Dayu Kao
Dayu Kao
Associate Executive Vice President, Information Security Division
Bank SinoPac

Da-Yu Kao is the Vice Chairman of TW Chief Information Security Officier (CISO) Alliance and the Associate Executive Vice President of the Information Security Division of Bank SinoPac, Taiwan. His crucial responsibility focuses on establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS), Business Continuity Management (BCM), and Information Security Management System (ISMS) in the form of an extension to the NIST Cybersecurity Framework (CSF) for keeping pace with the evolving cybersecurity landscape. These activities help the organization respond to and recover from potential threats as effectively as possible.English Profile & Professional Experience. A part-time professor in the Information Security Master Program at National Chengchi University, Taiwan. Nearly 30-year experience in the combination of Industry, Official, and University, he has cooperated with law enforcement officers in hundreds of information security incident identification, investigation, and forensic cases in many countries.

SPEECH
5/16 (Thu.) 14:00 - 14:30 7F 701A FINSEC Forum
Incident Response Trade-off for Financial CISO Mindset: Resilient Governance or Forensic Evidence

Cyberattack governance is discussed and analyzed from incident identification and investigation viewpoints. The RGFE cybersecurity governance is presented from the fusion model of NIST CSF and ISO/IEC 27043:2015. That day-to-day business activity model has demonstrated due diligence and good corporate governance. It also can promote the evidence of court acceptance and reduce the expenses and time of an internal investigation. That will enhance the financial CISO mindset capacity of incident response trade-off from the following benefits :

  1. Early detection and repair of potential risks.
  2. Deploy information security protection software against potential threats.
  3. Continuous monitoring of vulnerabilities and threats.
  4. Quickly determine the scope of damage and respond.