Dave Hatter
Cybersecurity Consultant | Recovering Developer
Cincinnati, Ohio, United States
Actions
An accomplished, enthusiastic, award-winning technology leader with over 30 years of software development, cybersecurity, and project management experience. Dave is a committed lifelong learner earning many leading certifications including CISSP, CISA, CISM, CCSP, CSSLP, Security+, Network+, MS Azure Fundamentals, PMP, PMI-ACP, PMI-PBA, PSM 1, PSD 1, and ITIL Foundation V3. He earned a BS in Information Systems from NKU and has written or contributed to 12 technology books, written more than 100 technology related articles and has been quoted in publications including The Wall Street Journal, Money, MSNBC, Salon, Reader’s Digest, MSN, Daily Mail, Business Insider, The Street, Yahoo!Money, The Ladders, Dice.com, InfoWorld, ComputerWorld, CIO, CSO, CIO Update, Search CIO, Recorded Future, Digital Trends, Tech Beacon, CyberNews, Lifewire and GearBrain. View here: https://davehatter.substack.com/p/dave-hatters-published-articles?r=vxw88
Dave is a regular media subject matter expert and can be heard every Friday morning at 6:30 AM on 55KRC’s “Tech Friday”, twice monthly on Simply Money on 55KRC, and seen every Monday on “Cyber Monday” on WTVG (13ABC) at 5:45 AM and “Tech Support” at 9 AM. Tech Friday has been named a Million Podcast Top 100 Cyber Security podcast, we're #39 on the Best 100 Hacker Podcasts. Join us every Friday at 6:30 AM on 55KRC or online. He is a regular guest on WXIX (FOX19), Local 12 (WKRC-TV), 700WLW and “City Talk” on TBNK. He has appeared more than 3,000 media interviews across the country including Fox News, CNN, MSN, NPR, Bloomberg Financial, SiruisXM, NewsNation, LocalNewsLive, Motley Fool Money, WCPO, WVXU, KVOA, 840 WHAS, WSMN and Spectrum News 1. He has also testified as cybersecurity expert before House and Senate committees at the Kentucky Legislature. View here: https://davehatter.substack.com/p/dave-hatter-media-appearances?r=vxw88
Dave has delivered hundreds of educational seminars for organizations including ISC2, ISACA, itSMF, ConnectWise, Cincinnati USA Regional Chamber of Commerce, Greater Cincinnati Better Business Bureau, Northern Kentucky Chamber of Commerce, Cincinnati AMA, PMI Southwest Ohio, Dayton/Miami Valley, PMI Central Ohio, The Circuit, Technology First, The Goering Center, The Kentucky League of Cities, Northern Kentucky University, the Ohio Cyber Range Institute, The Ohio Information Security Forum and the ISACA Cincinnati Chapter. View Here: https://davehatter.substack.com/p/dave-hatter-speaking-engagements?r=vxw88
Dave has educated over 1,100 students as an adjunct instructor at Cincinnati State Technical and Community College in a variety of software engineering and IT related courses. He has also taught at the University of Cincinnati and Gateway Community and Technical College, and he is the author of the Infosec Institute NIST 800-171 and the Certified Secure Software Lifecycle Professional Learning Paths.
Dave is committed to community service and has served as Mayor of Fort Wright, Kentucky since 2015 after serving eight terms on the Fort Wright City Council. He has also served on boards including the NKY Chamber of Commerce, the Cincinnati BBB, The Council of BBBs, PMI Southwest Ohio Chapter, NKU Alumni Council and Parish Kitchen. He is a member of Infragard, MS-ISAC, The NKU Business Informatics Advisory Council, The Cincinnati State Center for Innovative Technologies Advisory Committee, and the Gateway College of Information Technology Advisory Committee.
Dave is a graduate of Leadership Cincinnati, Leadership Kentucky, Leadership Northern Kentucky, and a member of the Cincinnati Business Courier’s “Forty Under 40”, Class of 2003. He was inducted into the Kentucky Veteran’s Hall of Fame in 2025, named the Kentucky League of Cities 2020 Elected Official of the Year, 2006 NKU College of Informatics Outstanding Alumnus, 1997 NKU Young Alumnus, a comSpark 2018 Rising Tech Star and he earned The Circuit’s 2021 Community Award.
Dave is currently an employee owner and Cybersecurity Consultant at Intrust IT.
Links
Area of Expertise
Topics
The Abysmal State of Software Security - And What To Do About It
From the SolarWinds breach to ransomware shutdowns of hospitals and automotive giants, software supply chain attacks are causing billions in damages and threatening national security. Meanwhile, the software we depend on is increasingly assembled from third-party and open-source components that organizations often can't even inventory, much less let alone secure.
