hi, I’m justin

(nice to meet you)

hi, I’m justin

(nice to meet you)

hi, I’m justin

(nice to meet you)

I post weekly professional insights and personal stories from my life as a management consultant, a dad, and an eternal optimist.

Scroll to learn more about my professionalpersonal, and “perfessional” background

professional

bio

I am the Founder and CEO of acceligence, a management consulting firm focused on technology, cybersecurity, risk, and strategy. I help executives and boards of the world’s leading organizations optimize their technology investments and transform risk into competitive advantage.

Prior to acceligence, I led the North America Cybersecurity Practice at McKinsey & Company, serving technology executives, the c-suite, and boards across a variety of industries, to protect their most critical assets while helping them go faster with confidence. I work closely with technology and cybersecurity providers and investors on strategy, growth, and go-to-market programs that build market leadership and yield tangible results.

Before McKinsey, I built, scaled, and led numerous global practices within EY‘s (Ernst & Young) cybersecurity, technology transformation, and digital divisions. I was also a senior consultant with Protiviti in Paris, and before that, I led the technology organization of a public sector consulting group. I began my career as a tech entrepreneur, founding a digital consulting company that designed, built, and implemented digital solutions.

I served on the faculty at Indiana University Kelley School of Business, where I taught award-winning courses on IT governance, risk, and controls in the MSIS and MBA programs. A strong believer in the power of education, I founded a scholarship focused on providing higher education opportunities to students in need.

I am a frequent speaker at industry conferences and various executive and board forums. I publish frequently on topics such as technology strategy, cybersecurity, technology risk, and digital transformation. I have a bachelor of science and an MBA from Indiana University, Bloomington; an executive certificate from Harvard Business School, and I hold the following professional certifications: CDPSE, CGEIT, CIPP/US, CISA, CISM, CISSP, CRISC, GIAC/GSEC, ITIL, PMP, and TOGAF.

I live in the Chicago suburbs and I serve as a Trustee on the Executive Committee and Chair the Audit and Risk Committee at Ravinia. I am also a member of the Dean’s Council at Indiana University’s Kelley School of Business. I am proud father of two amazing kids, and I have a list of hobbies and interests that only seems to be growing.

I write frequently at JustinGreis.com where I share professional insights and personal stories from work, life, and everything in between.

I am the Founder and CEO of acceligence, a management consulting firm focused on technology, cybersecurity, risk, and strategy. I help executives and boards of the world’s leading organizations optimize their technology investments and transform risk into competitive advantage.

Prior to acceligence, I led the North America Cybersecurity Practice at McKinsey & Company, serving technology executives, the c-suite, and boards across a variety of industries, to protect their most critical assets while helping them go faster with confidence. I work closely with technology and cybersecurity providers and investors on strategy, growth, and go-to-market programs that build market leadership and yield tangible results.

Before McKinsey, I built, scaled, and led numerous global practices within EY‘s (Ernst & Young) cybersecurity, technology transformation, and digital divisions. I was also a senior consultant with Protiviti in Paris, and before that, I led the technology organization of a public sector consulting group. I began my career as a tech entrepreneur, founding a digital consulting company that designed, built, and implemented digital solutions.

I served on the faculty at Indiana University Kelley School of Business, where I taught award-winning courses on IT governance, risk, and controls in the MSIS and MBA programs. A strong believer in the power of education, I founded a scholarship focused on providing higher education opportunities to students in need.

I am a frequent speaker at industry conferences and various executive and board forums. I publish frequently on topics such as technology strategy, cybersecurity, technology risk, and digital transformation. I have a bachelor of science and an MBA from Indiana University, Bloomington; an executive certificate from Harvard Business School, and I hold the following professional certifications: CDPSE, CGEIT, CIPP/US, CISA, CISM, CISSP, CRISC, GIAC/GSEC, ITIL, PMP, and TOGAF.

I live in the Chicago suburbs and I serve as a Trustee on the Executive Committee and Chair the Audit and Risk Committee at Ravinia. I am also a member of the Dean’s Council at Indiana University’s Kelley School of Business. I am proud father of two amazing kids, and I have a list of hobbies and interests that only seems to be growing.

I write frequently at JustinGreis.com where I share professional insights and personal stories from work, life, and everything in between.

I am the Founder and CEO of acceligence, a management consulting firm focused on technology, cybersecurity, risk, and strategy. I help executives and boards of the world’s leading organizations optimize their technology investments and transform risk into competitive advantage.

Prior to acceligence, I led the North America Cybersecurity Practice at McKinsey & Company, serving technology executives, the c-suite, and boards across a variety of industries, to protect their most critical assets while helping them go faster with confidence. I work closely with technology and cybersecurity providers and investors on strategy, growth, and go-to-market programs that build market leadership and yield tangible results.

Before McKinsey, I built, scaled, and led numerous global practices within EY‘s (Ernst & Young) cybersecurity, technology transformation, and digital divisions. I was also a senior consultant with Protiviti in Paris, and before that, I led the technology organization of a public sector consulting group. I began my career as a tech entrepreneur, founding a digital consulting company that designed, built, and implemented digital solutions.

I served on the faculty at Indiana University Kelley School of Business, where I taught award-winning courses on IT governance, risk, and controls in the MSIS and MBA programs. A strong believer in the power of education, I founded a scholarship focused on providing higher education opportunities to students in need.

I am a frequent speaker at industry conferences and various executive and board forums. I publish frequently on topics such as technology strategy, cybersecurity, technology risk, and digital transformation. I have a bachelor of science and an MBA from Indiana University, Bloomington; an executive certificate from Harvard Business School, and I hold the following professional certifications: CDPSE, CGEIT, CIPP/US, CISA, CISM, CISSP, CRISC, GIAC/GSEC, ITIL, PMP, and TOGAF.

I live in the Chicago suburbs and I serve as a Trustee on the Executive Committee and Chair the Audit and Risk Committee at Ravinia. I am also a member of the Dean’s Council at Indiana University’s Kelley School of Business. I am proud father of two amazing kids, and I have a list of hobbies and interests that only seems to be growing.

I write frequently at JustinGreis.com where I share professional insights and personal stories from work, life, and everything in between.

experience

chief executive officer

acceligence

August 2025 – Present

Chicago, Illinois

  • Founded management consulting firm focused on technology, cybersecurity, risk, and strategy

  • Oversee all client service and firm management activities

  • Built AI-first consulting platform and innovative service offerings

board advisory services

National Association of Corporate Directors (NACD)

April 2026 – Present

Chicago, Illinois

  • Serve as a faculty member to advise on AI, technology, cybersecurity, and risk topics

  • Provide actionable guidance through education, facilitation, assessment, coaching, and analysis

  • Help board and C-suite leaders govern AI and technology while moving at unprecedented speed

partner

McKinsey & Company

August 2021 – July 2025

Chicago, Illinois

  • North America Cybersecurity Leader

  • Global Cybersecurity People Leader

  • Chicago Office Firm-Serving Professional Leader

  • Chair, Healthcare CISO Group Roundtable

partner

EY (Ernst & Young)

June 2004 – July 2021

Chicago, Illinois

  • Global and Americas Cyber Strategy, Risk Compliance, and Resilience Leader

  • Americas Cyber Architecture, Engineering, and Emerging Tech Leader

  • Founding Partner of Tech Transformation and Digital Practices

adjunct faculty

Kelley School of Business

August 2008 – August 2021

Bloomington, Indiana

  • Adjunct faculty in the Master of Science in Information Systems (MSIS) Program

  • Taught multiple award-winning IT Governance, Risk, and Controls (IT GRC) courses

  • Taught numerous IT and Enterprise Risk Management courses in the Kelley Direct MBA program

senior consultant

Protiviti

March 2003 – June 2003

Paris, France

  • Helped establish and build firm’s european presence and Paris office location

  • Designed and built digital controls self-assessment platform

  • Developed solutions and go-to-market service offerings for the European region

BrainOrbit

Founder and CEO (June 2002 – May 2004) – Bloomington, Indiana
Founded profitable bootstrapped technology consulting company providing dynamic websites to large companies, universities, and government agencies. Oversaw numerous client go-lives and software launches of our clients’ digital projects and products.

The Eppley Institute for Parks and Public Lands

Technology Director (June 2000 – May 2004) – Bloomington, Indiana
Oversaw technology organization for non-profit, university-sponsored park service and public lands consulting agency.

education

bachelor of science

Indiana University, Bloomington

Kelley School of Business

August 1999 – June 2002

Bloomington, Indiana

  • Major: Accounting and Information Systems

  • Undergraduate and business honors program

  • Myers Writing Scholarship recipient

  • Featured in Time Magazine for teaching in IU’s innovative pre-Freshman program

mba

Indiana University, Bloomington

Kelley School of Business

June 2002 – June 2004

Bloomington, Indiana

  • Major: Accounting and Information Systems

  • President, Academy of Business Technology

  • Internship, EY (Ernst & Young) in Chicago, Illinois

  • MBA field study internship with Protiviti in Paris, France

executive certificate

Harvard University

Harvard Business School

January 2017 – December 2017

Cambridge, Massachusetts

  • Executive business leadership certificate program

  • Sponsored for enrollment among highest performing leaders in the firm

credentials

Certified Information Systems Auditor® (CISA)

Certified Information Security Manager® (CISM)

Certified in Risk and Information Systems Control™ (CRISC)

Certified Data Privacy Solutions Engineer™ (CDPSE™)

Certified in the Governance of Enterprise IT® (CGEIT)

Certified Information Systems Security Professional (CISSP)

Certified Information Privacy Professional/United States (CIPP)

GIAC Security Essentials Certification (GSEC)

Information Technology Infrastructure Library (ITIL)

The Open Group Certified: TOGAF® 9 Certified

Project Management Professional (PMP)®

McKinsey & Company - Cybersecurity Credential

McKinsey & Company - Knowledge & Capabilities Gold Credential

McKinsey & Company - Digital & Analytics (DnA) - Tech Resiliency & Cybersecurity

McKinsey & Company - All In, Diversity & Inclusion (ADI) Gold

McKinsey & Company - Innovation Olympics Silver Badge (2025)

McKinsey & Company - Innovation Olympics Bronze Badge (2024)

McKinsey & Company - Recruiting Gold Credential

McKinsey & Company - Knowledge & Capabilities Gold Credential

publications

The list below is a selection of my authored publications, research, and articles to which I have written, contributed, and/or been quoted.

