PCI Europe 2009: Speakers

PCI Europe Logo Small

Plenary Speakers

Peter Baird,  PCI DSS Manager, TUI Travel PLC

Peter has worked in TUI Travel for 6 years and on PCI DSS for over two years, initially in TUI UK and now as the Global PCI DSS Manager for TUI Travel PLC which has over 80 companies worldwide that come under the scope of PCI DSS. Peter has previously worked on call centre solutions, co-branded credit cards and consumer credit in the Home Shopping, Banking and Travel industries with a call centre solution for TUI UK winning an industry award.

__________________________________________________________________________________________________________

David Civile, Programme Manager and Independent Consultant

David is an International Senior Project manager and business analyst who holds a B.S. degree in Management, IT and Economy. He is an experienced senior executive with strong skills in strategic, tactical, and management aspects of technology, security management, risk management and services provision. In his professional career, David has built up tremendous experience in leading multimillion dollar projects and delivering multiple complex programs to achieve cost effectiveness and high performance in information technology services and solutions. Having worked on an international level in numerous business domains, David gained knowledge ranging from service provisioning to client and vendor management. He has experience in translating requirements into workable and achievable processes from a business dimensions perspective.

Having worked with multiple security methodologies (including PCI DSS, Sox, ISO27xxx, ISO 19xxx, Hipaa, Lean, and ITIL), David has become particularly knowledgeable on the alignment of IT and communication technology to serve business aims with an emphasis on improvement and the use of information in business processes. He has worked in all major industry sectors on strategic initiatives to ensure and maximise business advantage from technology.  During his last major projects he implemented the PCI DSS into different firms from different business domains, integrations running programs and defining policies into procedures leading to process.

__________________________________________________________________________________________________

Christophe Dolique, Chairman, SPVA

A co-founder of the SPVA, Christophe has sat on the Board of Directors and held the position of Chairman since its launch in April 2009. Christophe has also served as Global Marketing & Services Operations Director at Ingenico since June 2007. Prior to that, he was the Senior VP Telecom Strategy and Marketing at Gemalto, where he redefined the strategy and positioning of the company in the telco/wireless space and its related marketing.

Between 1999 and 2005, Christophe held the VP Strategic Business Development and Global Accounts position at Sybase 365, a leading global provider of network services and mobile payments. At Oberthur Card Systems (1997-1999), he was successively Business Director of the GSM Unit, and Head of Product Marketing & Business Development. He also held Sales management positions at Philips Business Communication Division (1995-1997) and IBM France (1986-1991).

Within Ingenico, Christophe Dolique is in charge of global marketing covering products marketing, services marketing and communication, and Services delivery (operation + sofware). Aged 46, Christophe Dolique holds a Master in Information Technology (Montpellier, 1989).

_______________________________________________________________________________________

Wenlock Free, Vice President of Business Development, SecurityMetrics

Wenlock is currently the Vice President of Business Development for SecurityMetrics. He has worked with data security for over 7 years, during which he has been involved with compromises, forensic incidents, audits, vulnerability assessments and payment terminal security.  He has had first hand experience watching the consequences of companies that have chosen not to secure their sensitive customer data.

Wenlock’s educational background was in International Sales and Marketing. He has over 20 years of experience in the sales and training industry. Public presenting was the early focus of his business career providing training in 48 states, the UK and Canada. He was invited to be the Director of sales for CORDA Technologies with an emphasis on the financial marketplace. He enjoys building new business relationships, strategic planning and Vintage Automobiles.

___________________________________________________________________________________________

David Froud, VP, Global Compliance Services, EMEA/APAC, Trustwave Ltd

David has 9 years experience in areas of Information, Internet, and Computer Security, including regulatory compliance (both Federal and Corporate), remediation support, security framework design, and best business practices.  He has served as a Managing Consultant / Project Manager for several Fortune 500 ‘Enterprise Class’ clients and has performed dozens of on-site assessments for Level 1 Merchants and Service Providers in the United States and overseas.  He now serves as Vice President of Global Compliance Service for EMEA and APAC.

