Author, Two-Time CISO
I'm a CISSP‑certified cybersecurity advisor, author of the GRC Maturity Model, and senior IEEE member. My first CISO role was in the DiB, my second CISO role was at a leading GRC startup.
Over nearly three decades I’ve helped Fortune 500 and Global 1000 firms align governance, risk, and compliance with business strategy, reduce incident‑response times by up to 45%, and avoid $10 M+ in potential losses. I have a book coming out later this year from a major publisher on why cyber risk is a fiction.
My work focuses on:
- Enabling CISOs, internal‑audit teams, and executives to translate technical risk into clear business outcomes.
- Designing GRC frameworks that turn compliance into a competitive advantage.
- Guiding organizations through emerging regulations such as the EU AI Act, SEC disclosure rules, and DORA.
I’m also a frequent keynote speaker and guest speaker on multiple podcasts, where I distill complex security topics into actionable insights for boardrooms and broader audiences.