The list below is a selection of my authored publications, research, and articles to which I have written, contributed, and/or been quoted.

This article warns that the rapid expansion of autonomous, agentic AI is set to explode enterprise attack surfaces just as CISOs remain largely blind to non-human identities (NHIs). Analysts estimate enterprises already manage millions of machine identities, with visibility often below 25% and projected to fall into the single digits as agents proliferate and spawn new credentials autonomously. Experts argue the core issue is not agentic AI itself, but decades of neglected NHI governance that left enterprises without scalable identity foundations. Rather than attempting to retroactively inventory and fix the mess, several practitioners advocate for containment strategies and clean-slate governance for all new identities going forward. The piece concludes that agentic AI forces a fundamental shift in security thinking, where identity becomes the operating system of trust and governance must focus on ownership, intent, and runtime accountability rather than static access controls.

Read more →

Go to website →

This article examines why 91% of enterprise users log in with maximum privileges, framing the behavior less as recklessness and more as the byproduct of years of accumulated complexity, weak governance, and brittle legacy systems. Analysts argue that always-on privilege persists because it keeps fragile environments running, even as it undermines core principles of least privilege and introduces major security, operational, and compliance risks. While experts widely agree that just-in-time access and stronger PAM controls are needed, adoption remains rare due to tool friction and fear of disrupting mission-critical systems. The problem is accelerating as non-human identities – such as service accounts, APIs, and automation pipelines – now hold the majority of standing privileges and operate continuously. Together, these forces are pushing privileged access management toward a fundamental paradigm shift, exposing the limits of human-centric IAM and PAM models in modern enterprise environments.

Read more →

Go to website →

Five leading cybersecurity executives and public company directors discuss how chief information security officers and boards can work together to grow and protect their organizations.

The era when cybersecurity was a separate, isolated function at organizations is over. Today’s threats, fueled by AI, require organizations to infuse “air to ground coverage”—from the boardroom down—across the institution. No one is more aware of these threats and the scale of the necessary response than an organization’s chief information security officer (CISO).

At a recent panel discussion, McKinsey and the National Association of Corporate Directors (NACD) gathered five top CISOs and board directors to discuss how cybersecurity is changing, how organizations must shift their approach, and how CISOs and directors are uniquely positioned to co-lead the effort to keep institutions safe while benefiting from new technologies.

Moderated by McKinsey alumnus Justin Greis, the panel included Katie Jenkins, CISO at Liberty Mutual; Marco Maiurano, CISO at First Citizens Bank; Matt Rogers, independent director for Exelon; Noopur Davis, chief product and information security officer for Comcast and board member at Regions Bank and Entrust; and Nora Denzel, an NACD director, lead independent director at AMD, and a board member at Gen Digital and Sony Group.

This Q&A has been edited for clarity and length.

Read more →

Go to website →

Supply chain cybersecurity vulnerabilities frequently make headlines, so being prepared must be a priority. Here’s a new approach to protecting business-critical processes from nth-party risks.

In the modern economy, almost every business is a tech business, with digitization, automation, and data solutions embedded into multiple operations. But with these advancements come risks. One of the most critical risks is that responsibility for technology often does not sit with companies themselves but instead with an array of third-party suppliers, service providers, and subcontractors. By outsourcing IT services, companies can unlock efficiencies and innovation. The downside is that they can also struggle to ensure that their businesses remain secure and resilient.

Modern technology supply chains are not much like chains at all. In fact, they are more like three-dimensional spiderwebs, each strand of which is connected to and dependent on others, and some of which are far removed from the company itself. As such, technology risk management is increasingly concerned not only with immediate supplier relationships but also with distant and sometimes ambiguous third parties, or nth parties, which often sit several layers away from the company’s direct line of sight.

Third- and nth-party supplier cyberincidents are a significant source of risk, in some cases leading to the loss of data for hundreds of millions of people. Indeed, over the past two years, nearly one-third of cyber breaches has been associated with technology supply chains, and multiple incidents have highlighted the cascading effects that a single compromised supplier can have on organizations and sectors. Moreover, despite companies sometimes spending millions on controls, supply chain oversight is often surprisingly basic—comprising unvalidated responses in risk questionnaires or simple clauses contained in contracts. Alternatively, companies spend so much time focusing on supplier cyber risks that they drag their feet and fail to implement a useful, high ROI solution in a timely fashion.

As the number of ransomware incidents, data breaches, and supply chain attacks continues to rise (up 83 percent, 135 percent, and 236 percent, respectively, over the past two years), companies urgently need to ramp up their capabilities. To some extent, this is already mandated by regulation. The European Union’s Digital Operational Resilience Act (DORA), the United Kingdom’s Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) operational resilience rules, and Australia’s APRA CPS 230 are among initiatives that lay out strict standards for IT risk management. These vary somewhat in their detail, but one underlying principle holds true: Companies have a duty to ensure that their approaches to supplier risk management reflect both their unique risk profiles and the criticality of the business processes in question.

Traditional third-party risk management (TPRM) frameworks often emphasize the confidentiality and integrity aspects of the CIA (confidentially, integrity, and availability) triad. But the availability—and, more specifically, the resilience of business-critical systems (the ability to withstand an adverse event without interruption)—is equally as important. Indeed, focusing on business-critical nth-party relationships, rather than getting bogged down in hypercomplexity, is an excellent way to get a grip on supply chain risks. At a time of rising cyberthreats, companies that can put this distinction into practice achieve the double win of protecting their vital operations and building competitive advantage.

Read more →

Go to website →

By Michelle R. Lowry,a Anthony Vance, Marshall D. Vancea, Accounting and Information Systems Department, Pamplin College of Business, Virginia Tech, Blacksburg, Virginia 24060; Department of Business Information Technology, Pamplin College of Business, Virginia Tech, Blacksburg, Virginia 24060 

We conduct a field study of boards’ emerging responsibility to oversee cybersecurity risk, a setting in which few directors have expertise. We find that, although nonexpert directors may genuinely seek to provide diligent oversight, without expertise their efforts lack substance and therefore are mostly symbolic, even when they perform the same oversight activities as expert directors. We also explore why boards do not prioritize the appointment of cybersecurity experts and show that nonexpert directors do not perceive that their efforts are symbolic and insufficient. In contrast, expert directors perceive keenly the deficiency of their nonexpert counterparts and argue for the need for more cybersecurity experts on boards, and this viewpoint is shared by cybersecurity executives and consultants who support the board. Thus, we contribute to our understanding of when boards are likely to provide substantive versus symbolic oversight and inform the debate on the merits of board-level cybersecurity expertise.

Note: Interviewed and quoted as anonymous expert contributor.

Read more →

Go to website →

The rapid advancement of AI and generative AI (gen AI) is fundamentally transforming the cybersecurity landscape, presenting both opportunities and challenges for cybersecurity providers. As more organizations in both the private and public sectors use AI to enhance their operations, they risk inadvertently introducing new cyber-related threats. This is creating a significant and growing demand for advanced cybersecurity solutions.

AI is also being used by bad actors as a tool to fuel more sophisticated cyberattacks and increase their volume, as exemplified by the rise in AI-enhanced social engineering and the substantial financial impact of data breaches. For example, gen AI has enhanced social-engineering techniques, in which attackers generate highly realistic phishing emails or deepfakes to trick employees into sharing sensitive information or credentials. In 2023, the total cost of cybercrime had more than doubled since 2015.

While companies’ response time to cyber-related risks has generally decreased over the past several years, it still takes organizations an average of 73 days2 to contain an incident, highlighting the ongoing difficulty of containing breaches. Combined with an expanding attack surface (that is, more devices and technologies that could be breached or exploited), an increase in threat actor sophistication, a lack of skilled cybersecurity workers, and a wave of new regulations, organizations are increasingly leaning on third parties to help them manage cyber risk.

Read more →

Go to website →

While companies’ response time to cyber-related risks has generally decreased over the past several years, it still takes organizations an average of 73 days to contain an incident, highlighting the ongoing difficulty of containing breaches. Combined with an expanding attack surface (that is, more devices and technologies that could be breached or exploited), an increase in threat actor sophistication, a lack of skilled cybersecurity workers, and a wave of new regulations, organizations are increasingly leaning on third parties to help them manage cyber risk.

Helping companies address these risks represents a significant opportunity for providers of cybersecurity solutions, but capitalizing on that opportunity requires considerable investment in innovation and new paths to market.

In addition to securing the general use of AI, using AI to help improve security is also an opportunity for cybersecurity providers. According to our research, customers say today’s cybersecurity solutions often fall short of meeting demands in terms of automation, pricing, services, and other capabilities. Helping organizations manage this risk in a cost-efficient manner is a big opportunity for cybersecurity providers, but they will need to understand AI technology and embrace it within their offerings. Innovation also remains critical in traditional cybersecurity products as the market continues to evolve, requiring providers to shift their marketing strategies to meet customers where they are seeking solutions.

Read more →

Go to website →

Horizons of Identity Security 2024-2025: Harnessing the power of identity security to bend the cybersecurity value curve

Higher identity security maturity delivers outsized returns

Cyber threats are evolving, and identity security is under increasing pressure to protect against growing attack surfaces while meeting the demand for seamless digital experiences – and showing a measurable return on investment. With 41% of organizations at the lowest maturity level for identity security, the path to reducing risks and enhancing business value is wide open.

The third annual Horizons of Identity Security report reveals how every dollar invested in identity security can “bend the cybersecurity value curve,” providing higher returns through risk reduction and workforce productivity gains – to name a few.

Gain insights for transforming your identity program into a strategic investment as you:

  • Understand the five horizons of identity security maturity and where your organization stands
  • Learn how to leverage AI and automation to enhance your security posture
  • Unlock new value pools, including reduced cyber insurance premiums and improved compliance

Read more →

Go to website →

The C-suite should not leave complete control of technology to the techies but assume rigorous oversight from day one

The risks of cybersecurity lapses are well known, from flight cancellations to ransomware demands to run-of-the-mill ever-present (though still troubling) data breaches. In 2023, known ransomware payments hit a record $1.1 billion. IBM research found a 71% increase in cyberattacks that used stolen or compromised credentials. A survey by McKinsey and the Institute of International Finance found that even among financial service companies, which are well aware that they are prone to attack, their capabilities are often no match for the skills of well-organized and expert cyber criminals.