___________________________________________________________________________________________

Thomas Raschke, Senior Product Marketing Manager, Security Solutions, Verizon Business

Thomas is a product marketing manager for Verizon Business. In this role he is responsible for developing global product strategy and marketing plans for Verizon Business’ security, risk, and compliance portfolio. Previously, he was an industry analyst working for Forrester Research and IDC, where he effectively launched and managed both firms’ European security research services. Thomas is also an experienced consultant, having led strategic advisory to security vendors and end-users, and having worked as a marketing & communications advisor prior to his analyst days. He is a frequent keynote speaker, and has developed and chaired events of all sizes; he is often quoted in the press. Thomas holds a M.Sc. from the University of Paderborn, Germany. He is based in Copenhagen, Denmark and speaks English and Danish in addition to his native German.

___________________________________________________________________________________________

Eamonn Skyrme, Senior Manager, PCI Compliance & Scheme Management, RBS Worldpay

For the last 12 years Eamonn has worked in the cards industry for Streamline (within the Royal Bank of Scotland Group) as a Credit and Compliance specialist, and holds responsibility for the ongoing implementation of  PCI DSS (Payment Card Industry Data Security Standard) for Streamline’s merchants – Streamline is the largest card payment processor in Europe. He originally started work as a management trainee for a major high street retailer, before working in a variety of sales and branch banking functions in his early banking career with NatWest.  Eamonn also holds responsibility for liaising with the PCI Compliance Council and main card schemes on PCI-DSS issues.

___________________________________________________________________________________________

Lars Syberg, PCI Manager, FortConsult

Lars is PCI Product Manager for the Danish based QSA, FortConsult. He has been working with PCI for the last five years and has been involved in a large number of projects related to data centres and banks. Lars is a member of the steering group for a number of the largest European banks and is also member of a Scandinavian bank sector PCI working group.


Lars holds a HD in Informatics and Management Accounting from Copenhagen business school with specialization in security investment models and business processes.

___________________________________________________________________________________________

Patrick Wheeler, Former IT Audit Manager, Levi Strauss & Co.

Patrick has been involved in IT Consulting, Business, Engineering and Security for over 16 yrs.  He has a Bachelors (BSEE) and an MBA and is a registered professional engineer.  His background includes fun job titles like Security Architect, Audit Manager, Inspector, Systems and Security Analyst, Project Manager, IS & Operations Director and VP of Operations.

His business, IT and best practices experience includes audit and compliance functions including PCI as well as internal & external financial & technology audits, security reviews, SAS-70 and Department of Defense.  With a legal support background he has served as an expert witness on various aspects of best practices and industry standards.

Patrick has been involved in many industries from Government Agencies and Banking through Fashion and Retail as well as technology startups and such well known firms such as Apple, Webex, Tibco, Brocade and Wine.com.  Prior to moving to Europe, where he is currently consulting in the security field, he served in California’s Silicon Valley specializing in security, compliance and operational efficiency topics.

As the European IT Audit Manager for Levi Strauss & Company he managed their global PCI program.  He remains active and opinionated within the PCI community encouraging adoption and improvements to security as well as the PCI program.  Personal interests include driving old cars too fast while taking photographs (in a well controlled secure environment).

___________________________________________________________________________________________

Steve Wilson, Head of PCI DSS Compliance, Visa

Steve Wilson is Head of Payment Security and Reputational Compliance for Visa Europe.  Steve has over 13 years experience in the card payments industry, firstly with JCB and then nine years with Visa.  Whilst at Visa, Steve has managed a variety of roles, both in Marketing and Risk Management.

Steve’s current position brings him into regular contact with banks, merchants, software vendors and security companies.  Steve and his team, which includes both technical and account management staff, are responsible for increasing the pace of compliance, thus minimising the risk of financial and reputational damage to all parties within the payment chain.  He presents regularly at conferences within Europe and across the world, as well as running training on PCI DSS.


Education Seminar Speakers

Nick Barratt, RSM and Security Consultant, SafeNet

Nick  is a seasoned IT security professional with over twelve years’ industry experience. Throughout his career he has worked with technologies associated to IDS and IPS, anti-virus and anti-spyware, content delivery and protection, and high speed internetworking. Today, his specialisations include encryption, tokenisation, key management and intelligent data protection.

Recently, Nick has focused his attentions on providing consultancy and technical advice to enterprises and the public sector on topics such as PCI DSS, SOX, Data Protection and general compliance based technology issues. He maintains very strong relationships with a number of experts in the PCI DSS arena and regularly participates in a number of working groups and special interest groups within the security industry.

