Skip to main content

Cybersecurity Conference (VIRTUAL)

Tuesday, Dec. 9
 8:20am - 4:40pm

(Check-In )

Add to Calendar

Online

8.00 Credits

Member Price $279.00

Price will increase by $35 after 12/2

Non-Member Price $404.00

Price will increase by $35 after 12/2

Overview

CPA firms and accounting departments are being specifically targeted and are under attack. Find out what you can do today to keep your data safe. This CTCPA conference, sponsored by the Technology Committee, is designed for CPAs. With cyber crime on the rise, you can't afford to miss this informative program.

Notice

By registering for this program and, accordingly, receiving the eMaterials, you're acknowledging that you understand both the copyright restrictions on your eMaterials and the CTCPA cancellation policy.

Tuesday, December 9

General Session

- Inside the Mind of a Cyber Criminal

Luke Kiely, Founder and Chief Security Officer, Get Busy

Luke Kiely

Luke Kiely | CISO | Founder | Ex-Law Enforcement (Cyber Crime)

Luke Kiely is a dynamic leader at the forefront of cybersecurity, data protection and compliance.

As the Founder and Chief Security Officer of ComplyWise Online, Luke’s journey began with a foundation few in the industry can match: his early career in law enforcement, where he developed his skills in covert operations to track, monitor and apprehend offenders in serious and organised crime, including complex cybercrimes. This front-line experience shaped his pragmatic approach to cybersecurity: understanding not just systems and controls, but the human behaviour behind them.

Transitioning into the corporate world, Luke has held senior leadership roles across global SaaS organisations, where he has built and led cybersecurity, risk and compliance programmes for organisations of all shapes and sizes. His work bridges technical assurance, regulatory obligations and commercial strategy ensuring that security enables, rather than constrains, business growth. Luke’s career reflects a clear purpose: to make cybersecurity practical, accessible and effective. From his early law enforcement work to his current leadership roles, he remains driven by a single goal - building a safer, more secure digital future.

Cyber crime has evolved far beyond amateur hackers and nuisance phishing emails. It is now a highly organized, low-risk and high-profit crime, and accountants have become a lucrative target. With access to financial systems, client identities, payroll data and tax refunds, accounting firms hold the information criminals need to monetize attacks quickly and quietly. 

Drawing on experience as a former law enforcement cyber crime investigator, now a Chief Security Officer advising firms across the profession, Luke will detail how criminals operate, the tools and access they exploit, and the uncomfortable truth that many attacks originate from with a business due to complacency, misplaced trust and the belief that “compliance is enough”.

This session aims to redefine the audience’s understanding of cybersecurity in the accounting world and demonstrate why traditional assumptions are no longer protecting anyone.

This session is available to registrants only.

General Session

- Ignore Previous Instructions: Embracing AI Red Teaming

David Campbell, Head of AI Security, Scale AI

David Campbell

David Campbell Head of AI Security at Scale, AI Boston, Massachusetts

David Campbell is Head of AI Security at Scale AI, where he leads efforts to secure and stress test the world’s most advanced AI systems. With nearly two decades in Silicon Valley’s startup ecosystem, David has built a career at the intersection of infrastructure, security, and cutting-edge AI. He pioneered one of the industry’s first large-scale AI Red Teaming platforms, now used to probe the limits of generative models and harden them against real-world threats.

David’s expertise has been recognized at the highest levels, from briefing the U.S. Congress and U.K. Parliament to advising NATO and the White House on AI risk and resilience. He is a founding member of OWASP AIVSS, helping establish open standards for AI security, and has played a key role in collaborative exercises such as CISA’s JCDC.AI cyber table-top series on AI-driven threats.

Prior to his work in AI security, David spent years shaping security and developer experience at Uber, DoorDash, and Nest Labs. His mission today is clear: align AI innovation with business resilience, so organizations can adopt transformative technologies without sacrificing trust or safety.

In this session, we will explore the journey of Red Teaming from its origins to its transformation into AI Red Teaming, highlighting its pivotal role in shaping the future of Large Language Models (LLMs) and beyond. Drawing from his firsthand experiences developing and deploying the largest generative red teaming platform to date, David will share insightful anecdotes and real-world examples. We will explore how adversarial red teaming fortifies AI applications at every layer—protecting platforms, businesses, and consumers. This includes safeguarding the external application interface, reinforcing LLM guardrails, and enhancing the security of the LLMs’ internal algorithms. Join David as we uncover the critical importance of adversarial strategies in securing the AI landscape.

This session is available to registrants only.

General Session

- Artificial Intelligence and Data Privacy: Connecticut Legislative Updates

Sherwin Yoder, Partner, Carmody Torrance Sandak & Hennessey LLP

Sherwin Yoder

Sherwin M. Yoder is a technology lawyer with a litigation background. He is a partner at Carmody Torrance Sandak & Hennessey LLP, where he leads the firm’s Privacy and Data Security practice. Sherwin helps Connecticut organizations and their service providers to assess and manage their peculiar technology and data protection compliance needs. When there is a data breach, Sherwin coaches organizations through investigation and reporting, including related regulatory action and litigation. Sherwin has assisted entities and individuals in investigating and civilly prosecuting others for computer crimes involving theft of confidential information and breaches of privacy. He serves as outsourced Chief Privacy Officer and Data Protection Officer and is a certified privacy professional (CIPP/US, CIPP/E, CIPM) with the International Association of Privacy Professionals.