Launching a cyberattack is relatively easy, and attackers have the luxury of failure: they only need to succeed occasionally. The implication is that the defenses need to be at least as determined as the assaults. And for that to happen, boards are in a unique position to play an active oversight role. Here are three principles to keep in mind.

Read more →

Go to website →

In the second quarter of this year, there were 877,536 phishing attacks, according to a report by the Anti-Phishing Working Group, a not-for-profit coalition of cybercrime experts.

According to APWG, phishing via phone calls and text messages is being used with “increasing frequency” to attack bank customers and payment service users. Meanwhile, Cofense Inc., an email security firm, notes that hackers often use times such as open enrollment and 401(k) updates to hack into participants’ accounts.

Plan advisers are, ideally, working with their plan sponsors on a consistent basis to stay up to date on their cybersecurity practices. The Department of Labor recently updated its cybersecurity guidance, reinforcing that guidance applies to all covered employee retirement benefit plans and health and welfare plans.

But what can plan fiduciaries do to help protect their employees from email, text and social media scams?

Justin Greis and Charlie Lewis, partners in consultancy McKinsey & Co., say via email that “no single control is a silver bullet to protect savers from becoming victims.” But they do provide six steps that fiduciaries can share with participants to help protect them from harm.

Read more →

Go to website →

The responsibilities of boards of directors regarding cybersecurity are changing significantly, as is the cybersecurity industry itself.

Amid growing corporate and public sector cyber breaches and recent high-profile technology outages, significant changes are occurring in both the role of boards in cybersecurity and within the cybersecurity industry itself. In this interview, McKinsey’s Sean Brown speaks with Vinnie Liu, the cofounder and CEO of the cybersecurity firm Bishop Fox, and McKinsey cyber-resilience experts Justin Greis and Daniel Wallance about how boards of directors should approach oversight of cybersecurity. The following is an edited transcript of their conversation.

For more discussions on the strategy issues that matter, follow the Inside the Strategy Room podcast on your preferred podcast platform.

Read more →

Go to website →

THE CYBER CLOCK IS TICKING: DERISKING EMERGING TECHNOLOGIES IN FINANCIAL SERVICES

As financial-services companies around the world race to keep pace with a rapidly evolving technology landscape, they should consider not only what benefits new emerging technologies offer but also what risks they introduce.

To understand how companies are grappling with the best ways to use and protect the technologies of today and tomorrow, McKinsey partnered with the Institute of International Finance (IIF) to survey financial institutions around the world regarding their current and planned usage of ten key emerging technologies. How are companies approaching emerging technologies? What emerging technologies are they adopting? How do they plan to secure and mitigate the associated cyber risks? What cybersecurity capabilities will be needed to successfully adopt and secure new technologies?

Of the emerging technologies included in the survey, a majority of financial-services companies indicated that they are prioritizing adoption of and investment in four of them: cloud and edge computing, applied AI, next-gen software development, and digital identity and trust architecture (exhibit). All four technologies are likely to see quicker adoption than advanced connectivity, future mobility, immersive reality, quantum, machine learning, and Web3. This is perhaps because of their widespread applicability and maturity, as well as their proven, value-based use cases for financial-services companies.

Read more →

Go to website →

Which technology trends matter most for companies in 2024? New analysis by the McKinsey Technology Council highlights the adoption, development, and industry effects of advanced technologies.

Despite challenging overall market conditions in 2023, continuing investments in frontier technologies promise substantial future growth in enterprise adoption. Generative AI (gen AI) has been a standout trend since 2022, with the extraordinary uptick in interest and investment in this technology unlocking innovative possibilities across interconnected trends such as robotics and immersive reality. While the macroeconomic environment with elevated interest rates has affected equity capital investment and hiring, underlying indicators—including optimism, innovation, and longer-term talent needs—reflect a positive long-term trajectory in the 15 technology trends we analyzed.

What’s new in this year’s analysis?
These are among the findings in the latest McKinsey Technology Trends Outlook, in which the McKinsey Technology Council identified the most significant technology trends unfolding today. This research is intended to help executives plan ahead by developing an understanding of potential use cases, sources of value, adoption drivers, and the critical skills needed to bring these opportunities to fruition.

Our analysis examines quantitative measures of interest, innovation, investment, and talent to gauge the momentum of each trend. Recognizing the long-term nature and interdependence of these trends, we also delve into the underlying technologies, uncertainties, and questions surrounding each trend.

Read more →

Go to website →

Third-party vulnerabilities spread like a digital forest fire

Threat researchers used the SecurityScorecard platform to identify the supply chain cyber risk across approximately 12 million organizations. Key findings include:

  • 150 companies account for 90% of the technology products and services across the global attack surface.
  • 41% of those companies had evidence of at least one compromised device in the past year.
  • 11% had evidence of a ransomware infection in the past year.
  • 62% of the global external attack surface is concentrated in the products and services of just 15 companies.
  • The top 15 third parties have below-average cybersecurity risk ratings – indicating a higher likelihood of breach.
  • Ransomware operators C10p, LockBit, and BlackCat systematically target third-party vulnerabilities at scale. Within 5 minutes of connecting an internet-facing device, state-sponsored threat actors will find it.

The sheer scale of these companies amplifies their risk of compromise, posing significant third-party risks to their extensive customer bases. Defending massive attack surfaces presents a formidable challenge, even for the most robust security teams. While these companies must maintain flawless security at all times, attackers need only exploit a single vulnerability within their expansive attack surface.

Read more →

Go to website →

Decision puts pressure on CISOs and those crafting SEC filings as wording could be judged as “half-truths” and considered misleading.

The United States Supreme Court unanimous ruling on an SEC disclosure case on Friday could have direct consequences on how security executives report cybersecurity incidents.

The decision in the Macquarie Infrastructure versus Moab Partners’ case gave enterprises the green light to not report incidents that are not material, which was already directly implied in the current SEC rules. The court was referring to risks, specifically those that are potential and theoretical but have not necessarily happened. That might include, for example, a series of attacks overseas that could potentially be modified to hurt the company at issue. It hasn’t happened yet, but it might.

The news for CISOs is that the court gave a strong caveat. It ruled that although companies are absolutely within their rights to not report such things, they have to carefully consider those items when phrasing what they do report to the SEC. The court warned companies that if the unreported information would make what the company does report to the SEC misleading or seriously out-of-context, the company could face serious consequences.

The Supreme Court’s decision referenced such statements that would later become misleading as half-truths. “The difference between a pure omission and a half-truth is the difference between a child not telling his parents he ate a whole cake and telling them he had dessert. It requires disclosure of information necessary to ensure that statements already made are clear and complete i.e., that the dessert was, in fact, a whole cake,” the Court ruled.

Read more →

Go to website →

As financial institutions actively adopt emerging technologies, they should act now to future-proof themselves against growing cyber risks.

As financial-services companies around the world race to keep pace with a rapidly evolving technology landscape, they should consider not only what benefits new emerging technologies offer but also what risks they introduce.

To understand how companies are grappling with the best ways to use and protect the technologies of today and tomorrow, McKinsey partnered with the Institute of International Finance (IIF) to survey financial institutions around the world regarding their current and planned usage of ten key emerging technologies. (For details on research methodology, including the short-listing of top technology trends, based on global industry trends, see “Appendix: Approach and methodology.”) How are companies approaching emerging technologies? What emerging technologies are they adopting? How do they plan to secure and mitigate the associated cyber risks? What cybersecurity capabilities will be needed to successfully adopt and secure new technologies?

Read more →

Go to website →

In the race to build new businesses, decision makers often overlook risk management and cybersecurity. We have identified six misconceptions that executives often bring to the table.

If it’s a great idea, just do it. In boardrooms around the world, entrepreneurial leaders understand that successful business building is about putting words into action. Nobody ever created a unicorn by having another meeting. Still, while business leaders are renowned for their ability to get things done, there is a flip side to the value creation gene. In the rush to market, it is easy to forget that the world’s most successful companies have often withstood early threats to their viability. Indeed, our experience shows that business leaders who build resilience into their strategies are most likely to create winning propositions.

Business building is high on CEO agendas: in a recent McKinsey global survey, eight in ten CEOs cite new-business building as a top five priority, despite heightened economic volatility. Business leaders are building 50 percent more new businesses per year than they did two to five years ago. And every dollar of revenue from new businesses generates almost twice the enterprise value of every dollar of core business revenues.

Still, new businesses also create unseen risks. For instance, in digital-business building, one commonly overlooked area is cybersecurity—the protection of information systems and networks from attacks by malicious actors. At the current rate of growth, it is estimated that cybercrime costs will reach about $10.5 trillion annually by 2025—a 300 percent increase from 2015 levels. Still, decision makers often fall victim to “normalcy bias,” or the tendency to underestimate the likelihood or impact of a potential hazard based on the belief that things will continue as they did in the past. In other words, “It won’t happen to me.”

Read more →

Go to website →

The new SEC rules make it seem that there is no need to report the presence of security vulnerabilities, but that doesn’t quite tell the full story.

Now that the SEC wants to know about any material security incidents within four days of determination, CISOs must determine what constitutes a material security incident — which goes far beyond a mere data breach.

One thorny element revolves around security vulnerabilities, regardless of whether they were discovered internally or reported by an external source. Security leaders need to ask: What could happen if attackers discover and use that flaw? How damaging would that be? Those answers could help security leaders figure out whether the security flaw should be reported to the SEC.

Read more →

Go to website →

A new report from the International Bar Association (IBA) Presidential Task Force on Cybersecurity and the IBA Legal Policy & Research Unit (LPRU) provides a first-of-its-kind global perspective on key governance practices for senior managers and boards of directors to protect their organisations against cyber-attacks. Titled “Global perspectives on protecting against cyber risks: best governance practices for senior executives and boards of directors,” the report provides an insight into existing cybersecurity threats and outlines actionable steps that companies can take to strengthen their cyber risk governance.

The report draws on sources across ten jurisdictions—Australia, Brazil, Denmark, Germany, India, Israel, Singapore, Uganda, the United Kingdom and the United States – to provide comparative analysis with diverse international case studies.

With the rise of 5G networks, quantum computing and devices linked to the Internet of Things, cybersecurity is fast evolving into a primary concern for society at large. According to data from the Identity Theft Resource Center, 53.3 million Americans were impacted by a data compromise in the first half of 2022. Meanwhile the telecommunications company Verizon reported that of the total breaches committed in 2022, 89% were financially motivated and almost half of all cyber breaches featured hacking.

