Upcoming Chapter Events

Below are upcoming chapter conferences, seminars, review courses, and other events.  Prior chapter events can also be viewed.

For information on our event policies, see https://isaca-gwdc.org/event-policies/.

Loading Events

« All Events

Cyber Impact and Strategy Analysis Seminar

October 2 @ 9:00 am - 5:00 pm EDT
GWDC Members $200, Non-GWDC Members $300

 

Cyber Impact and Strategy Analysis Seminar

Senior management often has two questions regarding cyberattacks: How would cyberattacks affect our organization and what should we do about them? Business Impact Analyses, as they have been performed for decades, are inadequate. The determination of RTO and RPO may be meaningless in the face of stolen information and ransomware attacks that reflect what business leaders would like to be done rather than what IT can do. Moreover, new government rules require analysis and disclosure that necessitate an understanding by executive management of what the impact of a cyberattack would be if an attack were to occur. This one-day seminar/workshop, combining instruction with a hands-on case study, presents practical methods for understanding the potential impact of cyberattacks, as the basis for remediation, reporting and recovery.

Intended audience: Management and staff in Information Security, Business Continuity Management, IT Auditing, Risk Management, Finance, Office of General Counsel.

Registration closes on Oct 1 @ 5pm.

Register Today!(opens in new tab)

 

 

Share this Event

If you are interested, planning to attend, or attending this event, please share with your colleagues across your social media networks.

 

 

Event Details

Date and Time

The workshop will be held on October 2, 2026 from 9:00 am to 5:00 pm.

Add this event to your calendar using the Add to Calendar link at the bottom of the page.

 

Virtual Event

The conference will be held using Zoom.

Prior to the event, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits.

 

Pricing

The fee for GWDC Members is $200 for the workshop.
The fee for all other registrants is $300 for the workshop.

To become a member and take advantage of the member rate for our events, among other benefits, join ISACA(opens in new tab) and select the Greater Washington D.C. Chapter as your local chapter.

 

Event Policies

Cancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details.

The GWDC welcomes your comments, complaints, suggestions, questions, and other feedback concerning our website information and services.
All complaints should be submitted through the Registration Contact Form.

 

 

ISACA AI Certifications

ISACA has launced new certifications in the AI space: Advanced in AI Audit™ (AAIA™) and Advanced in AI Security Management™ (AAISM™). Click on the links below to learn more about these certifications and how they can further your career in AI. If you are interested in taking one of these certification exams, check our events calendar for upcoming review courses.

Learn more about AAIA(opens in new tab)Learn more about AAISM(opens in new tab)

 

 

Course Outline

 

1. The Context of Cyber Impacts

  • Different types of attacks, different impacts
    • Theft of information
      • Personally identifiable information (PII)
      • Secrets
      • Digital resources
    • Attacks on Data Integrity
      • Ransomware
      • Destructive attacks
    • Inability to Perform Business Functions
      • Untrusted information
      • Lost or unavailable data
    • How the impacts would be felt
      • Financial
      • Sales 
      • Operational 
      • Reputational
      • Regulatory
      • Societal
    • Case Study #1

2. Why Traditional Business Impact Analyses Are Inadequate

  • Planned vs. actual variance
  • Emphasis on premises, personnel and equipment
  • Lack of meaningful metrics
  • Do Business Impact Analyses still make sense

3. The Cyber Risk Analysis Process

  • Scope and objectives within the cyberattack cycle
    • Awareness through post-recovery
    • The “Danger Zone”
  • Planning
    • Top-down versus bottom-up
  • Research
  • Data gatherings
    • IT view of impacts
    • Business view of impacts
  • Analysis
    • Leading to strategies
    • Categorization
      • Data theft
      • Critical application unavailability
  • Reporting
    • Obtaining buy-in for needed changes
  • Case Study exercise #2

