Uploaded August 2025 | Updated September 2026, 1 hour ago
Tom Millar (CISA, US), Eireann Leverett (Killara Cyber, GB), Wendy Nather (None, US), Declan Ingram (Trust Hound, NZ)
Mr. Millar has served in CISA since 2009, working to strengthen the nation's cyber defenses and resilience against emerging threats. His work has included increasing the level of public, private and international partner engagement, and supporting initiatives to improve information sharing, such as the standardization of the Traffic Light Protocol. As the Branch Chief of Cyber Resilience within the Cyber Security Division, he oversees CISA's architectural cybersecurity assessments, the Cybersecurity Performance Goals program, and training and standards for assessment performance. Prior to his cybersecurity career, he served as a linguist with the 22nd Intelligence Squadron of the United States Air Force. Mr. Millar holds a Master's of Science from the George Washington University and is a Distinguished Graduate of the National Defense University's College of Information and Cyberspace.
Eireann Leverett is the CTO of Killara Cyber, and a long time to collaborater to FIRST. He has risen through the roles of penetration tester, incident responder, researcher, and risk analyst to his current role. He has written many articles and one book, and has a deep interest in critical infrastructure, technology and risk, and catastrophe economics. He's like the little kid on this panel of international experts, and excited to be at the table!
Wendy Nather is the Senior Research Initiatives Director at 1Password. She was previously the Director of Advisory CISOs at Duo Security, Research Director at the Retail ISAC, and Research Director of the Information Security Practice at 451 Research. Wendy led IT security for the EMEA region of the investment banking division of Swiss Bank Corporation (now UBS), and served as CISO of the Texas Education Agency. She was inducted into the Infosecurity Europe Hall of Fame in 2021. Wendy serves on the board of directors for Sightline Security, is on the steering committee for the IST Ransomware Task Force, and is a Senior Fellow at the Atlantic Council's Cyber Statecraft Initiative.
Declan is a consultant from New Zealand. He did too much incident response (it was bad for his health) and kept pulling the thread of “why” until he ended up obsessing over organisational resilience and the failures of security strategies.
--
As threat actors become increasingly focused on disruptive incidents (ransomware being only one example) and such incidents increasingly becoming a matter of "when, not if," defenders must be increasingly prepared not only to rapidly minimize harm, but to quickly and safely recover after a disruption. This panel of experts from around the world will discuss lessons learned in cyber resiliency, including supply chain risk management, cyber hygiene, trustworthy ad hoc side channels, individual versus collective resilience (and the need for stronger collaboration), metrics for assessing resilience, and more. In addition, panelists will have an opportunity to share "war stories" of cyber resilience in the current threat context, so that all attendees can learn from the triumphs of other resilient teams.
Tom Millar (CISA, US), Eireann Leverett (Killara Cyber, GB), Wendy Nather (None, US), Declan Ingram (Trust Hound, NZ)
Mr. Millar has served in CISA since 2009, working to strengthen the nation's cyber defenses and resilience against emerging threats. His work has included increasing the level of public, private and international partner engagement, and supporting initiatives to improve information sharing, such as the standardization of the Traffic Light Protocol. As the Branch Chief of Cyber Resilience within the Cyber Security Division, he oversees CISA's architectural cybersecurity assessments, the Cybersecurity Performance Goals program, and training and standards for assessment performance. Prior to his cybersecurity career, he served as a linguist with the 22nd Intelligence Squadron of the United States Air Force. Mr. Millar holds a Master's of Science from the George Washington University and is a Distinguished Graduate of the National Defense University's College of Information and Cyberspace.
Eireann Leverett is the CTO of Killara Cyber, and a long time to collaborater to FIRST. He has risen through the roles of penetration tester, incident responder, researcher, and risk analyst to his current role. He has written many articles and one book, and has a deep interest in critical infrastructure, technology and risk, and catastrophe economics. He's like the little kid on this panel of international experts, and excited to be at the table!
Wendy Nather is the Senior Research Initiatives Director at 1Password. She was previously the Director of Advisory CISOs at Duo Security, Research Director at the Retail ISAC, and Research Director of the Information Security Practice at 451 Research. Wendy led IT security for the EMEA region of the investment banking division of Swiss Bank Corporation (now UBS), and served as CISO of the Texas Education Agency. She was inducted into the Infosecurity Europe Hall of Fame in 2021. Wendy serves on the board of directors for Sightline Security, is on the steering committee for the IST Ransomware Task Force, and is a Senior Fellow at the Atlantic Council's Cyber Statecraft Initiative.
Declan is a consultant from New Zealand. He did too much incident response (it was bad for his health) and kept pulling the thread of “why” until he ended up obsessing over organisational resilience and the failures of security strategies.
--
As threat actors become increasingly focused on disruptive incidents (ransomware being only one example) and such incidents increasingly becoming a matter of "when, not if," defenders must be increasingly prepared not only to rapidly minimize harm, but to quickly and safely recover after a disruption. This panel of experts from around the world will discuss lessons learned in cyber resiliency, including supply chain risk management, cyber hygiene, trustworthy ad hoc side channels, individual versus collective resilience (and the need for stronger collaboration), metrics for assessing resilience, and more. In addition, panelists will have an opportunity to share "war stories" of cyber resilience in the current threat context, so that all attendees can learn from the triumphs of other resilient teams.