Regulatory bodies have begun developing legal guidelines and standards in response to the increase in cyber-attacks. However, simply abiding by such regulations no longer secures companies, rather company leaders must proactively establish security frameworks and strategies.

Through its country-level case studies, the report highlights the widely varying cybersecurity practices across regions due to differences in regulatory capabilities. While organisation-level governance and accountability are important, large-scale leadership is undoubtedly necessary.

Read more →

Direct article link →

Go to website →

Imagine getting a frantic voice or video call from a familiar source. There’s an emergency. They request something dramatic like approval for a huge invoice, sending sensitive files or take assets offline. If this were a phishing email, someone might dismiss it. But when it’s a familiar voice or face, how hard would someone try to verify it’s legit? What if it turned out to be an artificial intelligence (AI)-fueled scam?

Whether firms adopt generative AI (GenAI) or not, hackers and security researchers are already exploring how to abuse it to attack anyone. Specifically, security leaders observe nine cyber threats that GenAI will amplify. They fall into one or more of three overlapping types: attacks with AI, attacks on AI or erring with AI. All told, there will be more things to attack, more ways to attack them (or trick people) and attacks will become easier and more damaging — at least initially.

Read more →

Go to website →

The release of ChatGPT-4 last week shook the world, but the jury is still out on what it means for the data security landscape. On one side of the coin, generating malware and ransomware is easier than ever before. On the other, there are a range of new defensive use cases.

Recently, VentureBeat spoke to some of the world’s top cybersecurity analysts to gather their predictions for ChatGPT and generative AI in 2023. The experts’ predictions include:

  • ChatGPT will lower the barrier to entry for cybercrime.
  • Crafting convincing phishing emails will become easier.
  • Organizations will need AI-literate security professionals.
  • Enterprises will need to validate generative AI output.
  • Generative AI will upscale existing threats.
  • Companies will define expectations for ChatGPT use.
  • AI will augment the human element.
  • Organizations will still face the same old threats.

Below is an edited transcript of their responses.

“Broadly, generative AI is a tool, and like all tools, it can be used for good or nefarious purposes. There have already been a number of use cases cited where threat actors and curious researchers are crafting more convincing phishing emails, generating baseline malicious code and scripts to launch potential attacks, or even just querying better, faster intelligence.

“But for every misuse case, there will continue to be controls put in place to counter them; that’s the nature of cybersecurity — a neverending race to outpace the adversary and outgun the defender.

“As with any tool that can be used for harm, guardrails and protections must be put in place to protect the public from misuse. There’s a very fine ethical line between experimentation and exploitation.”

— Justin Greis, Partner, McKinsey & Company

Read more →

Go to website →

Today’s business and public-sector leaders face an risk landscape disrupted at levels that few have seen before and none has ever confronted as an executive. We have reached a defining leadership moment, where executives are taking a step back and redefining resilience.

Read more →

Full PDF Download →

Direct Article Link →

Until recently, most companies were unaware of the “ingredients” or code that make up the software that powers their products and enterprise software. This is an issue because third-party code usage is increasing, and the consumption of open-source software (OSS) will accelerate in the years to come.

Companies leverage open source software because it reduces costs and increases the pace of software development. By layering in code that someone else has already built, developers can decrease their time to market and accelerate the feature sets most desired by their business partners. The challenge is that the code in the open source software repository may have embedded malware, bugs, or other vulnerabilities unbeknownst to the developer. Without a robust vetting process for the code in the open source software repository from which their developers are pulling, companies will remain unaware of threats lurking in their products.

To keep pace with the evolving security dynamic, companies need new programs and management techniques to understand the origin and security of the code that underpins their digital products and business operations. Without such a system, companies will remain vulnerable to unwittingly inserting malware that could cause cybersecurity incidents or damage critical applications. While some cyberthreats can be avoided by developing custom code in-house, that process is resource intensive and time-consuming. Moreover, using open source software has benefits such as being able to build quickly in the cloud or increasing developer productivity. In reality, most applications are built using a combination of custom code and open-source components. That is when a delicate balancing act falls on chief technology officers (CTOs), chief information officers (CIOs), and chief information security officers (CISOs) who are sensitive to OSS’s inherent risks.

Read more →

Go to website →

As software-related vulnerabilities continue to grow, companies must manage their software cyber risks to innovate faster and create safer, more secure digital products.

Until recently, most companies were unaware of the “ingredients” or code that make up the software that powers their products and enterprise software. This is an issue because third-party code usage is increasing, and the consumption of open-source software (OSS) will accelerate in the years to come.

Companies leverage OSS because it reduces costs and increases the pace of software development. By layering in code that someone else has already built, developers can decrease their time to market and accelerate the feature sets most desired by their business partners. The challenge is that the code in the OSS repository may have embedded malware, bugs, or other vulnerabilities unbeknownst to the developer. Without a robust vetting process for the code in the OSS repository from which their developers are pulling, companies will remain unaware of threats lurking in their products.

To keep pace with the evolving security dynamic, companies need new programs and management techniques to understand the origin and security of the code that underpins their digital products and business operations. Without such a system, companies will remain vulnerable to unwittingly inserting malware that could cause cybersecurity incidents or damage critical applications. While some cyberthreats can be avoided by developing custom code in-house, that process is resource intensive and time-consuming. Moreover, using OSS has benefits such as being able to build quickly in the cloud or increasing developer productivity. In reality, most applications are built using a combination of custom code and open-source components. That is when a delicate balancing act falls on chief technology officers (CTOs), chief information officers (CIOs), & chief information security officers (CISOs) who are sensitive to OSS’s inherent risks.

Read more →

Go to website →

Companies say they haven’t seen such wide-ranging board-governance proposals from the SEC since rules implemented after the Great Recession.

Read more →

Go to website →

As public companies prepare for cybersecurity disclosures, CFOs ready for another reporting responsibility.

Having long clamored for enhanced ESG transparency, investors are close to getting their wishes. In March, the Securities and Exchange Commission issued proposals for public companies to disclose their cybersecurity and climate change risks in financial statements. In the works is another SEC proposal involving the disclosure of human capital management policies and practices.

Assuming the three proposals reach a final stage of rulemaking with little change, they will add to a CFO’s reporting obligations and related legal accountability. Under the CEO/CFO Certification Requirement of the Sarbanes-Oxley Act, CEOs and CFOs must personally certify the accuracy of a public company’s financial statements.

“Like other CFOs I talk with regularly, no one is exactly sure how ESG will be monitored, other than it will be,” said Mark Partin, CFO at publicly traded BlackLine, a provider of financial and accounting software and services, with $425.7 million in 2021 revenues and more than 1,800 employees globally.

Fortunately, finance chiefs like Partin and other strategic CFOs have amassed a skills set that would humble their forebears. Immersed in their organizations’ fiscal health, technology underpinnings, customer experiences and enterprise operations, no other senior management leader has what it takes to oversee such rarefied disclosures.

Such is the case with the SEC’s 129-page cybersecurity proposal. Public companies would be required to report material cyber incidents within four business days, disclose their cybersecurity governance practices and expertise, and provide periodic updates of previously reported cyber incidents.

Read more →

Go to website →

Shed the conventional methods. Talent-to-value protection defines the most important cybersecurity roles that demonstrate the greatest reduction in risk for the enterprise.

To meet the security requirements to face evolving threats and changing technology, organizations must adapt and shift how they previously managed cybersecurity. While technical controls and capabilities still remain a priority and a commonly accepted method of securing the environment, adapting to a new approach for hiring cybersecurity talent can solve a leading concern of many leaders in a cost-optimized and risk-effective manner.

Hiring cybersecurity talent normally uses a top-down approach that fills most senior roles first before filling roles further down the organizational chart. However, because of cybersecurity worker shortages and the need to focus on specific capabilities from a talent pool—sometimes with nontraditional backgrounds—the standard hiring approach is less effective in this competitive job market.

While one answer may be to throw money at the problem and hire as many workers as possible to grow your organization over time, this approach does not necessarily lead to reduced risk. No matter what approach to resourcing companies use, the changing nature of cyberrisk means companies need to manage talent flexibly to adapt to new threats.

By preplanning and understanding the organization’s cybersecurity needs holistically, it is possible to lay out a hiring road map that focuses specifically on the most critical cyber initiatives. Assessing risks, understanding priorities, and then filling those roles based on capabilities and associated skills can reduce risk and protect business value.

Read more →

Go to website →

Cybersecurity incidents have been taking place for years, but most have remained out of the public spotlight until the past decade. Recent high-profile incidents that affected large numbers of everyday citizens have catapulted the issue into the national discourse and the legislative and regulatory spotlight. We are now entering a new era in cybersecurity—one in which governments, regulatory agencies, and companies around the world work to increase oversight of cybersecurity incidents.

Companies may regard new regulations as an opportunity to prepare for greater cyber transparency. In the US, two cyber regulations are likely to have an impact on multiple industries in the commercial sector. First, the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), signed into law in March 2022, will require critical infrastructure companies, including financial services, to report cybersecurity incidents, such as ransomware attacks, to the CISA. In addition, the US SEC in March 2022 proposed a rule requiring publicly listed companies to report to the SEC cybersecurity incidents, their cyber capabilities, and their board’s cyber expertise and oversight.

Entities in the 16 critical infrastructure sectors defined by CISA and all registrants with the SEC should consider acting now to prepare for CIRCIA and the expected SEC rule. Where appropriate, companies may consider providing their valuable input on the shape of the regulations’ detailed rules as they are formed in the months ahead. Regardless of how the final regulations are put into practical enforcement, organizations can benefit from establishing or fine-tuning cyber-crisis management programs that will help prepare for increased regulatory requirements and improve their cyber-defense posture.

This article lays out the new context of cyber and the contents of the anticipated new US regulations. It then proposes for a three-step approach to preparing organizations for readiness, response, and remediation.

Read more →

Go to website →

It’s not simply about getting easy permission to go when it’s time to part ways; it’s about IT making sure any decisions don’t complicate that eventual departure.

Read more →

Go to website →

The EY Global Information Security Survey 2021 finds CISOs and security leaders battling against a new wave of threats unleashed by COVID-19.

