About
I bring your cybersecurity and threat exposure into the light, so you can gain the needed support from the board, management, regulators and others to fund needed protections.
Like a capable physician, I first understand where it hurts, how long this has been happening, and things you've tried yourself. Then, you'll hear me say "let's run some tests". NIST. MITRE ATT&CK. Benchmarking against others in your industry. Applying actual event patterns and probabilities. And insurance-grade analysis. This allows us to answer the three key questions:
1.) How much cybersecurity risk do I actually have?
2.) Where is most of it coming from (root causes)?
3.) What is it costing me?
Once we know, we can sit down and craft the next steps to get things to a better place. No nonsense. Data-driven. Objective. Regulator-approved.
Many clients ask: "I know we're spending more on cybersecurity, but what are we actually getting?". This analysis is essential to not only cyber, but any properly-run function in the business. Cybersecurity is not a mystery-land that somehow is the one and only function of the entire enterprise that just can't be measured, cant't be quantified, and can't be transparent. Let me bring you the answers, and get on a better track to improvement and protection now.
A four-year US Air Force veteran with Secret clearance, David is an expert information security and executive-level technology professional with a 20+ year portfolio of some of the most ground-breaking and high-value project results in information security, technology, privacy, asset management, IT risk management and infrastructure.
For more than a decade he has been privileged to serve and consult to some of the world's most respected organizations in the United States, Latin America, and Europe. His writing includes examining the measurable value of technology-based capability and its role in risk mitigation in the 2011 book “Webify” (https://www.amazon.com/Webify-Interconnections-Strategy-Capability-Volatility-ebook/dp/B006RX4PXM). He has served on the board of a public investment trust and as a member of the senior executive committee of a $5bn Nasdaq company.
Services
Articles by R David
Activity
12K followers
Experience
Education
-
The University of Chicago - Booth School of Business
-
-
Activities and Societies: Appointed Leader - Czech Republic Market Economy Transition Team
-
-
-
-
-
-
-
-
-
-
-
Licenses & Certifications
-
Polsky Founders' Circle
Polsky Center for Entrepreneurship and Harry L. Davis Center for Leadership, University of Chicago
Issued -
-
Project Management Professional (PMP)
Project Management Institute (PMI)
Volunteer Experience
-
Architect & Builder
Il Pastor Community Health Clinic, Agua Prieta, Sonora, Mexico
- 3 years 8 months
Poverty Alleviation
Fundraising, design and build of community health clinic, well baby center and daycare facility
Publications
-
Webify: Interconnections of Strategy and Capability in an era of Risk and Volatility
Coyne Press
See publicationKnowing the new challenges of the 21st Century, and the transformation it will continue to bring across society,business, finance, careers and investments, how do we each adjust, and how do we get ourselves in alignment with this emerging and volatile external world?
We examine these issues with a fresh perspective. In a world of volatility, we are all subject to massive shifts in currencies, commodities, career dislocation and investment risk from all directions. More than ever, this…Knowing the new challenges of the 21st Century, and the transformation it will continue to bring across society,business, finance, careers and investments, how do we each adjust, and how do we get ourselves in alignment with this emerging and volatile external world?
We examine these issues with a fresh perspective. In a world of volatility, we are all subject to massive shifts in currencies, commodities, career dislocation and investment risk from all directions. More than ever, this requires a comprehensive reorientation of our approach as managers, career professionals and investors. Webify: examines the new roles of strategy, capability and management, identifying durable practices and trends from a 21st Century perspective.
Projects
-
Grant Thornton International (Chicago, IL, 2012–2014)
-
See projectAccomplishment: $160mm/yr in
shared services operating net savings identified through benchmarked technology consolidation
strategy. Design, planning, budgeting, business model and 5-year deployment roadmap for
greenfield hosted, cloud and dedicated data centers, networks, security and support for 78,000
employee firm across 120 countries -
Grant Thornton International (Chicago, IL, 2012–2014)
-
Accomplishment: $160mm/yr. in shared services operating net savings identified through benchmarked technology consolidation strategy. Design, planning, budgeting, business model and 5-year deployment roadmap for greenfield hosted, cloud and dedicated data centers, networks, security and support for 78,000 employee firm across 120 countries. $1.8mm project (Phase 1); team of 8.
