
Welcome back! Also, a few thoughts on that AI governance thing everybody's talking about.
It's been a minute since I had a website up, but I'm back — with a few thoughts on AI governance that didn't make the podcast cut.
ReadYour human in the loop — helping organizations reduce cyber risk and increase cyber resilience by empowering people to make better security decisions.

Custom awareness programs that go beyond compliance checkboxes. Behaviorally-grounded content, tabletop-inspired scenarios, and briefings that make security feel like stewardship — not surveillance.
NIST CSF, NIST 800-53, CIS Controls, ISO/IEC 27001 alignment reviews. Control gap analysis, risk registers, and remediation roadmaps written for humans, not auditors.
Design and facilitation of incident response tabletops using the PICERL framework. Actionable post-exercise reports that surface control deficiencies and audit-ready remediation paths.
Talks on human-centric security, GRC as culture, AI ethics for non-technical leaders, and building continuous awareness programs. Simply Cyber Con speaker (2023, 2024, 2025).
Three-time Simply Cyber Con speaker, ministerial teacher, GRC evangelist. I translate complex risk into decisions your people can act on.
View all talksLeveraging the Weekly News Brief to build a strong security awareness culture. Operationalizing threat intelligence into repeatable risk communication.
Educating ministerial staff on AI capabilities, emerging risks, and ethical decision-making frameworks. Introducing governance concepts to non-technical leaders.
Stay ready so you don't have to get ready. Design and execution of incident response tabletop exercises for readiness, control validation, and gap identification.

It's been a minute since I had a website up, but I'm back — with a few thoughts on AI governance that didn't make the podcast cut.
Read