In brief…

  • Cybersecurity is under pressure: 81% of execs say that COVID-19 forced organizations to bypass cybersecurity processes.
  • Three challenges stand out: insufficient budgets, regulation complexity, and strained relationships with the business.
  • If CISOs can readdress shortcomings with a security by design approach, they will become enablers of growth in the rebound era.

he EY Global Information Security Survey 2021 (GISS) illustrates the devastating and disproportionate impact that the COVID-19 crisis has had on a function that is striving to position itself as an enabler of growth and a strategic partner to the business.

Through a global survey of more than 1,000 senior cybersecurity leaders, we find CISOs and security leaders grappling with inadequate budgets, struggling with regulatory fragmentation, and failing to find common ground with the functions that need them the most.

Read more →

As the world continues to become more digitized and connected, the risks themselves are also changing, which opens systems and data to potential cybersecurity attacks. For the first time since 2013, the National Institute of Standards and Technology (NIST) has published the special publication (SP) 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations — which aims to assist public and private organizations better manage their risk — focusing on a “new state-of-the-practice controls.” Following the guidelines is voluntary in the private sector; however, NIST encourages the private sector to adopt the new guidelines, just as many have already adopted NIST’s Cybersecurity Framework (CSF).

NIST’s update and expansion to its flagship catalogue of controls creates an opportunity for those protecting the enterprise to leverage the “next generation of security and privacy controls” by going beyond compliance, integrating privacy and security efforts, and addressing complex supply chain risk management.

Read more →

The rapidly evolving threat around the COVID-19 virus, commonly referred to as coronavirus, is raising concerns among the business and investor community across the world. The global and interconnected nature of today’s business environment poses serious risk of disruption of global supply chains that can result in significant loss of revenue and adversely impact global economies. The impact on the global economy may increase depending on the extent of geographic spread of the virus. However, the current uncertainty has already negatively impacted the global economy as a whole.

Read more →

More than two decades since EY started reporting on organizations’ efforts to safeguard their cybersecurity, the threat continues to both increase and transform. We face more attacks than ever before, and from a wider range of increasingly creative bad actors — often with very different motivations. The good news is that boards and senior management are engaging more intimately with cybersecurity and privacy matters. In this era of transformation, senior leaders are acutely conscious
of their organizations’ vulnerabilities and the potentially existential dangers posed by attackers.

But there is work to do. Not only is cybersecurity an evolving risk, it also has to be confronted in the context of innovation and change. Security by Design should be the aim of every organization.

This year’s GISS explores these ideas in more detail. We’re grateful to everyone who took time to participate in this research — almost 1,300 organizations. Pooling our knowledge and experience and working together will improve cybersecurity for all.

Read more →

Throughout 2019, this mini-series will interview leaders from around the globe to discuss areas of cybersecurity. The purpose is to help students or those new to the industry gain perspective and guidance from professionals in the field. These interview insights aim to kick-start or re-energise your career journey in cybersecurity.

In this month’s feature, Justin Greis, EY’s Americas Practice leader for Cyber Resilience, shares:

  • His description of cyber resilience, and how this is portrayed in the market.
  • What, if any, information would he have liked to know starting out in his career.
  • How he suggests others new to the field get involved.

Greis describes how he discovered his passion to tinker and build things early in his career, which fostered his love for technology and business. He loved the idea that technology could fundamentally make lives better, more efficient, and more enjoyable. His career journey spans as an entrepreneur owning a technology consulting company to EY where he has gained experiences across a full spectrum of Advisory services, including Cybersecurity. His professional journey has led to many opportunities across technology to help his clients solve their most complex business and technology problems.

These are his insights.

Read more →

Go to website →

We live in a world in which data breaches and destructive cyber attacks have become a daily headline. By now, everyone has received a breach notification letter or an email apology from a company impacted by a major cybersecurity issue. Boards are asking, customers are asking, and the employees are asking, the whole world seems to be asking one simple question: Why?

Read more →

Quality is a word that has so many meanings. To say something is ‘quality’ or is ‘of good quality’ or is ‘quality made’ seems to be, like so many things a function of the trust you place in the person making the claim combined with individual standards we each apply to determine ‘what is good’ and ‘what is bad’. Like determining ‘what is beauty?’ we know these standards vary person to person, but I’m curious: are there universal truths to achieving high quality that transcend subjective opinion and relate to everyone universally regardless of background, bias or prior experience?

Read more →

As digital technologies take hold, organizations need to understand and manage the risks to their valuable assets. As organizations relinquish control of their applications, data, infrastructure and more, it is critical to assess the new digital risks they assume and find new ways to mitigate them.

Digital technologies such as social, mobile, analytics and cloud are fundamentally changing how companies do business. Companies that use digital technologies successfully embrace them as part of their business and IT strategies, weighing the value as well as the potential risks. Yet, as digital’s use expands across the enterprise, IT departments struggle to control and manage the proliferation of digital technologies within the organization, as well as the associated risks. They may improve the way we work, live and interact with one another, but can we trust it?

Building trust into an environment where digital technologies, legacy systems and infrastructure all have to live together in one digital ecosystem can be challenging. It requires organizations to rely more on third parties and expand the borders of the technology perimeter into places they cannot control. As organizations relinquish control, it is critical to assess the new risks they assume and find new ways to mitigate them.

Read more →

Unlike many industry publications that talk about the risks and roadblocks of moving to the cloud, this publication changes the dialog to thinking cloud first. The guide provides a cloud trust framework – built upon our knowledge and experience with working with some of the world’s largest and most complex Cloud Service Providers (CSP) and Cloud Service Consumers (CSC) – for creating an ecosystem that has a trusted design, trusted execution and trusted certification. We believe that all cloud environments should strive to be secure, trusted and audit-ready but it does take the know-how to weigh the risks and address them appropriately so they do not put the business in jeopardy.

We also introduced the concept of the cloud ecosystem. Previous thinking on the subject has primarily focused on either the CSC or the CSP. While both parties are important, they are two pieces of the puzzle that must fit together and work in harmony and not at odds. We have recognized that a trusted ecosystem can only be achieved when the two parties work together to build trust into their respective environments, thereby creating a trusted ecosystem of controls.

Read more →

Today’s digital landscape is changing rapidly and the risks can escalate quickly.

Cloud computing, mobile technology and social media can help an organization achieve its business goals, but boards need to pay close attention to the associated risks. We discuss the challenges and opportunities of current digital technologies, and provide questions for boards and audit committees to consider.

Cloud computing can provide organizations many benefits, but it’s important to build a secure, trusted and audit-ready environment to help avoid the dangers.

Read more →

Today’s digital landscape is changing rapidly and the risks can escalate quickly.

Cloud computing, mobile technology and social media can help an organization achieve its business goals, but boards need to pay close attention to the associated risks. We discuss the challenges and opportunities of current digital technologies, and provide questions for boards and audit committees to consider.

Many board members and employees use mobile devices to access data and perform their jobs. We explore how to develop a secure and successful mobile program.

Read more →

Today’s digital landscape is changing rapidly and the risks can escalate quickly.

Cloud computing, mobile technology and social media can help an organization achieve its business goals, but boards need to pay close attention to the associated risks. We discuss the challenges and opportunities of current digital technologies, and provide questions for boards and audit committees to consider.

Social media can be a powerful business tool, but it can come with some risks. A well-planned and executed strategy is critical.

Read more →

Wherever your business is in its ‘cloud journey’, you need to create a cloud services environment that is Secure, Trusted and Audit-Ready (STAR).

Read more →

“Building Trust in the Cloud” publication cited by IT Business Edge on March 3, 2014.

Read more →

Go to website →

To achieve a successful cloud computing deployment, companies must shift their focus toward building a secure, trusted and audit-ready cloud environment.

Original link to article (no longer posted)

Not that long ago, cloud computing was little more than a speck on the horizon. We heard reports of it rapidly becoming a mainstream technology, but it had yet to make a meaningful impact on our technology landscape. According to EY’s Global Information Security Survey, in 2010, 30 percent of respondents indicated that their organization used or was planning to use cloud computing-based services. In 2011, the percentage had risen to 44 percent. By 2012, cloud computing had reached a technological tipping point: Almost 60 percent of survey respondents said their organization was using or planned to use cloud computing services. And yet, 38 percent of respondents said that they had not taken any measures to mitigate the risks of using cloud computing services. This disruptive technology was advancing faster than many could secure it.

A more recent Forrester Research report suggests that for 73 percent of surveyed businesses in Europe and North America, security remains a major concern when considering cloud computing.

One of the first principles of improving information security is taking control of your environment. It would therefore feel counterintuitive for an organization to surrender control of its IT infrastructure and data to a third party. And yet this approach may offer the best opportunity to address increasingly complex security and privacy challenges. Rather than becoming an organization’s worst security nightmare, cloud computing platforms may offer its best hope to create a more secure IT environment by strengthening controls and improving information and security capabilities.

Read more →

Go to website →

Once an emerging technology, cloud computing services have arrived, and they are here to stay.

Cloud allows for increased business agility, faster speed to market, lower information technology costs and happier customers.

According to our survey, cloud adoption increased nearly 100% from 2010 to 2012. Yet, within many organizations, IT has been reluctant to embrace cloud as a viable solution.

Undeterred, business units are often going it alone, procuring cloud services without IT’s involvement. The result is a shadow IT environment that is tough to manage, difficult to operate and nearly impossible to secure.

Organizations seeking to take advantage of cloud computing to create a more nimble, digitally integrated business environment are quickly learning that cloud services need to be adopted as an integral part of the organization’s existing operating model. However, this can create unforeseen risks if businesses do not simultaneously develop a cloud governance model to establish standards for the business to follow and create clear direction and consistency in managing cloud services.

Read more →

Despite the risks of not making security policies central to enterprise BYOD and mobility programs, many organizations are ignoring this best practice.

With any new technology, enterprise IT organizations tend to deploy first, introduce policies later. This policy-as-an-afterthought approach is always problematic, but the potential for trouble is especially high when employees use their personal mobile devices for work purposes.

For example, a recent Jupiter survey found that more than 80 percent of smartphones are not protected against malware. Jupiter also noted that the BYOD (bring your own device) trend is making it tough for enterprises to maintain a holistic perspective on mobile security. Enterprises had a much easier time locking down mobile devices when all employees carried the same, company-issued device, often a BlackBerry.

But the mobile security landscape has changed, thanks to the proliferation of mobile devices and applications, most of which can be purchased from an app store and downloaded directly to a device.

“The threats are increasing in severity, frequency and complexity,” said Justin Greis, senior manager in EY’s Information Technology Advisory Practice. “And as the boundaries of organizations expand, threats have new places to hit. So unless you bake security and policy in from the beginning, it makes it hard to rein in the data.”

