Day 1
Thursday, June 26, 2025
All times below are Eastern Time
08:30AM – 09:20AM
In-Person
Registration & Breakfast
09:00 AM
09:00AM - 09:20AM
Virtual
Virtual Broadcast Begins
09:20 AM
09:20AM - 09:30AM
Opening Remarks
Brendan Kwolek
Chief Information & Digital Officer, Halton Healthcare
Kopiha Nathan
Privacy and Compliance Officer, HIROC
09:30 AM
09:30AM – 10:15AM
Session 1
KEYNOTE | Cyber Crime, Healthcare, AI and the Fight for Security
Expand/collapse session description...
Healthcare CIOs and CISOs, are well versed in the current state of cybersecurity. You have been defending your organizations against attacks for years. You’ve witnessed breeches, and you built back up. You are aware of the stakes, and you are preparing for the worst. So what can you expect in the years to come?
Looking from a global perspective Canadian healthcare can learn from not just from their peers, but from other industries, which are also under attack from cyber criminals. From ransomware to activists, to state sponsored attacks, cyber crime is not going away. That means we need to be more prepared for defending against the latest innovative attacks.
Key Session Takeaways Include:
- Why go after healthcare? What is the value of Canadian patient data?
- What are criminals after, and what tactics are they using now to expand the reach to commit fraud
- Who’s paying ransoms and why?
- How are advances in AI driving more sophisticated attacks – moving beyond emails to audio and video, such as the recent Arup attack
- Case studies from around the world, and what that tells us about future attacks
Chris Mathers
Founder, Chris Mathers Inc.
10:15 AM
10:15AM – 11:00AM
Session 2
Establishing a Patient-Centric Cybersecurity Program: Translating Technical Risk Into Clinical Impact
Expand/collapse session description...
Healthcare cybersecurity must evolve beyond traditional vulnerability scores to prioritize what matters most: patient safety and care continuity. This session explores how organizations can redesign their cybersecurity programs to align with the realities of clinical risk, creating visibility into how technical exposures affect real-world patient outcomes.
By aligning cybersecurity strategies with clinical priorities, we can move from reactive defense to proactive protection. Attendees will learn how to reframe risk in terms of patient impact and gain insight into building a systematic, context-aware program that improves both security posture and care delivery.
Learning Objectives:
- Define the structural components of a patient-centric framework
- Begin building a clinically aligned cybersecurity governance model
- Reframe CVEs and risk scores into clinical impact metrics
- Communicate cyber risk in the language of patient safety and care delivery
- Understand how to map vulnerabilities to patient workflows and disruptions
Mohammad Waqas
CTO Healthcare, Armis
11:00 AM
11:00AM - 11:30AM
Break
Morning Break
11:30 AM
11:30AM – 12:15PM
Session 3
Working With Your Boards: Providing the Right Details to Meet Governance Expectations, Safety Requirements, and Mitigate Risks
Moderated by: Brendan Kwolek, Chief Information & Digital Officer, Halton Healthcare
Expand/collapse session description...
Hospital boards in Canada play a crucial role in ensuring strong governance, patient safety, and risk mitigation. However, effectively communicating complex healthcare data, regulatory requirements, and safety concerns in a way that enables informed decision-making is a challenge for hospital executives and administrators.
This session will provide practical guidance on structuring board reports, aligning with Canadian healthcare governance expectations, and ensuring compliance with key safety and risk requirements.
Key Session Takeaways Include:
- Understanding Canadian hospital board governance and their oversight responsibilities
- Best practices for reporting patient data security and risk management to boards
- Strategies for presenting critical healthcare data in a clear, actionable format
- Meeting expectations set by Accreditation Canada, provincial health ministries, and regulatory bodies
Dave Brewin
Vice President Digital Health and Regional CIO, Royal Victoria Reginal Health Centre
Lyn Baluyot
President and Chief Executive Officer, TransForm Shared Service Organization
David Stankiewicz
Vice President and Chief Information and Privacy Officer, William Osler Health System
12:15 PM
12:15PM – 01:15PM
Break
Networking Lunch
01:15 PM
01:15PM – 02:00PM
Session 4
Navigating Cyber Threats: A Mock Incident Response for Public Sector Healthcare in Ontario
Expand/collapse session description...