-
Mesirow Financial (Chicago, IL, 2012–2014)
-
Accomplishment: $45mm/yr IT operation
transformed to re-architected and re-organized basis for $11mm in annual savings. Assessment
of enterprise-wide information technology:data, storage, applications, processes, support, financials,
and organization. Development of comprehensive IT re-engineering roadmap addressing
SOA capabilities, data governance, shared services and IT value enhancement. Review of strategic
alignment, cloud solutions, SAN architecture, data hosting options…Accomplishment: $45mm/yr IT operation
transformed to re-architected and re-organized basis for $11mm in annual savings. Assessment
of enterprise-wide information technology:data, storage, applications, processes, support, financials,
and organization. Development of comprehensive IT re-engineering roadmap addressing
SOA capabilities, data governance, shared services and IT value enhancement. Review of strategic
alignment, cloud solutions, SAN architecture, data hosting options, platform consolidation
strategy, vendor contracts and governance practices. Presentation of findings and recommendations
to group CEO, CFO and CIO resulting in approval and funding of comprehensive IT
restructuring program.Other creatorsSee project -
Colony Capital, Los Angeles, CA (2003–2004)
-
Accomplishment: General management of $380mm acquisition of worlds 8th largest hotel from Caesars Entertainment. Complete reconstruction of corporate networks, IT organization, security, data center, and applications for 4,000 employee operation in six months from signing of acquisition. Served as contract CIO; built and managed program management office operating 11 major projects across 214 vendors in coordination with City of Las Vegas, Caesars Entertainment, Deloitte, Nevada Gaming…
Accomplishment: General management of $380mm acquisition of worlds 8th largest hotel from Caesars Entertainment. Complete reconstruction of corporate networks, IT organization, security, data center, and applications for 4,000 employee operation in six months from signing of acquisition. Served as contract CIO; built and managed program management office operating 11 major projects across 214 vendors in coordination with City of Las Vegas, Caesars Entertainment, Deloitte, Nevada Gaming Commission, Las Vegas Convention Center and four labor unions. $49mm program across 11 projects; team of 45.
-
Cosmopolitan Resort Casino, Las Vegas, NV (2006–2008
-
Accomplishment: Technology strategy and infrastructure development for $4bn entertainment group as contract CIO, including requirements analysis, systems design, Web 2.0 strategy, data center build-out, mobility, business continuity, content management, and IT value assessment across 48 business-critical technology systems. $64mm program across 17 projects; team of 23.
-
Mesirow Financial (Chicago, IL, 2012–2014)
-
Accomplishment: Enterprise CISO. Cybersecurity operation transformed to re-architected and re-organized basis for $11mm in annual savings. Led teams up to 43. Assessment of enterprise-wide information technology: data, storage, applications, processes, support, financials, and organization. Development of comprehensive re-engineering roadmap addressing new capabilities, data governance, shared services and value enhancement. Coordination and data gathering across BoD, all senior Partners and…
Accomplishment: Enterprise CISO. Cybersecurity operation transformed to re-architected and re-organized basis for $11mm in annual savings. Led teams up to 43. Assessment of enterprise-wide information technology: data, storage, applications, processes, support, financials, and organization. Development of comprehensive re-engineering roadmap addressing new capabilities, data governance, shared services and value enhancement. Coordination and data gathering across BoD, all senior Partners and executives, hedge fund operations, insurance, wealth management, and PE operations. Review of strategic alignment, platform consolidation strategy, vendor contracts and governance practices. Presentation of findings and recommendations to group CEO, CFO and CIO resulting in approval and funding of comprehensive IT restructuring program. Named CISO in January 2013. $6.9mm in overall project accountability.
-
PIMCO (Newport Beach, CA, 2012)
-
Accomplishment: $12mm in compliance cost reduction in SEC-regulated compliance filing and compliance document management system. Enterprise legal data compliance initiative, satisfying legal processes related to SEC filings and other regulatory agency requirements. Project included data architecture, document classification, secure access provisions, and electronic signature management. $3.8mm project; team of 11.
-
Southern California Edison (Rosemead, CA, 2011–2012)
-
Accomplishment: $33mm/yr mitigation in risk and litigation exposure, personally leading deployment of legal case management and content management system. Development of legal content data management system, including digital transformation and content management for largest electrical utility in the US. $16mm project; team of 35.
Languages
-
English
-
-
German
-
Organizations
-
(ISC)2
-
- Present -
Association for Computing Machinery
-
- Present
Recommendations received
2 people have recommended R David
Join now to viewOther similar profiles
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content