With mobile devices increasingly embedded into all parts of our personal lives, organizations are finding that their employees increasingly want to use their own personal mobile devices to conduct work (often alongside corporate-provided devices), and many are reaching out to corporate IT for support.

In the current economic environment, companies are demanding that employees be more productive: having a robust mobile program that allows personal devices to be used safely in a work capacity can raise employee productivity and be a significant competitive advantage. It can even yield higher recruiting acceptance rates.

An employee IT ownership model, typically called bring your own device (BYOD), presents an attractive option to organizations. BYOD significantly impacts the traditional security model of protecting the perimeter of the IT organization by blurring the definition of that perimeter, both in terms of physical location and in asset ownership.

With personal devices now being used to access corporate email, calendars, applications and data, many organizations are struggling with how to fully define the impact to their security posture and establish acceptable procedures and support models that balance both their employees’ needs and their security concerns.

Read more →

Title XIII of the American Recovery and Reinvestment Act of 2009 (ARRA) includes the subsection known as the Health Information Technology for Economic and Clinical Health (HITECH) Act. In addition to its incentives for health care organizations to adopt electronic health records (EHRs), HITECH extended the scope of the HIPAA Privacy Rule and the Security Rule, increased penalties for failing to protect PHI and increased enforcement for violations of the Health Insurance Portability and Accountability Act (HIPAA).

Read more →

Cloud computing issues and impacts combines the insights of Ernst & Young’s own leading thinkers with analysis of secondary market research and other sources to synthesize our view of the current state of cloud computing, where it is going in the foreseeable future and the holistic way you should think about it. Through this series of topical drill-down discussions, we offer our insight and hope to stimulate productive dialogue within and across your organizations about how to make the most of the transformative force of the cloud.

Read more →

Many organizations are looking to cloud computing to increase the effectiveness of IT initiatives, reduce cost of in-house operations, increase operational flexibility, and generate a competitive advantage. Through an effective strategy, cloud computing can enable many companies to do much more with IT by becoming strategy focused and not operations focused. Cloud-based services are nimble and adaptive, increasing capability to read and react to changing marketplace conditions by responding to customer needs and competitors’ actions.

Read more →

Justin Greis is a senior manager in the advisory practice of Ernst & Young. He specializes in IT risk and assurance by helping his clients manage risk and improve business performance from their IT investments. Greis has more than 10 years of executive and entrepreneurial leadership experience in IT. He currently also serves as professor of information systems at Indiana University’s Kelley School of Business (USA). In 2010, he was selected as one of nine global winners of the Ernst & Young Chairman’s Values Award, the firm’s highest honor, for his outstanding commitment to the firm’s values and its people.

Read more →

Not that long ago, cloud computing was little more than a speck on the horizon.

According to EY’s Global Information Security Survey, in 2010, 30% of respondents indicated that their organization used or was planning to use cloud computing-based services.

In 2011, the percentage had risen to 44%. By 2012, cloud computing had reached a technological tipping point: almost 60% of survey respondents said their organization was using or planned to use cloud computing services.

And yet, 38% of respondents said that they had not taken any measures to mitigate the risks of using cloud computing services. This disruptive technology was advancing faster than many could secure it.

One of the first principles of improving information security is take control of your environment. It would therefore feel counterintuitive for an organization to surrender control of its IT infrastructure and data to a third party.

And yet this approach may offer the best opportunity to address increasingly complex security and privacy challenges. Rather than becoming an organization’s worst security nightmare, cloud computing platforms may offer its best hope to create a more secure IT environment by strengthening controls and improving information and security capabilities.

Read more →

The complexity of today’s enterprise systems leaves many companies struggling with the basic internal control of segregation of duties.

Segregation of Duties (SoD) is top of mind for many professionals, from compliance managers to executive-level officers. The increased interest in SoD is due, in part, to control-driven regulations worldwide and the executive-level accountability for their successful implementation. However, the underlying reason for these regulations is more important: no individual should have excessive system access that enables them to execute transactions across an entire business process without checks and balances. Allowing this kind of access represents a very real risk to the business, and managing that risk in a pragmatic, effective way is more difficult than it seems.

If this concept is common sense, why do so many companies struggle with SoD compliance and why does it repeatedly stifle information technology (IT), internal audit and finance departments? In large part, the difficulty rests in the complexity and variety of the systems that automate key business processes, and the ownership and accountability for controlling those processes.

SoD is a basic internal control that attempts to ensure no single individual has the authority to execute two or more conflicting sensitive transactions with the potential to impact financial statements. Without proper guidance and a sound approach, SoD implementation, testing, remediation and mitigation may appear to be extremely difficult to achieve. However, a risk-based approach can make the effort manageable for a company of any size.

Companies don’t need to create complex role structures or undertake expensive system overhauls in order to meet SoD compliance and the principle of least privilege. By focusing on the transactions that pose the greatest risk to the business, a company can quickly understand the issues related to access and determine — at a level that satisfies management and audit parties — that appropriate steps are being taken to remedy and mitigate the root causes of the issues.

This document outlines a practical, risk-based approach to SoD compliance.

Read more →

Segregation of duties (SoD) is a hot topic of conversation among a range of professionals, from compliance managers to executive officers. The outpouring of interest in SoD is due, in part, to the requirements of the Sarbanes-Oxley Act in the US and other similar control-driven regulations worldwide. However, there is another factor at work: the principle that no individual should have excessive system access that enables him/her to execute conflicting end-to-end transactions. If this concept is common sense, why do so many companies struggle with SoD compliance and why does it repeatedly stifle IT, internal audit and finance departments? In large part, the difficulty rests in the complexity and variety of the systems that automate key business processes and the ownership and accountability for controlling those processes.

Read more →

Segregation of Duties (SoD) remains elusive for many organizations even though its operating principle is quite simple: no individual should have excessive system access that allows them to commit fraud or materially impact the financial statements. The challenge lies primarily in the complexity of the interconnected systems and processes that exist in many modern enterprises. Spurred by Sarbanes-Oxley and similar control-related regulations worldwide, companies have never had a greater incentive to establish rigorous SoD policies and procedures.

Read more →

speaking and convening

The list below is a selection of my speaking engagements and events I have convened and/or participated.

The list below is a selection of my speaking engagements and events I have convened and/or participated.

Step into the future of work with a panel of AI trailblazers as they unpack what it really takes to thrive in artificial intelligence. Hear from leaders across academia, startups, and industry as they share honest insights on mentorship, skills, and turning your passion for AI into a purpose-driven career.

Curious about where a career in artificial intelligence can take you? Join us for an inspiring panel discussion where AI experts and industry leaders share their experiences, advice, and insights on mentorship, professional growth, and the future of work in AI. Whether you’re an undergraduate discovering your interests or a graduate student mapping your career path, this session will help you connect your academic experience to real-world opportunities.

Topics will include

  • Navigating the diverse career paths available in artificial intelligence and data science
  • Finding and building meaningful mentorship relationships in the AI community
  • Developing the technical and soft skills that make you stand out in a competitive field
  • Translating classroom learning and research into practical, impactful AI projects

Event details

  • Wednesday, November 17, 2025 from 5:00 PM to 6:00 PM
  • Hosted via Zoom in Virtual Panel format
  • Free to attend, but registration is required

Hosts and panelists

  • Erika C. Burt, Assistant Dean of Professional and Academic Programs, Illinois Institute of Technology, College of Computing
  • Nicole Beebe, Dean and Professor of Information Technology and Management, Illinois Institute of Technology, College of Computing
  • Justin Greis, Founder and Chief Executive Officer, acceligence
  • Paige Kinsley, Argonne Leadership Computing Facility Education Outreach Lead, Argonne Laboratories
  • Arpit Gangrade, Director of Data & AI Engineering, CCC Intelligent Solutions
  • Chloe Lannert, Go to Market, Anthropic

Most organizations are racing to adopt AI without considering the security implications. Justin Greis, former leader of McKinsey’s cybersecurity practice and founder of an AI-powered consulting firm Acceligence, explains why this approach creates risk and how security leaders can change the conversation.

Companies are deploying AI at different maturity levels. Some distribute AI tools to business units and wait for use cases to emerge. Others push boundaries with advanced algorithms. Few consider the associated risks. The right stakeholders often aren’t in the room when AI decisions are made, either because organizations want to move fast or because security teams are underfunded and focused on daily operations. Technology companies are making AI capabilities available at unprecedented speeds, leaving organizations uncertain about securing and deploying these tools responsibly.

Security should be the foundation of trust, not an afterthought. McKinsey research found that customers make buying decisions based on product security when companies can demonstrate testing and rigor. A secure, certified product materially influences purchasing choices compared to alternatives without visible security standards.

Greis emphasizes that compliance certifications like SOC 2 or ISO represent minimum requirements, not security maturity. Organizations secure enough to meet business objectives naturally achieve compliance. The goal is translating business initiatives into security requirements that exceed baseline standards.

The Chief Information Security Officer position has shifted from back-office administrator to business enabler. AI has accelerated this change by converging infrastructure, technology, and cybersecurity into unified platforms. CISOs now have opportunities to demonstrate how they understand business context and can help organizations move faster and safer.

The challenge for security leaders is communication and relationship building. Years of underfunding forced CISOs to focus on survival rather than strategy. As security functions reach parity with other departments, more leaders can engage at the executive and board level. This shift requires CISOs to develop storytelling skills that contextualize security metrics for business audiences rather than overwhelming boards with technical details.

As AI agents begin making decisions without human oversight, organizations face new risks. The push to remove humans from decision loops creates efficiency but introduces vulnerabilities, particularly when AI accesses data it shouldn’t process or makes decisions affecting vulnerable populations. Companies need frameworks to identify where human oversight remains necessary and mechanisms to monitor those boundaries.

Organizations implementing AI successfully have thought through secure development lifecycles, DevSecOps, and product operating models. Those starting from scratch face larger organizational changes to incorporate security, privacy, and responsible AI practices into development workflows.

Watch podcast at Kiteworks →

Watch podcast at YouTube →

Listen to podcast on Apple Podcasts →

Cybersecurity threats are no longer just an IT concern: they’re a boardroom issue. If you sit on a board, you’re already a target, and attackers know how to exploit vulnerabilities to their advantage. These straightforward, practical steps will help you protect your personal digital life and strengthen the cybersecurity posture of the organizations you serve.

