Thomas Dempsey | Deputy Executive Director, Cybersecurity Directorate
U.S. Customs and Border Protection

Thomas Dempsey, Deputy Executive Director, Cybersecurity Directorate, U.S. Customs and Border Protection

Thomas Dempsey joined the U.S. Customs and Border Protection (CBP) Office of Information and Technology (OIT) in October 2019, assuming the position of Branch Chief of Cyber Threat Intelligence (CTI). He was subsequently appointed Director of Cyber Risk Management (CRM) in April 2022 and is currently acting in that position while being appointed as the Director of Security Operations Division and Deputy Executive Director Cybersecurity Directorate Operations in April 2026. Prior to his service with CBP, Mr. Dempsey was a Civilian Marine assigned to Marine Corps Cyber Protection Teams (CPTs). He brings an extensive and diverse background in cybersecurity and information systems, with experience cultivated across the military, public, and private sectors. Mr. Dempsey is a U.S. Marine Corps Veteran, and has held  critical roles in information systems security, cyber network defense, and security authorization within components of the Department of Homeland Security (DHS) and the Department of Defense (DoD). His professional experience also includes serving as Security Assurance Manager (SAM) for Immigrations and Customs Enforcement (ICE), Chief Information Systems Security Manager for Marine Corps Cyber Command, and as a Lead Information Systems Security Officer for SE Solutions. During his time at U.S. CBP Mr. Dempsey established the Cyber Risk Management (CRM) Division by implementing a strategic framework that aligns with the overarching CBP cybersecurity strategy, focusing on the identification and mitigation of cyber risks. The CRM Division is tasked with the critical responsibility of identifying, communicating, and disseminating cybersecurity risks, along with actionable mitigations and remediations, across both tactical and strategic levels within the CBP information technology environment. Mr.  Dempsey has spearheaded several key initiatives within the CRM Division. He established a Component Cyber Acquisition Risk Management (C-CARM) Integrated Product Team (IPT) to ensure the early integration of cybersecurity considerations into information systems throughout the Acquisition Lifecycle Framework (ALF). Furthermore, he developed and implemented a  robust quantitative risk assessment process designed to identify both new and existing risks pertinent to CBP information systems. Complementing these efforts, Mr. Dempsey instituted a Cyber Supply Chain Risk Management (C-SCRM) process, which seamlessly integrates with CBP's existing technology review protocols to pinpoint potential supply chain risks associated with new products. Additionally, he has taken a leading role in Artificial Intelligence (AI) Cybersecurity initiatives, collaborating with the Chief Technology Officer to establish rigorous review processes for AI systems before their deployment in production CBP environments, thereby ensuring adherence to CBP's stringent security requirements. During his time as Branch Chief for CTI, Mr. Dempsey was instrumental in developing and implementing a robust cyber threat hunting capability. This initiative proactively identified  Advanced Persistent Threats (APTs) within the CBP enterprise, facilitated prompt incident response activities, and advanced the development of sophisticated analytics for detecting
advanced cyber threat actors. Mr. Dempsey possesses multiple industry certifications, including the Certified Information  Systems Security Professional (CISSP). He holds a Bachelor of Science in Information  Technology Management, a Master of Cybersecurity, and is currently a doctoral candidate in
Strategic Intelligence at American Military University.

Appearances:



Identity Week America - Day 1 @ 13:40

Panel: The criminal gravy tr(ai)n: How are AI & cyber threats evolving and how can you future proof your security?

  • What are the biggest threats in the cybersecurity landscape?
  • How can AI strengthen cybersecurity threat detection, response automation, and predictive analytics?
  • Address the risks of AI misuse in cyberattacks, including identity fraud, social engineering, and deepfakes
  • Review use cases of AI enhancement of cybersecurity operations
  • Discuss the importance of public-private sector collaboration to harness the potential of AI while mitigating emerging threats
last published: 02/Sep/26 18:05 GMT

back to speakers

GET INVOLVED AT IDENTITY WEEK AMERICA

 

 

TO SPONSOR


Sophia Farwell

s.farwell@sciencemediapartners.com

 

 

TO SPEAK


Francis Wright

frank.wright@terrapinn.com

 

 

MARKETING & PRESS


Rob Arrenberg

r.arrenberg@sciencemediapartners.com