R David Moon, CISSP

R David Moon, CISSP

Greater Chicago Area
12K followers 500+ connections

About

I bring your cybersecurity and threat exposure into the light, so you can gain the needed support from the board, management, regulators and others to fund needed protections.

Like a capable physician, I first understand where it hurts, how long this has been happening, and things you've tried yourself. Then, you'll hear me say "let's run some tests". NIST. MITRE ATT&CK. Benchmarking against others in your industry. Applying actual event patterns and probabilities. And insurance-grade analysis. This allows us to answer the three key questions:

1.) How much cybersecurity risk do I actually have?
2.) Where is most of it coming from (root causes)?
3.) What is it costing me?

Once we know, we can sit down and craft the next steps to get things to a better place. No nonsense. Data-driven. Objective. Regulator-approved.

Many clients ask: "I know we're spending more on cybersecurity, but what are we actually getting?". This analysis is essential to not only cyber, but any properly-run function in the business. Cybersecurity is not a mystery-land that somehow is the one and only function of the entire enterprise that just can't be measured, cant't be quantified, and can't be transparent. Let me bring you the answers, and get on a better track to improvement and protection now.

A four-year US Air Force veteran with Secret clearance, David is an expert information security and executive-level technology professional with a 20+ year portfolio of some of the most ground-breaking and high-value project results in information security, technology, privacy, asset management, IT risk management and infrastructure.

For more than a decade he has been privileged to serve and consult to some of the world's most respected organizations in the United States, Latin America, and Europe. His writing includes examining the measurable value of technology-based capability and its role in risk mitigation in the 2011 book “Webify” (https://www.amazon.com/Webify-Interconnections-Strategy-Capability-Volatility-ebook/dp/B006RX4PXM). He has served on the board of a public investment trust and as a member of the senior executive committee of a $5bn Nasdaq company.

Services

Articles by R David

Activity

12K followers

See all activities

Experience

Education

Licenses & Certifications

Volunteer Experience

  • Architect & Builder

    Il Pastor Community Health Clinic, Agua Prieta, Sonora, Mexico

    - 3 years 8 months

    Poverty Alleviation

    Fundraising, design and build of community health clinic, well baby center and daycare facility

Publications

  • Webify: Interconnections of Strategy and Capability in an era of Risk and Volatility

    Coyne Press

    Knowing the new challenges of the 21st Century, and the transformation it will continue to bring across society,business, finance, careers and investments, how do we each adjust, and how do we get ourselves in alignment with this emerging and volatile external world?

    We examine these issues with a fresh perspective. In a world of volatility, we are all subject to massive shifts in currencies, commodities, career dislocation and investment risk from all directions. More than ever, this…

    Knowing the new challenges of the 21st Century, and the transformation it will continue to bring across society,business, finance, careers and investments, how do we each adjust, and how do we get ourselves in alignment with this emerging and volatile external world?

    We examine these issues with a fresh perspective. In a world of volatility, we are all subject to massive shifts in currencies, commodities, career dislocation and investment risk from all directions. More than ever, this requires a comprehensive reorientation of our approach as managers, career professionals and investors. Webify: examines the new roles of strategy, capability and management, identifying durable practices and trends from a 21st Century perspective.

    See publication

Projects

  • Grant Thornton International (Chicago, IL, 2012–2014)

    -

    Accomplishment: $160mm/yr in
    shared services operating net savings identified through benchmarked technology consolidation
    strategy. Design, planning, budgeting, business model and 5-year deployment roadmap for
    greenfield hosted, cloud and dedicated data centers, networks, security and support for 78,000
    employee firm across 120 countries

    See project
  • Grant Thornton International (Chicago, IL, 2012–2014)

    -

    Accomplishment: $160mm/yr. in shared services operating net savings identified through benchmarked technology consolidation strategy. Design, planning, budgeting, business model and 5-year deployment roadmap for greenfield hosted, cloud and dedicated data centers, networks, security and support for 78,000 employee firm across 120 countries. $1.8mm project (Phase 1); team of 8.

