My work comes down to one question: can the organization prove that its controls work? I have answered it for bank examiners, auditors, insurers and boards.
At First Guaranty Bancshares I built the information security program under FDIC and FFIEC examination and was promoted from CISO to CIO within four months. At eQHealth Solutions I took the company to HITRUST CSF certification in 11 months. At Lockstep Technology Group I built two security operations centers and a $3.4M managed security practice. In the Navy I was the information assurance manager for more than 600 reserve centers.
Today I serve clients as a virtual CISO through Transformyx Technology Services and lead cybersecurity, network and infrastructure work at OneVision Consulting, including NIST-based risk frameworks for chemical manufacturing. My book, The Assurance Gap, defines the independent Cyber Assurance Officer.
- Board and executive reportingRisk, evidence and cost, stated in business terms.
- Examination and audit readinessFFIEC, HIPAA and HITRUST, CMMC, PCI DSS and SOC 2.
- Security operations from zeroSOCs, vulnerability management, penetration testing and incident response.
- Budgets and teamsIT budgets to $8.2M and cross-functional teams of 400+.
Now
- Principal & Virtual CISO, Transformyx Technology Services
- Managing Director, OneVision Consulting
- Finishing the CyberCAAT demo