Rochester built its reputation on imaging, and three of the four leaders below trace part of their careers through that legacy: Eastman Kodak, its health imaging spinout, its document imaging successor, and Xerox. The fourth came up through hospitals and clinical imaging networks before taking over security for the county. What connects the group is range. Between them they have written patented medical device software, operated Navy nuclear reactors, and supported telecom databases, and all four now hold the CISO title.
Michael LaLena – CISO, Carestream Health
As a college intern at the Naval Air Warfare Center, Michael LaLena found defects in ejection seat test data that had gone unnoticed for more than five years. His fix spared the Navy from repeating the tests. He had won the internship by taking first place at the Naval Air Development Center science fair. LaLena spent five years at ABB building history and reporting software for industrial control systems, then joined Eastman Kodak in 1999 to lead its common software platform for medical imaging. He stayed through the 2007 divestiture that created Carestream. There he led development of the DRX-Revolution mobile X-ray system, which reached 30% market share within three years and earned him nine U.S. patents. His move into security came through the products. As a software architect he built cybersecurity controls for Carestream’s imaging systems to FDA and RMF requirements, then directed product security for its medical devices. He became CISO in 2023, overseeing information security, privacy, and AI and medical device regulatory compliance. He also taught risk management for information security at RIT.
Daniel Krebs – CISO, Monroe County
Daniel Krebs spent most of his career keeping healthcare systems running. He administered networks and servers at Shore Health Services in Virginia, maintaining HIPAA and PCI compliance and migrating more than 400 endpoints to new antivirus protection. In Rochester he spent five years as the IT specialist for LDA Life & Learning Services across six locations. Three years at eHealth Technologies followed, supporting medical image exchange and the stroke network workflows that move radiology studies between hospitals. After a short stint as a clinical systems analyst at Monroe Community Hospital, Krebs joined Monroe County in 2019 as cybersecurity coordinator. He served two years as deputy director of Information Services and became CISO in January 2023. He now leads the county’s security strategy, policy, and incident response. He holds a CISSP. His first technology job was running a 50-computer student lab at Texas A&M University-Kingsville.
Deborah Cragg – SVP & CISO, Canandaigua National Bank & Trust
Database support was where Deborah Cragg started. She spent more than seven years at Nortel Networks managing Oracle systems in-house and at customer sites. At VoltDelta she led the technical support team through a joint venture merger, then spent 11 years as a quality and security compliance analyst. That work covered PCI, TL9000, ISO 9000, and SOX, along with automation tools for cross-functional teams. During Xerox’s corporate separation she helped establish the security program for the newly formed Conduent, later managing its data loss protection service for clients under PCI DSS, HIPAA, and GDPR requirements. She then led SIEM and intrusion prevention services for Xerox Global Security Services through Ciber. Cragg joined Canandaigua National Bank & Trust in April 2018 as SVP and CISO and has now held the role for more than eight years.
Bob Steron – SVP & CISO, Interactions LLC
Before cybersecurity, Bob Steron ran nuclear reactors. He spent nearly six years in the U.S. Navy as a reactor operator and electronics technician, supervising 20 sailors and teaching more than 300 students plant theory and operations. A decade at IBM followed. He consulted for financial sector clients and later served as functional CISO for Kaiser Permanente, IBM’s largest strategic outsourcing engagement at more than 30,000 managed hosts. Steron became the first-ever CISO of Kodak Alaris in 2016, building its security program from nothing across 40 countries and co-founding its global privacy office as data protection officer. After leading data protection at CCC Intelligent Solutions, he joined Interactions in 2021. As SVP and CISO since November 2024, he is accountable for cybersecurity, AI governance, privacy, IT, data, and quality assurance. He built an AI governance program for the full SoundHound.AI organization, including a public AI Trust Center, and was named 2025 Top Global CISO of the Year by Cyber Defense Media Group. He completed the FBI CISO Academy in 2025, chairs the Upstate NY Cybersecurity Executive Council, and has taught cybersecurity as an adjunct professor at RIT.
Rochester’s Second Act
Rochester’s imaging industry left behind more than buildings. It left a generation of technologists who learned to build regulated, high-stakes products, and several of them now run security. LaLena wrote medical imaging software for two decades before protecting it. Steron built Kodak Alaris’s first security program from scratch. Cragg helped stand up security for a company spun out of Xerox. Krebs took a different road through clinical systems and image exchange networks, but he landed in the same place: responsible for protecting data that people’s health and livelihoods depend on. Two of the four have also taught at RIT, and in a city with deep engineering roots, passing that knowledge on is part of the job.
Discover more CISOs securing their organizations:
- The Sun City’s Cybersecurity Leaders to Watch
- Between the Lakes: Madison’s Cybersecurity Leaders to Watch
- The House Always Defends: Las Vegas’s Cybersecurity Leaders to Watch
- Victoria’s Cybersecurity Leaders to Watch
- Huntsville’s Cybersecurity Leaders to Watch
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