  • Mesirow Financial (Chicago, IL, 2012–2014)

    -

    Accomplishment: $45mm/yr IT operation
    transformed to re-architected and re-organized basis for $11mm in annual savings. Assessment
    of enterprise-wide information technology:data, storage, applications, processes, support, financials,
    and organization. Development of comprehensive IT re-engineering roadmap addressing
    SOA capabilities, data governance, shared services and IT value enhancement. Review of strategic
    alignment, cloud solutions, SAN architecture, data hosting options…

    Accomplishment: $45mm/yr IT operation
    transformed to re-architected and re-organized basis for $11mm in annual savings. Assessment
    of enterprise-wide information technology:data, storage, applications, processes, support, financials,
    and organization. Development of comprehensive IT re-engineering roadmap addressing
    SOA capabilities, data governance, shared services and IT value enhancement. Review of strategic
    alignment, cloud solutions, SAN architecture, data hosting options, platform consolidation
    strategy, vendor contracts and governance practices. Presentation of findings and recommendations
    to group CEO, CFO and CIO resulting in approval and funding of comprehensive IT
    restructuring program.

    Other creators
    See project
  • Colony Capital, Los Angeles, CA (2003–2004)

    -

    Accomplishment: General management of $380mm acquisition of worlds 8th largest hotel from Caesars Entertainment. Complete reconstruction of corporate networks, IT organization, security, data center, and applications for 4,000 employee operation in six months from signing of acquisition. Served as contract CIO; built and managed program management office operating 11 major projects across 214 vendors in coordination with City of Las Vegas, Caesars Entertainment, Deloitte, Nevada Gaming…

    Accomplishment: General management of $380mm acquisition of worlds 8th largest hotel from Caesars Entertainment. Complete reconstruction of corporate networks, IT organization, security, data center, and applications for 4,000 employee operation in six months from signing of acquisition. Served as contract CIO; built and managed program management office operating 11 major projects across 214 vendors in coordination with City of Las Vegas, Caesars Entertainment, Deloitte, Nevada Gaming Commission, Las Vegas Convention Center and four labor unions. $49mm program across 11 projects; team of 45.

  • Cosmopolitan Resort Casino, Las Vegas, NV (2006–2008

    -

    Accomplishment: Technology strategy and infrastructure development for $4bn entertainment group as contract CIO, including requirements analysis, systems design, Web 2.0 strategy, data center build-out, mobility, business continuity, content management, and IT value assessment across 48 business-critical technology systems. $64mm program across 17 projects; team of 23.

  • Mesirow Financial (Chicago, IL, 2012–2014)

    -

    Accomplishment: Enterprise CISO. Cybersecurity operation transformed to re-architected and re-organized basis for $11mm in annual savings. Led teams up to 43. Assessment of enterprise-wide information technology: data, storage, applications, processes, support, financials, and organization. Development of comprehensive re-engineering roadmap addressing new capabilities, data governance, shared services and value enhancement. Coordination and data gathering across BoD, all senior Partners and…

    Accomplishment: Enterprise CISO. Cybersecurity operation transformed to re-architected and re-organized basis for $11mm in annual savings. Led teams up to 43. Assessment of enterprise-wide information technology: data, storage, applications, processes, support, financials, and organization. Development of comprehensive re-engineering roadmap addressing new capabilities, data governance, shared services and value enhancement. Coordination and data gathering across BoD, all senior Partners and executives, hedge fund operations, insurance, wealth management, and PE operations. Review of strategic alignment, platform consolidation strategy, vendor contracts and governance practices. Presentation of findings and recommendations to group CEO, CFO and CIO resulting in approval and funding of comprehensive IT restructuring program. Named CISO in January 2013. $6.9mm in overall project accountability.

  • PIMCO (Newport Beach, CA, 2012)

    -

    Accomplishment: $12mm in compliance cost reduction in SEC-regulated compliance filing and compliance document management system. Enterprise legal data compliance initiative, satisfying legal processes related to SEC filings and other regulatory agency requirements. Project included data architecture, document classification, secure access provisions, and electronic signature management. $3.8mm project; team of 11.

  • Southern California Edison (Rosemead, CA, 2011–2012)

    -

    Accomplishment: $33mm/yr mitigation in risk and litigation exposure, personally leading deployment of legal case management and content management system. Development of legal content data management system, including digital transformation and content management for largest electrical utility in the US. $16mm project; team of 35.

Languages

  • English

    -

  • German

    -

Organizations

  • (ISC)2

    -

    - Present
  • Association for Computing Machinery

    -

    - Present

Recommendations received

View R David’s full profile

  • See who you know in common
  • Get introduced
  • Contact R David directly
Join to view full profile

Other similar profiles

Explore top content on LinkedIn

Find curated posts and insights for relevant topics all in one place.

View top content

Add new skills with these courses