How to prioritize incident response investment by financial exposure
Every parent company knows its subsidiaries need incident response plans. Far fewer can say where an incident would hurt most and whether investment reflects it. Without a way to quantify exposure, IR spend tends to follow whoever asks loudest or whichever entity had the last scare.
LevelBlue and Resilience will walk through a practical model for putting a dollar figure on exposure, entity by entity, so investment follows risk concentration rather than recency.
Moderating and joining the conversation are Devon Ackerman, Global Services Leader, DFIR, and Ben Demonte, SVP, from LevelBlue, along with Simon West, Director of Cyber Resilience, and Ian Todd, SVP of Cybersecurity, from Resilience. The session is built for CFOs, risk managers, and security leaders at organizations with multiple subsidiaries or business units.
About Speakers

Devon Ackerman is the Global Leader for Digital Forensics and Incident Response services at LeveBlue. Devon’s experience includes serving as a Special Agent with the FBI with a focus on Digital Forensic Sciences, Counterintelligence, and Cyber-focused investigations. His passion lies in advising, investigating, and guiding victims of cyber incidents. Devon is the author of the book, “Diving In – An Incident Responder’s Journey,” which focuses on his experiences dealing with cyber threats, trends, and threat actor groups for nearly 25 years.

Ben Demonte is a seasoned cybersecurity executive and senior digital forensic examiner with more than three decades of experience spanning federal law enforcement, global consulting leadership, and high-stakes incident response. Over the course of his career, he has personally led hundreds of cyber investigations during his tenure with the Federal Bureau of Investigation and has overseen thousands more in his executive roles at Kroll and Cybereason, covering matters ranging from criminal and national security investigations to corporate data breaches, ransomware, business email compromise, insider threats, and advanced persistent threat intrusions. His career reflects a consistent focus on digital forensics, cyber investigations, and the operational management of large, technically sophisticated teams.

Ian Todd is Senior Vice President at Resilience, where he helps companies quantify cyber risk in financial terms across subsidiaries, portfolio companies, and business units, enabling them to prioritize security investments. He previously served as a director at NCC Group, focused on the financial services and insurance sectors, and co-founded two cybersecurity data platforms, SalesLynk and ThreatLynk. Earlier in his career, he held roles at Splunk, BlackBerry, and PwC spanning security advisory, IoT security, and cyber risk consultancy. He holds an MSc in Homeland Security from Northumbria University and a BA (Hons) in Criminology from Abertay University.

Si West leverages over two decades of global security expertise to bridge the gap between technical risk and business strategy. He partners directly with risk-focused CISOs to enable better decision-making while assisting brokers in mitigating client exposure. Si’s track record includes building out international security & risk services teams, advising on global underwriting teams, and developing critical incident response frameworks for large-scale, complex books of business. His credentials include 14 years of service in the Royal Marines, an NCSC Assured Instructor status, and an MSc in Cyber Security and Human Factors.
Any company that sells hardware or software with network connectivity into an EU member state has to report vulnerabilities and incidents affecting that product. The regulation calls these products with digital elements, and it applies to the manufacturer regardless of where the manufacturer is based, so a US firm with no EU presence is covered from the moment its first unit ships into the single market.