Session details coming soon!

This session is available to registrants only.

General Session

- From Paper to Practice: How to Build a Real Security Program

Luke Kiely, Founder and Chief Security Officer, Get Busy

Luke Kiely

Luke Kiely | CISO | Founder | Ex-Law Enforcement (Cyber Crime)

Luke Kiely is a dynamic leader at the forefront of cybersecurity, data protection and compliance.

As the Founder and Chief Security Officer of ComplyWise Online, Luke’s journey began with a foundation few in the industry can match: his early career in law enforcement, where he developed his skills in covert operations to track, monitor and apprehend offenders in serious and organised crime, including complex cybercrimes. This front-line experience shaped his pragmatic approach to cybersecurity: understanding not just systems and controls, but the human behaviour behind them.

Transitioning into the corporate world, Luke has held senior leadership roles across global SaaS organisations, where he has built and led cybersecurity, risk and compliance programmes for organisations of all shapes and sizes. His work bridges technical assurance, regulatory obligations and commercial strategy ensuring that security enables, rather than constrains, business growth. Luke’s career reflects a clear purpose: to make cybersecurity practical, accessible and effective. From his early law enforcement work to his current leadership roles, he remains driven by a single goal - building a safer, more secure digital future.

A Written Information Security Program (WISP) is a regulatory requirement for accounting firms, yet far too many exist only as a static document rather than an operational security framework. When a cyber incident occurs, an outdated or poorly implemented WISP provides no meaningful defense and offers limited evidential value to regulators, insurers or clients. 

In this session, Luke will clarify what a WISP is intended to achieve, why many current implementations fall short and how firms can mature their security governance to meet both legal obligations and real-world threats. Attendees will be guided through the essential components of an effective WISP, including risk-based controls, clear accountability, measurable outcomes and ongoing operational oversight.

This session provides a pragmatic blueprint for transforming a WISP from a check box exercise into a foundational element of a firm’s protection and resilience.

This session is available to registrants only.

General Session

- Cyber Training System Shoot Out

Jeff Cappa, Senior Cyber Forensic Analyst, Whittlesey Technology

Jeff Cappa

Education
• BBA in Management, Western Connecticut State University, Danbury, CT
• MS in Cybersecurity, Sacred Heart University, Fairfield, CT

Professional Experience
• Cybersecurity and Digital Forensics Analyst
• Expertise in penetration testing, vulnerability scanning, digital forensics and network architecture
• Maintains Security Awareness Programs for Whittlesey and clients
• Over 12 years of professional IT experience
• Previous role of IT Director at digital media company
• Worked as senior analyst at Fortune 500 company

Professional Activities
• ACE – AccessData Certified Examiner
• Member, Information Systems Security Association (ISSA), CT Chapter

Learn about the options for training your staff on cybersecurity so they can protect your firm/company from a compromise or breach. This shoot-out will compare the leading cyber security awareness systems on the market for small- to medium-sized firms and companies, to help you find the right fit for your firm or business!  We will review different systems, comparing their costs, benefits, and differences. In addition, we will outline why training is still the number one way to protect your firm/company from attack and what makes a cybersecurity awareness program successful.

This session is available to registrants only.

General Session

- Cyber Insurance: Do You Have the Required Controls in Place?

Daniel Palmer, Risk Strategies | Pace

Session details coming soon!

This session is available to registrants only.

Optional Session

- Live System Compromise WITH MFA Enabled: Technical Session by a White-Hat Hacker

Jeff Cappa, Senior Cyber Forensic Analyst, Whittlesey Technology

Jeff Cappa

Education
• BBA in Management, Western Connecticut State University, Danbury, CT
• MS in Cybersecurity, Sacred Heart University, Fairfield, CT

Professional Experience
• Cybersecurity and Digital Forensics Analyst
• Expertise in penetration testing, vulnerability scanning, digital forensics and network architecture
• Maintains Security Awareness Programs for Whittlesey and clients
• Over 12 years of professional IT experience
• Previous role of IT Director at digital media company
• Worked as senior analyst at Fortune 500 company

Professional Activities
• ACE – AccessData Certified Examiner
• Member, Information Systems Security Association (ISSA), CT Chapter

We are no longer “safe” with just MFA (Multi-Factor Authentication).  Join this live demonstration of an MFA bypass attack against a Microsoft 365 account.  MFA bypass attacks are currently being executed in high volume at all businesses. Learn why hackers are doing this, how AI (Artificial Intelligence) is used, and most importantly, how to protect your business from these dangerous attacks!

This session is available to registrants and their guests

Non-Member Price $404.00

Member Price $279.00