Read more →

Read more →

Go to website →

The pace of technological change presents profound opportunities and risks for business. This brings the relationship between boards, CISOs, and the partners that corporations rely on into acute focus. Join NACD and McKinsey & Company for cocktails and hors d’oeuvres at the 2025 RSA Conference and for networking and a panel discussion as we explore the evolving relationship between Chief Information Security Officers (CISOs) and Directors. During this panel discussion, we’ll discuss how that relationship is evolving to address the current — and stay ahead of the rapidly evolving — technology and cyber environment so that boards, CISOs, and the partners that corporations rely on can work together to help govern, grow, and protect their organizations.

As generative AI rapidly advances, it brings transformative opportunities alongside multifaceted risks that organizations must navigate. This panel discussion will delve into exploring the critical challenges and strategic imperatives for managing these risks effectively. Join us for an engaging discussion that will equip leaders with actionable strategies to harness the power of generative AI while safeguarding against its inherent risks. This session is essential for business executives, risk management professionals, and AI practitioners committed to responsible AI innovation.

Video Replay (YouTube) →

Event Link →

Co-presenter for Horizons of Identity Security 2024-2025 breakout session at SailPoint Navigate Executive Circle Conference.

In today’s episode, we discuss the top 10 questions boards should ask to ensure comprehensive cybersecurity oversight. We’re joined by Justin Greis, a partner in our Chicago office who leads McKinsey’s cybersecurity work in North America; Daniel Wallance, a senior expert in our New York office who focuses on cybersecurity and technology resilience in financial institutions, critical infrastructure companies, and public sector organizations; and Vinnie Liu, who is the CEO and co-founder of the cybersecurity firm Bishop Fox.

Read more →

Apple Podcasts →

Spotify →

IN THIS PANEL, EXPERTS WILL PROVIDE A COMPREHENSIVE RECAP OF THE CYBER LANDSCAPE IN 2023, HIGHLIGHTING SIGNIFICANT EVENTS, TRENDS, AND DEVELOPMENTS.

FROM EMERGING CYBER THREATS TO ADVANCEMENTS IN CYBERSECURITY MEASURES, THE PANELISTS WILL ANALYZE THE KEY FACTORS SHAPING THE CURRENT LANDSCAPE. ADDITIONALLY, THE DISCUSSION WILL DELVE INTO FORECASTS FOR THE FORESEEABLE FUTURE, EXPLORING POTENTIAL CHALLENGES, OPPORTUNITIES, AND STRATEGIES FOR NAVIGATING THE EVOLVING CYBER ENVIRONMENT.

THIS PANEL PROMISES VALUABLE INSIGHTS INTO THE CURRENT STATE AND FUTURE TRAJECTORY OF CYBERSECURITY.CITIZEN INSECURITY AND CRIME MIGRATION TO IN LATIN AMERICA

————-

EN ESTE PANEL, LOS EXPERTOS BRINDARÁN UN RESUMEN COMPLETO DEL PANORAMA CIBERNÉTICO EN 2023, DESTACANDO EVENTOS, TENDENCIAS Y DESARROLLOS IMPORTANTES.

DESDE LAS CIBER AMENAZAS EMERGENTES HASTA LOS AVANCES EN LAS MEDIDAS DE CIBERSEGURIDAD, LOS PANELISTAS ANALIZARÁN LOS FACTORES CLAVE QUE DAN FORMA AL PANORAMA ACTUAL. ADEMÁS, EL DEBATE PROFUNDIZARÁ EN LAS PREVISIONES PARA EL FUTURO PREVISIBLE, EXPLORANDO POSIBLES DESAFÍOS, OPORTUNIDADES Y ESTRATEGIAS PARA NAVEGAR EN EL ENTORNO CIBERNÉTICO EN EVOLUCIÓN.

ESTE PANEL PROMETE INFORMACIÓN VALIOSA SOBRE EL ESTADO ACTUAL Y LA TRAYECTORIA FUTURA DE LA CIBERSEGURIDAD.

Boards play a vital role in overseeing the “risk barometer” for their organizations. As companies advance their digital journeys, cybersecurity has consumed more of the corporate board agenda than ever before. Many Directors are getting smarter on cyber and are asking better questions that recognize cyber as a cornerstone of digital trust.

But just as attackers change their tactics, the questions boards ask should adapt and evolve to ensure CISOs and technology leaders have the resources necessary to protect and grow the business.

Listen to the replay of a webcast from May 7, 2024 at 10:00 AM Eastern US live from RSA Conference with my McKinsey & Company colleague, Daniel Wallance, and Founder and CEO of Bishop Fox, Vinnie Liu, as we explore the latest questions boards can ask (and answers management can provide). We will share our latest research and trends from our work with boards and cyber/tech leaders blended with a heavy dose on-the-ground technical testing insights.

Read more →

We are delighted to host a special IIF event to present and discuss the IIF/McKinsey 2024 Report on Futureproofing Cybersecurity and Emerging Technology on Thursday, March 14.

This joint report explores how financial services firms around the world are currently “futureproofing” themselves to keep pace with a rapidly evolving technology landscape that presents growing cyber risks. In doing so, they must consider not only what benefits new emerging technologies offer, but what risks they have the potential to introduce.

Featured Speakers:

  • Lamont Atkins, Senior Advisor, McKinsey & Company
  • Soumya Banerjee, Associate Partner, McKinsey & Company
  • Lauren Craig, Consultant, McKinsey & Company
  • Justin Greis, Partner, McKinsey & Company

Read more →

In this episode of the IIF Global Regulatory Update Podcast, we host four McKinsey senior financial leaders – Justin Greis, Lamont Atkins, Soumya Banerjee, and Lauren Craig. All featured McKinsey speakers have vast experience and influence in the world of cybersecurity and emerging technology: Justin is a Partner leading cybersecurity work in North America within the Risk & Resilience Practice, Lamont is a Senior Advisor, Soumya is an Associate Partner, and Lauren is an engagement manager and cybersecurity expert.

The focus of the conversation revolves around findings of the joint IIF/McKinsey 2024 Report on Futureproofing Cybersecurity and Emerging Technology, titled: “The Cyber Clock is Ticking: Derisking Emerging Technologies in Financial Services.” Topics include the challenges and opportunities financial services firms face in adapting to the rapidly evolving technology landscape and the associated cybersecurity risks.

The episode delves into themes such as the changing cyber risk landscape, the benefits and risks of emerging technologies, the relevance of cloud and edge computing, the impact of generative AI and the importance of cyber risk management strategies. The group also discusses key questions for organizations to consider in enhancing their security posture. The podcast concludes with suggestions for listeners to enhance their own cyber resilience in the face of evolving technological landscapes.

The full survey report is available on both the McKinsey and IIF websites.

Listen to podcast →

Go to website →

Guest lecture and discussion covering what it takes for cyber to become a strategic capability and competitive differentiator.

Read more →

Delivered 90-minute guest lecture of Kelley School of Business MBA students discussing the current cybersecurity landscape, board-level impacts, and leading practices for cybersecurity programs.

Read more →

Two day cybersecurity event for business executives focusing on board and executive-level topics on cybersecurity.

All too often the business case for cybersecurity investment is framed ONLY as risk mitigation for the company. While investing in cybersecurity does reduce risk, that is an incomplete story; especially when it comes to business-enabling services like identity and access management (IAM).

This presentation discusses how companies are accelerating business performance by building, growing, and maturing capabilities in identity security. We share why mitigating risk is just PART of the equation when making the case for advancing your IAM-fueled cybersecurity program.

This session will focus on the latest developments around Cybersecurity and Third-Party Risk Management. IIF colleague Mary Frances Monroe (Director, Insurance Regulation and Policy) will be joined by Justin Greis and Charlie Lewis, Partners at McKinsey & Company to provide an overview of the current cyber risk threat landscape, including the impact of emerging technologies such as generative AI (ChatGPT), and what insurance companies are already doing to address these growing threats to the financial sector. There will also be a focus on the use of critical third-parties, especially cloud service providers, and how global standard-setters and key regulators are deciding how to supervise the use of critical third-parties by regulated financial institutions.

Read more →

This session will focus on the latest developments around Cybersecurity and Third-Party Risk Management. IIF colleague Martin Boer (Senior Director, Regulatory Affairs) will be joined by Justin Greis and Charlie Lewis, Partners at McKinsey & Company to provide an overview of the current cyber risk threat landscape, including the impact of emerging technologies such as generative AI (ChatGPT), and what financial firms are already doing to address these growing threats to the financial sector. There will also be a focus on the use of critical third-parties, especially cloud service providers, and how global standard-setters and key regulators are deciding how to supervise the use of critical third-parties by regulated financial institutions.

Read more →

GenAI is a topic that is now a topic that covers boardroom to dinner tables. It has generated excitement and anxiety at a global scale. As AI continues to grow in complexity and influence, and getting adopted at an unprecedent rate as no other technology, it is crucial to ensure that its deployment remains responsible, ethical, and secure. This town hall event aims to foster an open dialogue and promote global collaboration in addressing the challenges and opportunities presented by AI technology.

During the event, renowned experts in the field will share their insights and experiences, discussing the ethical considerations and potential risks associated with AI. They will delve into the importance of responsible AI practices, such as transparency, fairness, accountability, and privacy, and explore strategies for integrating these principles into AI development and implementation.

Additionally, the event will address the pressing issue of AI security, highlighting the potential vulnerabilities and threats that arise from the misuse or malicious exploitation of AI systems. Experts will shed light on the latest advancements in AI security measures, including robust safeguards, authentication mechanisms, and proactive defense strategies, to ensure the protection of individuals and organizations from AI-related risks.

This global town hall event provides a unique opportunity for participants to engage in meaningful discussions, ask questions, and share their perspectives on the responsible and secure use of AI. Attendees will gain valuable insights into best practices, learn about emerging regulations and policies, and connect with a diverse community of AI enthusiasts, practitioners, and advocates.

Whether you are an AI researcher, a policymaker, a business leader, or simply a concerned citizen, this event welcomes individuals from all backgrounds who are interested in shaping the future of AI in a responsible and secure manner.

Read more →

The new White House National Cybersecurity Strategy proposes regulations that will hold software and technology providers liable for breaches, with the end goal of making security a priority throughout product development lifecycles and shifting more responsibility to vendors. If you’re wondering what the legal and logistic ramifications to your business are, you aren’t alone.