__________________________________________________________________________________________

Robert Eatwell, Product Line Executive, Endpoint Security, McAfee

Rob Eatwell is line of business manager for McAfee’s endpoint security business in EMEA, for whom he has worked for the past 14 years.  In total Rob has nearly 30 year’s experience in IT, including ownership of one of the first microcomputer retail store chains outside central London, followed by entrepreneurial activity in the formative days of commercial PC-based business computing.  With McAfee, Rob has seen the company grow from a small unlisted anti-virus software developer through to the position McAfee holds today as a world-leading security and risk management vendor.  With McAfee’s recent acquisition of Solidcore, Rob has been given EMEA responsibility for ensuring that customer needs are understood and that McAfee’s sales and pre-sales support organisation stand ready to provide accurate and usable guidance on this useful technology.

___________________________________________________________________________________________

Ian Eyles, Director of European Business, Security Metrics

Ian began his career with British Telecom working in the Data Communications and Networking arena. After 13 years, he moved to a senior technical position at Barclaycard to support one of the largest bank owned terminal estates in Europe, which had in excess of 170,000 devices. Within 6 months, Ian was assisting with the design, development and testing of the first hand-held terminal supported by Barclaycard with a major global terminal vendor. Changes in the retail market away from terminals to integrated systems and the demand for centralised processes and real time high speed authorisation, required new solutions for large merchants. Bespoke solutions that use managed data networks for real time authorisation and file transfer of card data soon became standard products.

Over the course of 20 years, Ian worked with pan-European multi-currency merchants acquired by Barclaycard to enable cross-border transaction processing through a single acquirer relationship. At APACS, the UK Standards body, Ian has held the chair for the 29/50 development group and up until leaving Barclaycard after 20 years of service, held the chair of the PCI working Group. During the last 3 years at Barclaycard, he was responsible for PCI DSS Compliance and Compromise Management, leading a dedicated team supporting merchants at all levels, industry groups, seminars and exhibitions. Since leaving Barclaycard Business in 2007, Ian has been Director, European Business for SecurityMetrics managing key acquirer relationships predominantly in the level 4 arena.

___________________________________________________________________________________________

Richard Jones, EMEA Alliance Manager, Trustwave Ltd

Richard is focused on the delivery of large scale compliance programs for acquiring banks and payment service providers. Since 2004, he has been working with all levels of merchants, leading acquiring banks and security solutions vendors with regards to PCI DSS compliance, and has firsthand knowledge of the challenges that must be overcome to maximize mass market adoption of PCI DSS compliance.

Having become part of Trustwave as a result of the acquisition of UK QSA One-SEC, Richard’s experience in business development began in 1998, specialising in managed security solutions, biometrics and Y2K compliance.  Prior to becoming involved in information security, he managed the UK channel for Firefox and worked as an account manager for ICL.

____________________________________________________________________________________________

Manav Khurana, Head of Industry Marketing, Aruba Networks, Inc.

Manav is the head of the industry marketing organization at Aruba Networks where he is responsible for solutions and go-to-market strategy for different vertical markets.

No stranger to wireless LANs, mobility and security applications, his involvement dates back to the pre-standard days of wireless LANs. Manav has firsthand experience with mobility implementations at large retail, healthcare and government organizations. Prior to Aruba, he was the senior product manager for at Motorola’s wireless business unit and Meru Networks.

Manav holds an MBA from Santa Clara University and a B.S. in Electrical Engineering from the University of Rochester.

___________________________________________________________________________________________

Hervé Liotaud, Sales Director France/CH/BeNeLux, LogLogic

With 20 years of experience in the IT industry, Hervé joined Exaprotect, now part of LogLogic – the leader in information security management and compliance -  in 2006 as Senior Sales Director for France, where he developed the channel and secured various large customers from the CAC40 index. After starting his career at Sagem, and successful experiences at Verizon and McAffee, Herve works directly with accounts in an indirect model with Value Added Resellers, promotes the VAR Channel, and manages the sales and pre-sales engineers team.

______________________________________________________________________________________

Ryan Rubin, Associate Director, Protiviti

Ryan is an Associate Director in Protiviti’s London office and leads Protiviti’s PCI DSS service offering for the CEMEA region. Additionally he co-ordinates European security, privacy and computer forensic services.

Ryan has extensive breadth and depth of 12 years of experience supervising and delivering business focussed information security consulting and assurance services. Prior to joining Protiviti, he worked at a Big Four audit firm for over 10 years in their security and privacy practice.