We'll connect the dots between the rise of software-defined everything, the explosive growth of open-source dependencies, and the mounting wave of supply chain compromises. He'll walk through the sobering data: 57% of breaches trace back to unpatched software, 89% of codebases contain open-source components more than four years out of date, and 98% of organizations use at least one vendor that's been breached in the past two years.
But this isn't all a doom-and-gloom talkm we'll demystify Software Bills of Materials (SBOMs). What they are, why Executive Order 14028 now requires them for government software vendors, and how they serve as a foundation for vulnerability management, license compliance, and zero-trust architecture.
Attendees will learn the three accepted SBOM formats (SPDX, CycloneDX, SWID), explore Software Composition Analysis (SCA) tools, and understand how Vulnerability Exploitability eXchange (VEX) helps separate real risk from noise. The session closes with a call to action around CISA's Secure by Design principles and practical steps every organization can take today.
Agenda:
- Software-Defined Everything
- The Changing Nature of Software Development and Attacks
- Increasing Use of Free and Open-Source Software (FOSS)
- Third-Party and Fourth-Party Risk
- Supply Chain Attacks in the Wild
- Software Bill of Materials (SBOM)
- Secure by Design / Secure by Default
- Key Takeaways and Call to Action
- Q&A
Software Security: The Critical Role of Software Bill of Materials (SBOM)
Our increasingly digital society relies on software and the recent rise in software supply chain attacks and ongoing software vulnerabilities has forced software security to the forefront of public attention. As software grows ever more complex and inter-connected, it becomes more difficult to ensure that it is free of vulnerabilities and hardened against attacks. One approach to addressing this challenge is the use of Software Bill of Materials (SBOM) - a comprehensive list of components that make up a piece of software.
We will explain what SBOM is, how it works, and why it is essential for identifying and managing vulnerabilities. We will also examine the benefits of using SBOM, including improved transparency and accountability, better risk management, and enhanced cybersecurity posture.
We will also cover ongoing initiatives by governments, industry associations, and software vendors to promote the use of SBOM. We will also review the current state of SBOM adoption and provide recommendations for organizations to implement SBOM in their software development and procurement processes.
Mitigating the Privacy and Security Risks of “Citizen Development”
Digital transformation is driving up the demand for rapid application development and organizations are increasingly embracing “Citizen Development” to satisfy the demand. Non-technical users can leverage low-code and no-code (LCNC) tools and platforms to build and deploy software solutions with limited or no programming expertise. These tools are rapidly growing in popularity, in fact, Gartner predicts that by 2025, 70% of enterprises will use LCNC tools.
But LCNC solutions can pose significant security and privacy challenges that must be addressed to prevent data breaches and compliance issues. Forrester recently predicted that citizen development will lead to a headline security breach in 2023.
We will discuss popular NCLC tools and platforms used for Citizen Development, examine the challenges of managing Citizen Development, explore the threats and risks of Citizen Development and look at best practices for securing these tools and their output including security awareness training for Citizen Developers.
Summary:
This presentation will provide an in-depth understanding of the privacy and cybersecurity risks associated with Citizen Development and equip attendees with the knowledge and tools needed to effectively secure their organizations’ Citizen Development programs.
• Understanding Citizen Development
• Privacy Risks in Citizen Development
• Security Risks in Citizen Development
• Regulatory Compliance Challenges
• Reducing the Citizen Development Risk
• Building a Secure Citizen Development Program
• Q&A
How CIS Control 16 - Application Software Security - Helps Build More Secure Software
In today’s threat landscape, a single vulnerability in the code we write, the libraries we import, or the infrastructure we configure can lead to data breaches, downtime, regulatory fines, and eroded user trust.
This presentation dives into the CIS Controls Application Software Security Domain (Control 16 - https://www.cisecurity.org/controls/application-software-security), a respected framework for managing the full security lifecycle of in-house, hosted, and acquired software.
Tailored specifically for software engineers, the session highlights the real-world impact of insecure development practices and provides practical, actionable guidance drawn directly from the 14 safeguards in CIS Control 16. You’ll leave understanding why secure coding, threat modeling, vulnerability management, and secure design are non-negotiable parts of our daily work—and exactly how to apply them to prevent exploits before they reach production.
Agenda:
• The Critical Need – Why Software Security Is No Longer Optional
• CIS Control 16 at a Glance – The Official Framework for Application Security
• Core Practices Every Engineer Must Own (Core of CIS Control 16)Secure by Design & Development
• Vulnerability Management & Third-Party Risk
• Testing, Hardening & Separation
• From Awareness to Action – Making Security Part of Your Daily Workflow
• Key Takeaways, Q&A, and Your Next Steps
Dave Hatter
Cybersecurity Consultant | Recovering Developer
Cincinnati, Ohio, United States
Links
Actions
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top