Council
From Compliance to Confidence: Building Continuous Assurance at Scale

Virtual Council

Date

January 28, 2026

Location

National

Community

CIO / CISO
Your Vision is our mission

Agenda

January 28, 2026
All times Eastern Time
3:00 PM-4:15 PM
From Compliance to Confidence: Building Continuous Assurance at Scale

Traditional GRC processes can no longer keep pace with the speed of modern business. Lengthy security reviews and manual evidence collection slow innovation, strain teams, and create uncertainty for customers and boards alike. With AI transforming every layer of the enterprise, leaders have an opportunity to reimagine assurance as a real-time, intelligence-driven capability that supports responsible, rapid growth.

This executive event will bring together leaders to discuss the strategies and operating models shaping the future of trust. We’ll explore how organizations are adopting AI-enabled assurance, enhancing visibility across their environments, and strengthening customer confidence while reducing operational drag. Participants will walk away with actionable insights to modernize GRC functions, improve trust velocity, and position assurance as a strategic business enabler.

Chair
Timothy Swope Lighthouse Cyber Risk Management
Timothy Swope

CISO

Lighthouse Cyber Risk Management

Mr. Swope brings over 20 years of experience in IT Project Management, BI Solutions Development, IT Security, IT Controls (CoBIT, SOX 404/MAR, etc) IT Risk Management, and HealthCare Compliance, to both the public and private sectors. His focus is on identifying gaps relating to key IT security processes and the implementation of IS Security and Risk Management programs to Health Care, Pharmaceutical and various commercial clients. Has a proven track record of delivering the following: • Interpreting and applying 21 CFR Part 11, GLP, GMP, GCP, and QSR regulations • MDM and Data Governance • Identity Access Management • HIPAA Risk Assessments and GAP analysis • Information Assurance Program Management - SCRUM, AGILE, SDLC, Six Sigma • Implemented large security, risk and compliance initiatives of SOX-404 IT, HIPAA/HITECH, including security policies, procedures and controls. • "Big Data", Data Management and Health Care Data Analytics • Federal Information Security Management Act (FISMA) Compliance Reviews • Implemented the security standards - 45 CFR Parts 160, 162, and 164 Health Insurance Reform: Security Standards; Final Rule He has supported these Information Assurance and IS Security initiatives for organizations that include: Excellus BCBS, Medimmune/Astra Zeneca, ENDO Pharmaceuticals, Novo Nordisk, Daiichi-Sankyo Solutions, Catalent Pharma Solutions, Johnson and Johnson, District of Columbia Government office of the Chief Financial Officer, District of Columbia Water and Sewer Authority, City of Richmond, Virginia Department of Public Utilities, Virginia State Department of Health, and the Kentucky Department of Health Services, as well as the U.S. Department of Labor.
Panelists
Al Yang Drata

Speaker

Al Yang

CEO/Co-Founder of SafeBase,

Drata

Al Yang is the CEO and Co-founder of SafeBase, a Trust Center and AI-powered Questionnaire Automation platform designed to eliminate friction from the security review process. A Y Combinator alum, SafeBase has raised over $50 million from top-tier investors. Its 202 acquisition by Drata, a leading compliance automation platform, marks Al’s third successful exit. Based in San Francisco, Al is a proud father of two and an avid golfer. He is passionate about startups and actively mentors and advises emerging companies, drawing on his experience in building and scaling high-growth businesses.

Amna Awan CDW

Speaker

Amna Awan

Head of Security Risk Management

CDW

Amna Awan is the Head of Security Risk Management within the Global Information Security organization. Her team has responsibility for security governance, risk, and compliance including: customer trust, third party risk, global policies, standards, ISO 27001, PCI-DSS, CMMC Level 2, SOX ITGC, security awareness training, cyber risk quantification, metrics, risk management and reporting.
Jonathon Harbin AWS
Jonathon Harbin

Principal Practice Manager

AWS

Steve Craig (1) New York Presbyterian Hospital

Speaker

Steve Craig

Senior Technical Architect IT

New York Presbyterian Hospital

NewYork-Presbyterian is one of the nation’s most comprehensive, integrated academic healthcare systems, dedicated to providing the highest quality, most compassionate care and service to patients in the New York metropolitan area, nationally, and around the world. In collaboration with two renowned medical schools, Weill Cornell Medicine and Columbia University Vagelos College of Physicians and Surgeons, NewYork-Presbyterian is consistently recognized as a leader in innovative, patient-centered clinical care, research and medical education. Steve is the Senior Architect/SME in various Microsoft Technologies and has over 20 years’ experience managing and designing email systems and directory services. Steve has multiple advanced certifications and over 16 years’ experience training system engineers in multiple Microsoft technologies. Managed, designed, and migrated Exchange systems with 10+ servers in multiple locations.
Hans Vargas-Silva (1)
Hans Vargas-Silva

Data Protection Lead- Cybersecurity Governance

Company Confidential Fortune 500

Don't take our word for it

Together With

Don’t take our word for it

Heard In The Room