Security Alliance
Nils Puhlmann is the Co-Founder of the Cloud Security Alliance, a community of more than 4,000 security professionals with the goal to promote the use of best practices for providing security assurance within cloud computing, and provide education on the uses of cloud computing to help secure all other forms of computing.
As Chief Security Offi cer of Qualys, Puhlmann was responsible for security, risk management and business continuity planning for Qualys. His responsibilities included the security of the cloud-based QualysGuard SaaS platform. He also led the Qualys CSO Advisory Board and evangelized at various international industry events in areas of security management and cloud security. Prior to Qualys, Puhlmann was the CISO for Electronic Arts, with global responsibility for information security, intellectual property protection, risk management, compliance, physical security, forensics & investigations and business continuity management/disaster recovery. He was also previously the CISO at Robert Half International, where he had global responsibility for managing information security, risk management, privacy, forensics & investigations, CERT and business continuity management enterprise wide. Puhlmann also was previously Director Global IT & Security and Chief Privacy Officer at Mindjet Corp, where he was responsible for managing Mindjet’s global information security, physical security and privacy programs. He was Senior Manager Product Security at Adobe Systems, responsible for creating and managing Adobe’s product vulnerability program, overseeing security assessments of Adobe applications, driving product security certifi cations and promoting secure development practices. He created Adobe’s product security incident response team, chaired Adobe’s Security Task Force and managed Adobe’s fi rst Common Criteria Certifi cation. Puhlmann held senior positions at Nortel Networks and START Amadeus, and was an independent security consultant with clients such as the State of California. He maintains numerous security certifi cations, including CISSP-ISSMP and CISM. He has held several Board of Directors positions (ISACA Silicon Valley, OVAL), is a member of the CSO Interchange, the CISO Executive Council and a subject matter expert for ISACA and ISC2. He is also a member of the Advisory Council for the CISO Forum of ISSA.
-
Sanjiv Ranjan
Chief Security Architect
Genentech, Inc.
Sanjiv Ranjan is Director of IT Security, Privacy and Compliance at Genentech, responsible for establishing and communicating IT security strategies, solutions roadmaps, policies, controls and governance. His team is also responsible for the engineering of the end-to-end IT security solutions, including identity management, network security, IT-DR, privacy, backend and compliance.
With more than 20 years of IT leadership experience, Ranjan has held a wide variety of leadership roles at Cincinnati Bell Information Systems, The Associates and American Airlines. He holds an Engineering degree from BIT, Mesra, India, and an M.S. in Computer Science from University of Mississippi.
-
-
Randall Spratt
EVP, CTO & CIO
McKesson Corporation
Randall N. Spratt is Executive Vice President and Chief Information Officer for McKesson Corporation. Spratt is responsible for McKesson's global technology strategy and technology infrastructure operations for the Corporation. A passionate executive with a strong emphasis on sound governance, good process, and constant innovation, he is leading the evolution of McKesson's information technology as a competitive edge in every business line.
Spratt has been with McKesson for more than 20 years, most recently as Chief Process Officer for McKesson Provider Technologies (MPT), the company's medical software and services division based in Alpharetta, Georgia. He also managed MPT's Business Development, Information Technology, and Strategic Planning offices, as well as MPT's Technology Services business.
-
Tim Stanley
CISO
Continental Airlines, Inc.
Responsible for the development and execution of CO's enterprise-wide IT security strategy and driving implementation of security related programs within each business unit. Also responsible for development and implementation of corporate IT security and control policies and standards, as well as ensuring that appropriate tools and metrics are in place to allow for effective monitoring, measurement and control of risk as it relates to IT security and PCI compliance.
-
Michael Wilson
VP & CISO
McKesson Corporation
Mike Wilson took on the role of Chief Information Security Officer (CISO) for McKesson in early 2008. Mike has 20 years of experience in information security and risk management.
Mike’s career has spanned the globe – from New Zealand and Australia to North America – and has been primarily focused on the healthcare and financial services industries. Prior to McKesson Mike held senior strategy and practice management responsibilities in the professional services and consulting arena. Mike has held information technology and security roles for various organizations predominantly in the financial services industry.

