The Qualys CSO Advisory Board is composed of industry security leaders, whose real-world expertise in forging security policies and implementing security best practices, help guide the strategic direction in the further development of Qualys' vulnerability management web service.
- Howard A. Schmidt, President and CEO, R & H Security Consulting LLC
- Larry L. Brock, Chief Information Security Officer, DuPont
- Dennis Devlin, Chief Information Security Officer, Brandeis University
- Daniel Klinger, Manager of Information Executive, Hershey Foods Corporation
- Dr. John I. Meakin, Chief Information Security Officer, BP
- Paul Simmonds, Global IS Integrated Assurance Director, AstraZeneca Plc.
- Andreas Wuchner, Head of Global IT Security, Novartis
Howard A. Schmidt \ President and CEO, R & H Security Consulting LLC
Howard A. Schmidt is an American computer security specialist. He is currently President and CEO of R & H Security Consulting LLC, which he founded in May 2005. Schmidt has served as Chief Security Strategist for the US CERT Partners Program for the National Cyber Security Division through Carnegie Mellon University, in support of the Department of Homeland Security. He has served as Vice President and Chief Information Security Officer and Chief Security Strategist for eBay. He was named to become president of the Information Security Forum.
In May 2003, Schmidt retired from the White House after 31 years of public service in local and federal government. After the 9/11 attacks, he was appointed by President Bush as the Vice Chair of the President.s Critical Infrastructure Protection Board and as the Special Adviser for Cyberspace Security for the White House in December 2001. While at the White House, assisted in the creation of the US National Strategy to Secure CyberSpace. He assumed the role as the Chair in January 2003 until his retirement in May 2003, when he joined eBay.
In 1997, Schmidt joined Microsoft, as the where Director of Information Security, Chief Information Security (CISO) and Chief Security Officer, (CSO). He was the co-founder of the Trustworthy Computing Security Strategies Group.
In 1994, Schmidt was a Supervisory Special Agent and Director of the Air Force Office of Special Investigations Computer Forensic Lab and Computer Crime and Information Warfare Division. In 1996, while serving in that position, he established the first dedicated computer forensic lab in the government, which was the basis for the formation of the Defense Computer Forensic Laboratory (DCFL).
Prior to the AFOSI in 1994, Schmidt was with the FBI at the National Drug Intelligence Center, where he headed the Computer Exploitation Team. He is recognized as one of the pioneers in the field of computer forensics and computer evidence collection. Before working at the FBI, Schmidt was a city police officer from 1983 to 1994 for the Chandler Police Department in Arizona where he served on the SWAT team, Organized Crime and Drug Enforcement Unit and formed and led the Special Enforcement Team.
Schmidt served with the U.S. Air Force in various roles from 1967 to 1983, both in active duty and in the civil service. He served in the Arizona Air National Guard with the 161st Communications Squadron in based at Phoenix International Airport, Phoenix, AZ from 1989 until 1998. In 1998, Schmidt transferred to the U.S. Army Reserves as a Special Agent, Criminal Investigation Division, where he continues to serve and is currently assigned to the Computer Crime Investigations Unit (CCIU). He has also served with the 315th MP Det (CID) at Ft. Lawton in WA. He has testified as an expert witness in federal and military courts in the areas of computer crime, computer forensics and Internet crime.
Schmidt also serves as the international president of the Information Systems Security Association and was the first president of the Information Technology Information Sharing and Analysis Center. He is a former executive board member of the International Organization of Computer Evidence, and served as the co-chairman of the Federal Computer Investigations Committee. He is a member of the American Academy of Forensic Scientists. He had served as a board member for the CyberCrime Advisory Board of the National White Collar Crime Center, and was a distinguished special lecturer at the University of New Haven, Conn., teaching a graduate certificate course in forensic computing. He has also taught courses for the FBI and DEA on the use of computers and law enforcement investigations.
Schmidt also serves on the Executive Committee of the Information Technology Sector Coordination Council. His memberships include the High Technology Crime Investigation Association, the American Academy of Forensic Sciences and the International Association of Chiefs of Police.
He served as an augmented member to the President's Committee of Advisors on Science and Technology in the formation of an Institute for Information Infrastructure Protection. He has testified before congressional committees on computer security and cyber crime, and has been instrumental in the creation of public and private partnerships and information-sharing initiatives. He is regularly featured on various worldwide television and radio shows including, BBC, ABC, CNN, CNBC, Fox TV as well as a number of local media outlets talking about cyber-security, investigations and technology. He is a co-author of the Black Book on Corporate Security and author of Patrolling CyberSpace, Lessons Learned from a Lifetime in Data Security.
Schmidt has been appointed to the Information Security Privacy Advisory Board to advise the National Institute of Standards and Technology the Secretary of Commerce and the Director of the Office of Management and Budget on information security and privacy issues pertaining to Federal Government information systems.
Schmidt holds board positions on a number of corporate boards in both an advisory and director positions.