Join us for an interactive simulation that walks through a realistic cyber incident scenario tailored to the public healthcare sector. You’ll gain practical insights into incident response strategies, stakeholder coordination, and lessons learned from real-world breaches.
Whether you’re a CISO, IT leader, or healthcare executive, this session—and the broader conference—offers valuable takeaways to help you protect your organization in an increasingly complex threat landscape.
Anastasia Lou Regen
Partner, Technology Consulting, Cybersecurity, EY
Alex Shadeed
Manager, Technology Consulting, EY
02:00 PM
02:00PM – 02:45PM
Session 5
How Ontario Health is Boosting Cyber Resilience in the Healthcare Sector
Moderated by: Sabrina Lavi, MA, MCM, Senior Advisor, Communications, Ontario Health Cyber Security Centre (OHCSC), Digital Excellence in Health
Expand/collapse session description...
As cyber threats become increasingly sophisticated, it is crucial for health service providers to enhance their cyber capabilities to protect sensitive information and ensure the safety of their operations and patient care.
Join us as leaders from the Ontario Health Cyber Security Program share how to achieve a mature defense program, leveraging the NIST Cybersecurity Framework to effectively manage and mitigate cyber risks.
Key Session Takeaways Include:
- What a mature defense program looks like and the steps to achieving it
- Why the use of the NIST Cybersecurity Framework as a core resource for better management and reduction of cyber security risk
- Upcoming initiatives from Ontario Health and essential preparations for health service providers
Greg Moshonas
Director, Cyber Security Defense, Ontario Health
Amna Amin
Director, Information Security Office, Ontario Health
Stephen Lloyd
Director, Cyber Security Centre, Ontario Health
02:45 PM
02:45PM – 03:15PM
Break
Afternoon Break
03:15 PM
03:15PM – 04:00PM
Session 6
The Breach Brief: What We Learned Today
Moderated by: Mohammad Waqas, CTO Healthcare, Armis
Expand/collapse session description...
What stood out, what sparked debate, and what deserves a second look, our panel of experts unpacks the day’s most important takeaways.
Brendan Kwolek
Chief Information & Digital Officer, Halton Healthcare
Lyn Baluyot
President and Chief Executive Officer, TransForm Shared Service Organization
Kopiha Nathan
Privacy and Compliance Officer, HIROC
Stephen Lloyd
Director, Cyber Security Centre, Ontario Health
04:00 PM
04:00PM – 04:10PM
Closing Remarks
Brendan Kwolek
Chief Information & Digital Officer, Halton Healthcare
Kopiha Nathan
Privacy and Compliance Officer, HIROC
04:10 PM
04:10PM - 06:00PM
Networking Cocktail Reception
Day 2
Friday, June 27, 2025
All times below are Eastern Time
08:15AM – 09:20AM
In-Person
Registration & Breakfast
09:00 AM
09:00AM - 09:20AM
Virtual
Online Broadcast Begins
09:20 AM
09:20AM - 09:30AM
Opening Remarks
Brendan Kwolek
Chief Information & Digital Officer, Halton Healthcare
Kopiha Nathan
Privacy and Compliance Officer, HIROC
09:30 AM
09:30AM – 10:15AM
Session 7
Beyond Firewalls: The Expanding Role of CISOs and the Talent Crisis in Canadian Healthcare Cybersecurity
Expand/collapse session description...
As healthcare digitization accelerates across Canada, CISOs have evolved from firewall gatekeepers to strategic leaders in risk, compliance, and resilience. With AI, virtual care, and data-sharing expanding rapidly, sensitive patient information now flows far beyond traditional EHRs—introducing new vulnerabilities and a vastly broader attack surface. At the same time, hospitals face mounting pressure to fill cybersecurity roles amid a national talent shortage and constrained budgets.
