Information Security Best Practices for Content Security

In this panel, we will discuss best practices for cybersecurity and information security, including the recent updates to ISO 27001, 27002 standards, and the Motion Picture Association’s (MPA) Best Content Security Practices. We will also explore the benefits that certification and an enhanced level of security maturity can bring to the media and entertainment industry.

Chair: Vinícius Brasileiro, Information Security Strategy, Governance and Risk Manager, Globo

Bachelor's degree in Computer Science and Accounting, with a specialization in IT Auditing and certified as a Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), and Certified in Risk and Information Systems Control (CRISC) by ISACA, Certified Chief Information Security Officer (CCISO) by EC-Council, and Certified Business Continuity Professional (CBCP) by DRI International. Vinícius has 20 years of experience in the areas of information security, governance, risk, and compliance. He is currently the Coordinator of the Information Security Working Group at SET, Vice President of ISACA Chapter Rio de Janeiro, guest lecturer at PUC-PR, and leads the Security Strategy and Risk area at Globo.

Speaker: Kari Grubin, Director, Motion Picture Association Trusted Partner Network

Kari Grubin is a multi-talented executive who has spent the past 25 years leading and managing studio divisions, global postproduction facilities, corporate departments, and groups within trade organizations. Kari is the Membership Services Director for the Motion Picture Association Trusted Partner Network where she works with program participants and members to help grow the TPN program and TPN+ platform for security preparedness and enhanced awareness of content security best practices at all stages of content development in the digital media supply chain. Kari serves on the executive board of the Hollywood Professional Association (HPA) and is an active member of the Academy of Motion Picture Arts and Sciences, serving on the Production and Technology Branch Executive Committee. Kari holds three US patents in media and entertainment technology as a co-inventor.

Speaker: Ariosto Farias Jr., Consultant, CQSI - Management and Information Security Consultancy

Expert and Head of Delegation (HoD) for Brazil since the year 2000 to the present date in the International Committee ISO SC 27 - Information security, cybersecurity, and privacy protection. Responsible for the development of ISO 27001:2022 and ISO 27002:2022 standards. - Coordinator of the ABNT CE 021.027 Commission, responsible for the adoption of NBR ISO 27001, NBR ISO 27002, and other ISO 27000 Family Standards in Brazil. - Senior Consultant since the year 2001, specializing in ISO 27001 and ISO 27002 standards. Assisted multiple companies in implementing and obtaining ISO 27001 certification. - Certified ISO/IEC 27001 Senior Lead Auditor by PECB (Canada). Holds a degree in Civil Engineering from the Polytechnic School of UFBA.

Speaker: Lucas Bortolato, CTO/CISO at Every System Company

As CTO/CISO of Every System Company since 2017, I have led my team in developing several high-complexity and security projects following the best practices of the agile methodology using tools like scrum, kanban, heijunka, kaizen, and 5S. PROJECTS: Construction of high-performance and high-availability data centers. Operational redundancy projects. Physical and logical security. Intrusion testing and security assessments, including black-box, grey-box, and white-box testing. Performance testing. Implementation of compliance standards such as SOC-1, SOC-2, PCI-DSS, TPN (MPAA), ISO 27001/27002, HIPPA. Development of scalable and secure critical applications. Anti-fraud projects. Implementation of security projects.

Speaker: Daniel Tupinambá Gonçalves, Partner, Deloitte

A leader in Cyber Forensics with industry and consulting experience. He has served as a global CISO and executive for major players, possessing a strategic profile and a strong technical background. He has acted as an advisor to over 30 CISOs and CROs from large organizations, foundations, and government entities in Brazil. Globally, he has participated in technological transformation, cyber, safety initiatives in aviation, and military missions in countries such as the United States, France, Sweden, Portugal, the Netherlands, Singapore, and England.