Join Bishop Fox for a fireside chat with renowned cybersecurity experts – Evan Wolff, a highly sought-after attorney and thought leader on federal government initiatives addressing cyber issues, and Justin Greis, partner at McKinsey & Company and leader of McKinsey Digital and the Risk & Resilience Practices. We’ll address your questions and concerns and discuss how the new proposed policies will impact offensive security initiatives, both short- and long-term.

Topics will include:

  • How these regulations and regulators are shifting the way pen testing, red teaming, and other offensive security solutions should be thought of and used
  • The changing scope of software liability and modifications to existing liability frameworks and safe harbor provisions
  • How customer buying patterns (i.e., supply chain security, contractual security requirements) have changed
  • The likely role of penetration testing and red teaming in protecting technology providers

Read more →

Join us for a real-time, video-based cyber crisis war game that allows participants to engage in responding to a realistic cyber incident that impacts both information technology and operational (OT) technology assets. This session, led by one of McKinsey’s Cyber Practice leaders, brings together the theory behind crisis response with a real-life scenario representative of the type of technology used by IDFA members. Participants will play various roles and discuss a set of questions and response options as part of this “water through the pipes” exercise. At the completion of the exercise, participants will have a better understanding of the dynamic nature of cyber crises and what actions their organization could take if impacted.

Read more →

In this episode of the GRU, we host Justin Greis, a McKinsey Partner whose specialties lie in cybersecurity, the cloud, technology strategy, and digital transformation. The discussion centers around the many challenges and developments in the cyber world, including assessing the present landscape within the industry, what emerging technologies may provide to organizations, how the development of quantum computing effects organizational planning systems and best practices within an ever-emerging cyber industry.

Listen to podcast →

Go to website →

Cyber risks to companies and their customers and employees have reached unprecedented new levels. The onslaught of ransomware attacks, state-sponsored cyber intrusions, and myriad online fraud schemes is now combined with the renewed specter of politically motivated, destructive cyber-attacks on a global scale, including against critical infrastructure companies. This session will begin with a keynote and fireside chat featuring Rob Silvers, U.S. Department of Homeland Security Undersecretary for Policy and recently appointed by President Biden to head the nation’s first Cyber Safety Review Board. This will be followed by a panel of leading cyber and data privacy legal counsel from companies and law firms around the world, who will address how lawyers can drive positive changes for their clients and firms in managing emerging cyber risks.

Read more →

Read more →

We have seen an increase in cybercrimes and cyberattacks in the past year. The estimated average loss for each cyberattack is around USD 22 million and will continue to rise. It is crucial to shore up cybersecurity to protect your financial institution.

This online roundtable brought CROs together to discuss pertinent cyber security issues impacting on risk management and compliance teams.

Read more →

What should management and the board do to prepare in an environment of escalating destructive and disruptive attacks? What are the right questions to ask and what are the red flags to look out for? As cybersecurity regulations increase so too do the expectations of board members’ familiarity with cybersecurity-related concepts. This session will review cybersecurity trends, discuss the intensifying threat landscape and explore the evolving role of the board of directors in governing cybersecurity. You’ll gain valuable insights on effective cybersecurity organizations and what it takes to “futureproof” cybersecurity programs.

Read more →

Go to website →

Co-Moderated a panel of innovators, experts, and industry luminaries exploring the risks, opportunities, and emerging trends surrounding Machine Learning (ML) and Artificial Intelligence (AI).

Read more →

This session, hosted by Martin Boer (Senior Director, Regulatory Affairs, IIF) and Justin Greis (Partner, McKinsey), will focus on the current cyber risk landscape, effective cyber incident reporting and information sharing, and addressing the growing threat of ransomware. It will also include strategies to help build up cyber and operational resilience.

Read more →

Go to website →

Cyber-attacks are a growing threat to public safety and our national and economic security. In our current digital environment, every company, large or small, is now a reachable target. Today’s attackers are well-funded, highly organized, and well-trained cyber criminals, which is why all companies must invest in cybersecurity and cyber resilience.

While cybersecurity plans can help prevent a data breach or reduce the risk of malicious activity, no plan is perfect, and as cyber-attacks continue to become more sophisticated, these plans alone are no longer sufficient. Therefore, it is critical for companies to have cyber resilient strategies in conjunction with cybersecurity to mitigate the impacts of these attacks.

Read more →

Go to website →

Watch on Vimeo →

As the threat of foreign and domestic malicious cyber actors increases, there are lessons to be learned from other sectors including meat and retail. Hear how dairy can protect itself from cyber-attacks.

Read more →

Participate in an interactive, video-based cyber crisis war game that allows participants to engage in responding to a realistic cyber incident that impacts both information technology and operational (OT) technology assets. This session, led by one of McKinsey’s Cyber Practice leaders, brings together the theory behind crisis response with a real-life scenario representative of the type of technology used by IDFA members. Participants will play various roles and discuss a set of questions and response options as part of this “water through the pipes” exercise. At the completion of the exercise, participants will have a better understanding of the dynamic nature of cyber crises and what actions their organization could take if impacted.

Read more →

A webinar delivered in conjunction with Indiana University Kelley School of Business, The Kelley School of Business – Institute for Corporate Governance, Indiana University Ostrum Workshop, and the European Corporate Governance Institute (ECGI) exploring the the digital and technology trends shaping the future of cybersecurity. We also propose futureproofing recipes that companies can take today to ready themselves for the technology and digital future of tomorrow.

Read more →

Go to website →

Watch on YouTube →

Presented at the ISF North America Conference 2021

Cybersecurity programs continue to mature and evolve with the threats they seek to mitigate, but it is an ever-accelerating race to strengthen companies’ security postures in response to the increased threat landscape. With digitization now a reality, ransomware and destructive attacks a daily occurrence, and elevated customer expectations for products and services incorporating security and privacy “by design,” what should companies do to assess and address their most critical cybersecurity risks?

Simultaneously, the market for cybersecurity solutions has seen a rapid surge of new entrants to address various cybersecurity challenges. While some are niche players that focus on a narrow slice of a company’s cyber risk profile, others promise an integrated set of solutions in one convenient platform…with a price tag to match! How do Chief Information Security Officers, business leaders, and Boards strike the balance between good cybersecurity and cost-effectiveness?

In this session, we will explore some of the common themes discovered in the thousands of cyber assessments we have performed – and cyber strategies created – in recent years. While the unique root causes change from company to company, most assessments share a consistent set of themes with a common pattern of solutions to follow. We will also share observations on emerging cybersecurity solutions, start-ups, and how to evaluate new companies to cut through the noise of “silver bullet” claims and “zero breach” guarantees.

Read more →

From “brand bots” & 3D printed cars to virtual reality operating rooms & ride-sharing meal delivery apps, cloud is powering the disruptive technology that lets us to do things that weren’t possible yesterday. Today, cloud is no longer a nice-to-have; it is a business necessity capable of turning our brightest ideas into never-before-imagined products & services. Yet adoption of cloud technology is not without its challenges, in large part, due to security concerns. Are these concerns justified?

Watch on YouTube →

Presentation to the ISACA Charlotte Chapter on A risk-based approach to segregation of duties.

Read more →

Presentation at the ISACA 2011 ISACA Governance, Risk, and Compliance Conference on Information Security Governance Models.

Read more →

Presentation at the ISACA 2010 ISACA North America CACS Conference on A Risk-Based Approach to Segregation of Duties.

Read more →

awards

Winner of The Coalition of the Green Light Award, awarded to Partners who demonstrated outstanding commitment to Caring People Leadership.

Regional Finalist for EY’s Better Begins With You Program

Overall Finalist for the 2015 Association of Management Consulting Firms’ (AMCF) consulting awards in the “Internal Initiative” category for the EY Culture Recognition Program/Culture Coin Program.

Overall Winner for the most innovative program for the Culture Recognition Program/Culture Coin Program

First Place Winner in the Fortune Magazine and Rock and Roll Hall of Fame Battle of the Corporate Bands 2011.

Read more →

Global Winner of EY’s Chairman’s Values Award, the firm’s highest honor, for outstanding commitment to the firm’s values and its people.

First Place Winner at the 2009 Workshop on Information Technologies and Systems (WITS) Conference for “Best Innovation in Teaching” for cutting-edge teaching methods in the MSIS program.

Read more →

Winner of the 2007 “Outstanding Service Alumni Award” by the Indiana University, Kelley School of Business, MSIS Program for exceptional contributions and impact to the University and MSIS Program.

Contributed to, and taught in, Indiana University’s Intensive Freshman Seminar (IFS) program leading to it winning “College of the Year” in 2001.

Read more →

Recognized by Consulting Magazine as 2026 Top Consultant for profound impact on the consulting profession, acceligence, and my clients.

Read more →

personal

interests

I have quite a few interests, hobbies, and things that bring me joy. However, my greatest joys in life are my two superhero kids who both add to my ever-growing list of hobbies and passions. I’ll share more about my interests as I post to the blog. Click the boxes below to explore posts about the things that fill my overflowing cup!

kids

art

biking

#biking

books

cooking

#cooking

concerts

#concerts

drums

edc

fish

fishing

#fishing

games

harmonica

#harmonica

health

#health

hiking

#hiking

lego

music

photography

#photography

rocks

rucking

#rucking

swimming

#swimming

technology

#technology

travel

#travel

ukulele

#ukulele

writing

#writing

kids

art

biking

#biking

books

cooking

#cooking

concerts

#concerts

drums

edc

fish

fishing

#fishing

games

harmonica

#harmonica

health

#health

hiking

#hiking

lego

music

photography

#photography

rocks

rucking

#rucking

swimming

#swimming

technology

#technology

travel

#travel

ukulele

#ukulele

writing

#writing

perfessional

boards

trustee

Ravinia Festival

Board of Trustees

October 2022 – Present

Highland Park, Illinois

  • Chair, Audit & Risk Committee

  • Executive Committee Member

  • Past: DE&I and Facilities Committee

council member

Kelley School of Business

Dean’s Council

April 2023 – Present

Bloomington, Indiana

  • Bloomington Dean’s Council Member

  • Co-Chair, Dean’s AI Roundtable

  • Provide strategic advisory and advocacy

trustee

Merit School of Music

Board of Trustees

August 1999 – June 2002

Chicago, Illinois

  • Member of the Board of Trustees

  • Chair, Technology Committee

  • Oversaw technology transformation efforts