Presented by




Sponsored by


Speaker Information

Speaker Bios

Duane Baldwin, MBA, CISSP

Cyber Security Practice Director, COMSYS
Duane Baldwin leads the COMSYS Information Security Governance team. He has 20+ years of information security experience, working for numerous organizations including the Department Of Defense, Bank One, and the Department Of Energy. His team works with a number of Fortune 500 companies to address industry best practices for security and risk assessment, with a particular emphasis on regulatory requirements such as SOX, GLBA, PCI, and HIPAA. These efforts include successful remediation of vulnerabilities found in one of the largest data breaches in U.S. history.

Mr. Baldwin has extensive speaking experience, including presentations for the MIS Training Institute, InfraGard, ISSA, Tech Execs, and a presentation on cyber-security for a congressional sub-committee.

As a Certified Information Systems Security Professional (CISSP), Mr. Baldwin has more than 20 years in information security and information systems management, holding high ranking positions in the corporate, government, and financial sectors.

Mr. Baldwin’s work experience includes Fortune 500 companies such as SunTrust Banks, Abbott Laboratories, TJX, Bank One, Cisco Systems, and Dow Chemical. In 1999, he was part of the team that received the Computer Security Institute’s award for the nation’s best information security program.

Mr. Baldwin developed client/server architectures for secure financial transactions over public networks. This facilitated the deployment of banking services and retail sales of products over the Internet. These projects were the companies’ first deployment of secure financial transactions over the Internet and serve as the basis for the offering of additional services.  His work with standards has been implemented on a national level. As a member of the ABA Information Security Infrastructure Taskforce he collaborated on establishing security standards for financial Institutions. He also worked on the National X9 committee, developing and reviewing ANSI standards for secure electronic commerce.

Mr. Baldwin has worked with companies and agencies developing strategies for compliance with standards such as Sarbanes Oxley, PCI, GLBA, ISO 17799, NIST, DOE regulations, HIPAA, and others. This broad range of requirements provides the opportunity assist clients addressing best practices for their particular industry and environment and demonstrate means of establishing the appropriate level of security for their organization.

Mr. Baldwin has extensive experience with government agencies at the state and federal levels, working with both civilian and military personnel, to deploy and secure the nations cyber infrastructure in conjunction with the U.S. Department of Energy and the Department of Homeland Security.

Mr. Baldwin has performed cyber security assessments for a variety of enterprises with evaluations of both internal and external connections. These security assessments of both government and corporate connections have evaluated compliance with regulations, standards, directives, policies, and procedures. The results of some of this work at government laboratories and nuclear facilities have been published for Congress. The assessment of root causes of vulnerabilities discovered has been instrumental in eliminating weak points and improving processes for maintaining critical systems.

Mr. Baldwin holds a Masters of Business Administration degree from The Ohio State University.