Edward Yu

Blackcat Information Corp. / GM

Zyxel Group Corporation / Chief Information Security Officer, Chairman Office

Yu Cheng-Ching currently serves as the Chief Information Security Officer of Zyxel Investment Holdings and the General Manager of Black Cat Information. With over 20 years of experience in cybersecurity, he specializes in defensive infrastructure for information security and enterprise digital transformation. Under his leadership, Black Cat Information delivers integrated cybersecurity solutions encompassing SIEM, XDR, and SOC platforms, empowering organizations to tackle increasingly complex digital threats effectively and enhance resilience and efficiency.

During his tenure, Yu Cheng-Ching has actively promoted security testing for ICT products and the integration of threat intelligence, reinforcing attack surface management and risk control. Leveraging AI analytical technologies, he has accelerated threat detection and response. He has successfully implemented honeypot deployments, threat hunting, and the MITRE ATT&CK framework, significantly enhancing real-time hacker behavior analysis and risk management capabilities. Furthermore, he is dedicated to vulnerability management and optimizing cybersecurity strategies, helping enterprises reduce risks and strengthen overall defense capabilities.

Certified as a C|CISO (Certified Chief Information Security Officer), Yu Cheng-Ching combines a robust professional background with hands-on experience. He has led Zyxel Investment Holdings and Black Cat Information to become key leaders in the domestic cybersecurity field, driving innovation and development within the industry.hin the industry.

SPEECH
4/15 (Tue.) 14:00 - 14:30 7F 702 InfraSec Forum
From Basic Defense to Advanced Threat Hunting: Building Comprehensive Cybersecurity Resilience

In an era where digital threats are constantly escalating, Black Cat Information leverages integrated cybersecurity solutions to help organizations transition from basic defense to advanced threat management, thereby enhancing overall cybersecurity resilience. This presentation will focus on Black Cat Information's core technologies and services, demonstrating how the integration of SIEM, XDR, and SOC platforms enables comprehensive monitoring, intelligence integration, and rapid response.

The presentation will cover Black Cat Information's application in domain security detection, illustrating how to identify potential risks and vulnerabilities within a domain while proposing effective remediation and reinforcement strategies. Additionally, practical cases in External Attack Surface Management (EASM) will be introduced, showcasing how to inventory and manage digital footprints to reduce attack surfaces and minimize asset exposure risks. 

We will also share insights into the deployment of honeypot technology, threat hunting, and the application of the MITRE ATT&CK framework in analyzing hacker behavior. Real-world examples will be used to illustrate the effective implementation of cybersecurity defense strategies.

Through this session, participants will gain an in-depth understanding of how Black Cat Information employs innovative technologies and strategies to assist enterprises in countering escalating digital threats. Attendees will acquire hands-on experience in transitioning from foundational infrastructure to advanced threat management, ultimately strengthening their cybersecurity capabilities and resilience.

4/17 (Thu.) 15:30 - 16:00 7F 701D CISO Forum
Information Security Risk Management: Building Resilient Defense to Embrace Digital Challenges

This presentation will delve into the core strategies of Information Security Risk Management, focusing on how to build resilient cybersecurity defenses against increasingly sophisticated digital threats. As enterprises accelerate digital transformation, they face a rising frequency and complexity of cyberattacks. Drawing from Zyxel Group Corporation’s hands-on experience, this session will provide a deep dive into today’s most pressing cybersecurity threats, including social engineering, endpoint security, cloud security, and system vulnerability management.

The discussion will highlight how businesses can conduct comprehensive risk assessments, identify high-risk assets, and implement effective countermeasures. Special emphasis will be placed on practical strategies for Zero Trust architecture and supply chain risk management, equipping organizations with the tools to proactively mitigate emerging threats.

Key Takeaways for the Audience:

Gain critical insights into identifying and addressing the most prevalent cybersecurity threats faced by enterprises.

Master cutting-edge security techniques and best practices for effective implementation.

Learn from real-world case studies to understand the seamless integration of cybersecurity strategies into business operations.

This session aims to enhance attendees' strategic perspective on cybersecurity, empowering them to fortify their organizations’ digital resilience and stay ahead in the evolving threat landscape.