Walking Through Before, During & After an Incident

Thursday, Sept. 10, Friday, Sept. 18 & 25, 2026 | 2:00PM EDT | 1 Hour Each | 3 CPE

Major, globally visible events—such as the World Cup or Olympic Games—fundamentally change how cyber-physical risk must be identified and prioritized. Events such as these usually are designated as National Special Security Events (NSSEs), based on factors like national significance, projected attendance, and potential threat levels, with the U.S. Secret Service leading security operations.

In Session 1, held Sept. 9, experts discuss how organizations can prepare to support a major event by identifying, quantifying, and prioritizing cyber-physical risks pertaining to operational technologies (OT) deployed for the event.

Session 2, Sept. 18, drills down on the “what if” scenarios developed in Session One that challenged common assumptions that underpin security and resilience planning, focusing in particular on lack of visibility for the operations technology (OT) that ties into IT.

In the closing Session 3, Sept. 25, the focus shifts from prevention to action, examining the operational, policy, and political dimensions of managing a catastrophic incident.

September 10: Mission Ready: Rethinking Risks at High-Profile Events

Major, globally visible events—such as the World Cup or Olympic Games—fundamentally change how cyber-physical risk must be identified and prioritized. Events such as these usually are designated as National Special Security Events (NSSEs), based on factors like national significance, projected attendance, and potential threat levels, with the U.S. Secret Service leading security operations.

Cyber-physical risk is the potential for cyberattacks on networked systems—such as IoT devices, industrial control systems, or medical equipment—to cause real-world damage, including physical injury, environmental catastrophes, or destruction of infrastructure. These risks occur at the intersection of digital, networked software and physical, mechanical processes. NSSEs increase the potential for attacks on such devices as credential readers, environmental control systems (heating, cooling, and water), and hospitals near the events.

Join us as thought leaders from government and industry discuss how organizations can prepare to support a major event by identifying, quantifying, and prioritizing cyber-physical risks pertaining to operational technologies (OT) deployed for the event.

Learning Objectives:

  • Understand the distinct risks to OT in major event environments, especially when systems are temporary, shared across public and private owners, or rapidly deployed

  • Identify which OT-related threats or vulnerabilities tend to have the most significant downstream or cascading impacts, and which are most often underestimated during planning

  • Learn how to assess and model cyber-physical risk across interconnected systems, such as venues, transportation, and broadcast infrastructure
  • Delineate what effective integration between cybersecurity, physical security, and operational stakeholders looks like in practice – and where it breaks down most often

Vitaliy Panych, Senior Cybersecurity & Risk Advisor, World Wide Technology & Former CISO, State of California

Vitaliy Panych
Senior Cybersecurity & Risk Advisor,
World Wide Technology & Former
CISO, State of California
Cory Simpson, CEO, Institute for Critical Infrastructure Technology

Cory Simpson
Moderator & CEO, Institute for
Critical Infrastructure Technology
Jeremy Stanley, Senior Business Solutions Leader, Cisco Systems

Jeremy Stanley
Senior Business Solutions Leader,
Cisco Systems

September 18: Anticipating Trouble: Mapping Dependencies & Challenging Assumptions

After the hard work of assessing cyber-physical risks in advance of National Special Security Events (NSSEs) such as the Olympics or World Cup, the next step is discussing systemic vulnerabilities and planning for blind spots. Every major event runs on a complex, interconnected web of systems, yet the full chain of critical dependencies is rarely mapped and tested.

This session explores complex “what if” scenarios that challenged common assumptions underlying security and resilience planning, with a particular focus on limited visibility into the operational technology (OT) environments connected to IT systems.

Join us as thought leaders from government and industry share how they approach mapping dependencies, looking for unsuspected connections, and work to avoid making assumptions about roles and responsibilities.

Learning Objectives:

  • Outline the process for “gaming out” possible scenarios

  • Establish methods for decision-making during moments of uncertainty or ambiguity

  • Evaluate criteria for partnerships to strengthen responses

  • Delineate best practices for developing effective incident response plans at a scale appropriate to the NSSE

  • Identify where regulatory frameworks may conflict with operational needs

Tatyana Bolton, Principal & Head of Cybersecurity Practice, Monument Advocacy

Tatyana Bolton
Principal & Head of Cybersecurity
Practice,
Monument Advocacy
Abby Deift, Managing Director, FGS Global

Abby Deift
Managing Director,
FGS Global
Michele Iversen, Principal & Head of Geopolitical & Regulatory Risk, The Chertoff Group

Michele Iversen
Principal & Head of Geopolitical &
Regulatory Risk,
The Chertoff Group
Patrick Kelly, Director, Law Enforcement, Booz Allen Hamilton

Patrick Kelly
Director, Law Enforcement,
Booz Allen Hamilton
Nick Reese, Founder & CEO, Triantha

Nick Reese
Founder & CEO,
Triantha

September 25: Moving at the Speed of a Crisis: Integrated Incident Response & Recovery

This panel focuses on the moment of truth: coordinated, rapid, and effective response when the inevitable occurs. When a cyber intrusion escalates into a kinetic crisis—disrupting power, transportation, or public safety at a major event—a unified, cross-domain response is essential.

This panel shifts the focus from prevention to action, examining the operational, policy, and political dimensions of managing a catastrophic incident:

  • How cyber incidents escalate into a kinetic attack, affecting the ability to respond to the critical incident

  • What first responders need to manage the incident

  • What preparations should be made in advance of a critical event

  • When a cyber incident escalates into real-world public safety impacts, how CISA defines its operational role in the first 24–72 hours—coordinating with DHS components, FEMA, state and local emergency management, and private sector owners—while balancing the need for decisive federal coordination with respect for state authority and private ownership

  • The importance of executing a coordinated recovery plan to rapidly restore safety and service to the event

There is a natural tension between preparing for worst-case scenarios and avoiding unnecessary alarm. CISA promotes joint preparedness across cyber and emergency management communities; you can help shift the focus from recovery to restoring public and stakeholder confidence when systems are back online.

Join us as thought leaders from government and the private sector discuss the big picture – that preparing for a cyber attack at a National Special Security Event, responding to that attack, and working to restore confidence – and answer your questions.

Learning Objectives:

  • Identify what first step(s) to take if there is a cyber crisis during NSSA-designated events

  • Outline steps that can contribute to restoring public confidence

  • Review existing joint preparedness agreements to find areas that can be further strengthened

St. John (Singhe) Stanley, Lead international USAR Instructor, Guardian Centers

St. John (Singhe) Stanley
Adjunct Professor, Homeland Security,
CPS, GWU & Founder & CEO, CIRRUS Group
Michael Dunaway, Adjunct Professor, GW, & Founder & CEO, CIRRUS Group

Michael Dunaway
Adjunct Professor, GW, &
Founder & CEO, CIRRUS Group
Robert Thompson, Deputy Associate Director, Threat Hunting, CISA

Robert Thompson
Deputy Associate Director,
Threat Hunting,
CISA
Corey Collings, Technical Director, First Line Technology

Corey Collings
Technical Director,
First Line Technology
Elaine Lammert, Director of Homeland Security Continuing Education Programs, GW College of Professional Studies

Elaine Lammert
Moderator & Director, Homeland Security
Continuing Education Programs,
GWU

FI-CPS-TCG-Logos

Protecting Major Events Series Registration

Please use this form to register for FedInsider Webinars you are interested in attending.

"*" indicates required fields

Name*
Address*
Would you like to receive a training credit (no cost) for attending this webinar?*