Another layer to this is that cybersecurity teams are challenged with recruitment, staffing, and budgets to optimally manage this vital role.
So, with the CISO role expanding within Canadian healthcare, and the growing complexity of protecting patient data in an AI-driven ecosystem, what can teams inspire and attract the brightest minds in cybersecurity to support the mission of protecting patients’ lives.
Key Session Takeaways Include:
- Learn how CISOs are taking on broader responsibilities in governance, compliance, and enterprise risk management
- Understand how advances in clinical AI, data sharing agreements, research, clinical trials, and emerging technologies are expanding the CISO’s role
- Explore innovative approaches to building cybersecurity teams despite limited budgets and a national talent gap
Jessica C. Ojiaku
Data Privacy Associate, Pharmaceuticals
10:15 AM
10:15AM – 11:00AM
Session 8
Containing the Threat: Microsegmentation as a Defense Against Ransomware in Healthcare
Expand/collapse session description...
Ransomware attacks on healthcare institutions are escalating, disrupting patient care, compromising sensitive data, and imposing significant financial burdens. Traditional perimeter defenses alone no longer offer sufficient protection against increasingly sophisticated threats. Microsegmentation presents a proactive, granular security approach, enabling healthcare organizations to limit the damage of ransomware by isolating critical systems, restricting lateral movement, and containing threats swiftly.
In this session, we will explore real-world examples of ransomware attacks in healthcare, emphasizing the vulnerabilities exploited and the subsequent impact on patient services and operations. We’ll introduce microsegmentation strategies designed explicitly for healthcare environments, detailing how they provide robust protection through network isolation, visibility enhancements, and improved control over access management. Attendees will gain actionable insights on deploying microsegmentation to reinforce their cybersecurity posture, effectively mitigating the risks associated with ransomware attacks.
Key Session Takeaways Include:
- Understanding Ransomware Risks in Healthcare: Identify key ransomware threats specific to healthcare environments, including their common entry points, attack methodologies, and operational consequences.
- Microsegmentation Fundamentals: Learn what microsegmentation is, how it functions as a cybersecurity tool, and why it significantly enhances resilience against ransomware threats.
- Implementing Effective Microsegmentation Strategies: Acquire practical guidance on deploying microsegmentation within healthcare IT infrastructure to limit the impact of ransomware, enhance network visibility, and ensure compliance with healthcare security regulations.
Douglas Holland
Senior Solutions Engineer, Akamai Technologies
11:00 AM
11:00AM – 11:30AM
Break
Morning Break
11:30 AM
11:30AM – 12:15PM
Session 9
Less is More: How to Deliver Greater Security With Less Technology and Cost
Expand/collapse session description...
Cybersecurity is often described as an escalation in applying the newest and most advanced technological solutions. And while technology is vital in protecting healthcare organizations, there are plenty of tech options already at your disposal, and as well many non-tech options for securing your systems than you may think.
Key Session Takeaways Include:
- How to maximize your current security options, and how they can get you most of the way there
- How to get back to the basics, and focus on the 80-90 percent work that’s most effective
- Why more security is not the necessarily the best security – and working with what you have
- Working with Boards and the importance of FUD
Skerdi Cerga
Chief Technology and Security Officer, Trillium Health Partners
12:15 PM
12:15PM – 12:25PM
Closing Remarks
Brendan Kwolek
Chief Information & Digital Officer, Halton Healthcare
Kopiha Nathan
Privacy and Compliance Officer, HIROC
12:25 PM
12:25PM – 01:00PM
Break
Networking Lunch
Ongoing Call for
Speakers
This is your opportunity to share your knowledge and experience with other industry professionals.
Please email us at info@sparkconferences.com to receive more information.
We look forward to receiving your submissions!