Customers expect digital first products and services accessible from anywhere on any device. This has resulted in many things that were never envisioned to be remotely accessible now on the Internet. It also opened companies, and sometimes individual Executives, liable when those devices aren’t properly protected.
Providing appropriate protections is a balancing act between profitable business operations, allocating resources effectively, and managing the risks from the threat landscape the business operates in. Some organizations are fortunate enough to have someone within their organization to help them understand the more confusing cybersecurity risks they face, but people like that tend to be overloaded and pulled in many directions. Even with those people in-house, having a trusted advisor for thinking through challenges with a fresh pair of eyes that can share insights from regularly working with companies around the world on similar challenges can be a valuable asset.
I help CISOs and Executives take the jumble of standards and frameworks, best practices, audit findings, pen-test recommendations, project requirements, and business objectives and build roadmaps to take clients from current state to target state, explain the benefits and value of each workstream, and consolidate all the various requirements into a unified plan.
For the past 10 years, I led a global team that helped mature and enhance the cybersecurity programs for some of the world’s largest companies in the fintech/financial, critical infrastructure, global logistics, retail, healthcare, education, etc. industries using skills validated by 29 different professional certifications earned during my 25+ year career.
My outcome focused approach has delivered the following value:
Global Logistics Conglomerate: Removed the communication and operational friction that was preventing their Global SOC from performing effectively. Unified key stakeholders into a high functioning team, established clear roadmaps and milestones, then effectively delivered results.
Extremely large Global Financial Organization: Board wanted comprehensive cybersecurity monitoring within 1yr, but couldn’t articulate requirements. Resolved the ambiguity by defining scope and standards, then worked directly with stakeholders to deliver a unified, repeatable, and metric driven solution within 1yr that was praised by the Board and Executives.
Large National Utility Organization: Project to migrate on-prem core platform to Cloud was completely stuck for 1+ months even after bringing in vendor, developer, and Cloud experts. After reviewing the technical solution they were pursuing, I recognized that this was actually an intentional feature from one of the security protocols in use. I documented why the current approach could never work, and provided alternative solutions with the functionality and necessary security protections.
Large Manufacturing Organization: Needed an OT network design with effective segmentation and security monitoring of an immense manufacturing environment that prevented Wi-Fi and traditional cabling. Designed IP addressing and segmentation Architecture with multiple layers of protection that provided cybersecurity and traditional OT monitoring capabilities. This allowed for more effective cybersecurity as well as better QA due to the ability to identify defects earlier to reduce costs.
Large National Financial Organization: Regulatory audit finding related to internal data access on IBM mainframe. Worked with SMEs to understand Risk and identify mitigations. Within 1 month I developed a repeatable control to scan 55,000 datasets using VB, capture relevant evidence, and provide results to SMEs and auditors. Regulators complemented the effectiveness of my solution and closed the finding.
Please contact me on LinkedIn to discuss how I can help you achieve your business and cybersecurity objectives.