Ryan leads regional PCI DSS projects supporting merchants, service providers, issuing and acquiring banks with their PCI DSS requirements. He has also provided consulting services with card brands and payment providers in the past.

Ryan has served clients globally across several industries providing a wide breadth of IT risk and governance related consultancy services including: PCI DSS engagements, strategy and architecture, identity and access management, penetration testing, application and database security, infrastructure implementation, IT audit and due diligence, forensic investigations, risk management and e-Discovery. He has also provided internal and external security training on topics ranging from e-Crime and fraud, identity and access management, ethical hacking, PCI DSS compliance and incident response handling. Ryan holds various industry qualifications including QSA, CISSP, CISM, CFHE and a Master of Science degree in Computer Science.

____________________________________________________________________________________________

Richard Running, Vice President, Marketing, Security Metrics

Richard is the vice president of marketing for SecurityMetrics, with responsibility for global campaign and field marketing, partner and product marketing, and branding and marketing communications. He has more than twenty years of experience building successful software technology companies. As an executive at Novell, and more recently Symantec, Richard was responsible for driving top and bottom-line company growth through fiscally accountable and operationally efficient marketing. His leadership has helped to establish over $2 billion in global software products over the past two decades. Throughout his career, Richard has directed and integrated diverse teams across product management, sales support, alliances, field and global marketing.

________________________________________________________________________________________

Gorka Sadowski, Senior Technical Consultant, LogLogic

Gorka is involved in all technical and technology-related activities for end-clients and partners in the region of Southern Europe. He is an expert in risk management methodologies and in the use of technology in business processes of large enterprises. Before LogLogic, Gorka was Director of the Security Group for Unisys France, where he managed a team of consultants in security advisory, and was in charge of project management in the integration of complex solutions for global CAC40 corporations.

Gorka spent 15 years in the USA, where he was Director of Emerging Technologies at NetScreen in the Silicon Valley. There, he was in charge of the strategy for technologies that complement NetScreen’s main focus. Gorka also held the position of Director of the Security Group for CTP, a software development firm specialized in the design and implementation of client/server applications to automate business processes of the largest American companies.

_________________________________________________________________________________________

Sarah Swatman, EnCE CISSP, EMEA Technical Manager, Guidance Software

Sarah is a Technical Manager for EMEA, with responsibility for managing the technical aspects of sales and implementations across commercial, government and public sector organisations. She covers Europe, Middle East and Africa. Sarah has 11 years experience in the IT software and services industry. Prior to joining Guidance Software, she started her career as a developer, moving into consulting at CA specialising in IT Security and Information Management. Sarah has extensive experience in Security Information Management, Audit and Compliance in relation to multiple sectors, particularly Retail and Finance. Sarah received her Bachelor of Science in Applicable Mathematics in 1998 and has since achieved other industry recognised qualifications including CISSP and EnCE.

_________________________________________________________________________________________________

Nitzan Tal, Regional Marketing Manager, VeriFone

Nitzan has been with VeriFone since 2007, serving as Product Marketing Manager for the regional marketing team in Asia. In 2009, he was promoted to Director of Marketing for Continental Europe and Southeastern Europe regions, where he is responsible for driving and executing strategic product planning and product roadmaps, market analysis, product lifecycle management, and marketing activities and programs solution development.

Nitzan brings more than 7 years experience in marketing and business development positions in such industries as electronic payments, semiconductors and wireless transmission.

He holds an MBA in Marketing and Finance, and a BA in Business Administration and Middle East History, from Tel Aviv University in Israel.

_____________________________________________________________________________________________

Ciske van Oosten, PCI Practice Leader, EMEA, Verizon Business

Ciske is the Practice Leader for PCI Security in EMEA for Verizon Business.  He has sixteen years of experience in information security, risk management and compliance and has been involved with PCI Security for the past six years.  Ciske made significant contributions towards establishing and leading the first certified Qualified Security Assessor (QSA) company, offering global PCI Security compliance services.

In addition, Ciske has worked as head of professional services at several leading QSA’s, including Dimension Data and Trustwave. During this time, he has overseen more than a thousand PCI Security assessment projects for merchants, service providers, processors and acquiring banks in a diverse range of industries.  Ciske holds various industry qualifications including ISO/IEC 27001 Lead Auditor, CISSP, CISM, and a Master of Science degree in Information Security.