4. Strategies to Mitigate Business Impact of Cyberattacks

  • Dependency-based strategic approaches
    • Cash flow and capital
    • Human resources
    • Information
    • Technology
    • Systems
    • 3rd parties
    • Equipment
  • Business process-based strategic approaches
    • Procure to Pay (P2P)
      • Financial systems
      • Alternate SaaS applications
    • Order to Cash (O2C)
      • Contingent arrangements
      • Co-opetition
    • Case Study exercise #3

5. Strategies to Shorten System Recovery Times

  • Digital Forensics and Incident Response (DFIR)
  • Cyber health check
  • Scanning software and data
  • Retention of backups
  • Practice
  • The Human Factor

6. Cyber Insurance to Mitigate Cyber-Related Losses

  • Cyber insurance concepts
  • Cost and coverage
  • Policy complexity
    • Cyber Liability vs. Cyber Breach insurance
    • First Party vs. Third Party insurance
    • Other cost factors

7. Long-Term Cyberattack Mitigation Strategies

  • Cyber-response governance
  • Specialized personnel
  • Zero Trust Architecture
  • Threat intelligence
  • Artificial intelligence

8. Conclusion

 

 

Interested in Speaking at a Chapter Event

If you are interested in speaking at an upcoming conference, please visit the Call for Speakers page and complete the form.

Call for Speakers(opens in new tab)

 

Instructor

 

Steven J Ross
Executive Principal @ Risk Masters International LLC

Mr. Ross is Executive Principal of Risk Masters International and holds certification as a Certified Information Systems Security Professional (CISSP) as well as a Master Business Continuity Professional (MBCP), a Certified Information Systems Auditor (CISA) and a Certified Data Privacy Solutions Engineer (CDPSE). Mr. Ross is a specialist in the field of information systems security and control, specializing in Information Security, Business Continuity Management, Data Privacy and IT Disaster Recovery Planning services. He has implemented Information Security programs for numerous banks, government agencies and industrial corporations. Prior to founding Risk Masters, Mr. Ross was a Director and global practice leader with Deloitte & Touche.

In consulting engagements, he specializes in planning, policy development, implementation, and standardization of Information Security processes. In recent years, his focus has been on reliability, prevention, detection and recovery from the technical and business impact of cyberattacks. He has published a book, Creating a Culture of Security. He was editor of the multi-volume series, e-Commerce Security, and author of several of the books in the series, including e-Commerce Security: Public Key Infrastructure. Since 1998, Mr. Ross has regularly published the column, “IS Security Matters”, in the ISACA Journal. In 2022, he was inducted into the ISACA Hall of Fame.

 

 

Questions about this Event

If you have any registration questions about this event, please contact us by completing the Registration Contact Form linked below.

Registration Questions(opens in new tab)

 

If you have CPE questions after the event has concluded, please contact us by completing the CPE contact form linked below.

CPE Questions(opens in new tab)

 

 

CPE Information

Earn up to 8 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org(opens in new tab)

 

Poll Questions

Participants must respond to all the poll questions polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls.

 

CPE Distribution and Evaluation Survey

CPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit.

 

Learning Objectives

Participants in this seminar will learn:

  • Long-Term Cyberattack Mitigation Strategies
  • How cyberattacks change the context of Business Impact Analyses
  • The differences in effects of different types of cyberattacks
  • How to conduct a Cyber Impact Analysis
  • Different techniques to develop cyberattack recovery strategies
  • How IT can shorten the time needed for recovery
  • Including insurance in cyber resilience strategies.
  • How to plan for resilience over the longer term

CPE-Related Details

  • Prerequisites: None
  • Advance Preparation: None
  • Program Knowledge Level: Basic
  • Delivery Method:  Group Internet Based
  • Field of Study:  Information Technology – Technical

Details

Venue

  • Virtual Event

Organizer

  • Clifton Persaud (Certifications Program and Special Assistance Requests)
  • Email certifications@isaca-gwdc.org