Larry L. Brock \ Chief Information Security Officer, DuPont
Larry Brock directs information technology security initiatives and operations globally at E. I. DuPont de Nemours. His 27-year IT career at DuPont includes broad business experience across the global science and technology company, including Corporate IT and the Imaging, Fibers and Nylon business units. He has led the development and implementation of several large systems such as manufacturing product control, materials management, engineering maintenance, quality management, and data warehouse. Brock spearheaded DuPont's migration to open-based systems for networking and computing. He also led development and deployment of several imaging based systems, including a patented system to electronically move radiographs between hospitals and remote physicians. Prior to DuPont, Brock was an information security officer in the U.S. Air Force at the National Security Agency. He served 26 years in the reserves and retired as a Lt Colonel. Brock has Bachelor and Master degrees in electrical engineering.
Dennis Devlin \ Chief Information Security Officer, Brandeis University
Dennis Devlin is the Chief Information Security Officer for Brandeis University. Prior to Brandeis University, Devlin was the Chief Security Officer for The Thomson Corporation, the leading global provider of integrated information-based solutions to business and professional customers. During his tenure at Thomson, Devlin led Thomson's information security and privacy program, as well as corporate-wide initiatives in identity management and directory services. Devlin has more than 35 years of information technology leadership experience in private industry and higher education. Before Thomson, Devlin filled multiple IT leadership roles at Harvard University and served on higher education technology advisory councils for major manufacturers such as Microsoft, IBM and Apple. Devlin graduated from the University of Pennsylvania, has lectured at the UCLA Anderson School of Management, Babson College Center for Information Management Studies, University of Massachusetts Strategic Information Technology Center, and at many industry conferences.
Daniel Klinger \ Manager of Information Executive, Hershey Foods Corporation
Daniel Klinger leads information security efforts at Hershey Foods Corporation, the world's largest chocolate candy company selling more than 50 brands in over 90 countries. His responsibilities include implementing industry-leading security policies, standards and practices to ensure the confidentiality, integrity and availability of Hershey's critical information assets. Klinger also has pioneered IT security assessment and documentation processes at Hershey that satisfy auditor requirements for corporate compliance with the Sarbanes-Oxley Act. His career in information security spans 13 years, including safeguards for network and application security. Klinger is a Certified Information Security Manager (CISM).
Dr. John I. Meakin \ Chief Information Security Officer, BP
John Meakin is the Chief Information Security Officer for BP, one of the world's largest energy companies with 97,600 employees in more than 100 countries around the world. Prior to BP, Meakin lead a global information security team at Standard Chartered Bank, one of the world's most international banks with 30,000 employees in more than 50 countries and a management team comprised of 70 nationalities. Meakin has 18 years of experience in information systems security. His specialty is better modeling and managing the costs and benefits of security for large businesses, particularly enabling dynamic management and monitoring instead of traditional static prevention processes. Previously, Meakin led systems security policy and strategy for Reuters, the Royal Bank of Scotland, Swiss Bank Corporation, and the investment-banking arm of Dresdner Bank. Meakin has also provided information security consultancy support to several blue chip clients aimed at improving systems security and effectiveness. He has a Ph.D. in experimental solid state physics from Cambridge University, plays football regularly and builds computers in his spare time. Meakin is a regular speaker at industry conferences and public forums.
Paul Simmonds \ Global IS Integrated Assurance Director, AstraZeneca Plc.
Paul joined AstraZeneca one of the world's leading pharmaceutical companies with over 67,000 employees and active in more than 100 countries, in July 2008 merging their IS risk, security and assurance functions into a single unit under the title "Integrated Assurance". Prior to AstraZeneca Paul spent six years as the CISO of ICI; prior to ICI he was Head of Information Security with a high security European web hosting company and before that spent seven years with Motorola, as global information security manager. Paul has a degree in Electronic Engineering and a City & Guilds in Radio Communication. Paul was awarded Chief Security Officer of the year at the 2005 SC Magazine European Awards and is listed in both the 2004 & 2005 global top 50 most powerful people in networking, by the US publication Network World. Paul is a co-founder and sits on the management board of the Jericho Forum and the Executive Advisory Board of ISSA UK. He also is a British Canoe Union Level 3 Kayak Coach.
Andreas Wuchner \ Head of Global IT Security, Novartis
Andreas Wuchner, CISO, CISSP, is Head of Global IT Security at Novartis Pharmaceuticals where he leads IT Security and Security Emergency Response globally across the corporation. In this role he and his team are responsible for the planning and supervision of Novartis' worldwide computer and network information security systems, defining the company's IT security policies & standards and enhancing the security of Novartis IT services and global infrastructure.
He has more than 12 years of experience managing all aspects of information technology management, with deep expertise in rapidly changing, highly demanding large-scale environments. Prior to joining Novartis Pharmaceuticals, Andreas worked for Ciba Geigy and IBM on various IT projects covering all aspects of information technology.
Andreas is a regular speaker on numerous aspects of information risk management and IT security practices from a pharmaceutical business viewpoint. Recent speaking engagements include security seminars in Europe, Asia and USA.
He represents Novartis on strategic executive advisory boards of several leading security industry companies including Symantec Corporation, Microsoft and Qualys. Andreas holds a bachelor degree in Electronics and Computer Science from the University of Applied Sciences in Offenburg in Germany.
