Gary Cyganek, CISSP. ***********@*****.*** 214-***-**** mobile. US Citizen.
Hands-on Sr Security Specialist/virtual Chief Information Security Officer (vCISO)/Director, Information Security, Governance, Risk, Compliance (GRC). Transformational, Visionary, Global Security Advisor: “Proven in Production”, “Missing in Market “:
Client, Custom, Deliverables: Security Risk Management/Third Party Vendor Risk Management including:
Global client custom Security management program.
Cyber Security Governance, Risk, Compliance (GRC) program.
Successful Security: Infrastructure/Architecture/Applications/Networks/Data/End-Points/etc.
Initial Development, Management: Leads, defines, maintains:
Work with peers, executive stakeholders, IT, team members, etc.
Expert: Custom client Security Vision/Strategy/Policy/Architecture/Infrastructure, etc aligned to client custom Business/Priorities for client buy-in.
Federal/Government/Financial/Technology/Digital/Transformation/Fortune 500: Security/
Privacy/Risk Maturity Assessments in line with client Business, Goals, timelines, budget, etc.
oDevelopment, implementation, execution client custom Security Program.
oSecurity Advisor: Custom client security needs, problems and corresponding client solutions.
oExperience developing, interpreting, installing, etc custom client security strategies, policies and procedures.
ointerprets guidelines, issues on process, methods, procedures, etc for security initiatives.
oSupports the information security program for protection of national security information.
oExpert Knowledge: current plus “missing in market” security concepts involving wide range security issues and emerging threats, risks, vulnerabilities, etc.
oAbility to manage a wide range of security programs.
oOversight: proper data classification, labeling, handling classified information.
oProvides briefings, trainings, mentoring.
oInvestigates security incidents and applies custom client security solutions.
oWorks with the external Security entities (including serving as a point of contact-- on physical security infrastructure, equipment, and systems, plus personnel security), etc.
oSupports the Emergency Management Program (Federal/Non-Federal) (i.e. including key emergency response roles, assisting with the development and maintenance client custom Business Continuity (BC) and Disaster Recovery (DR) Plans).
Missing: Develop, translate client Business Needs into client Security/Privacy/Risk/GRC model
Enable risk-based decision making and “Predictive Security” prevention techniques.
Expert: client Maturity Assessments (see above):
oAssess/Strengthen client custom Current/Target needs.
oOversight: Critical Information Security areas.
oInitial Development: (Digital Transformation Security): New security (new core process).
oManagement Oversight: All short-term/long-term Security/Privacy/Risk solutions.
oIdentify Security gaps plus client custom resolution.
oUsing “Predictive Security”, avoid future Security/Privacy/Risk liability.
oDevelop different options: client custom “Acceptable Level of Risk”.
oArticulate Cybersecurity Impact on client business. Ability to predict/respond swifty.
Security/Privacy/Risk presentations, planning to Board.
oPresent current/target client security posture status/cost to Board based upon Return on Investment (ROI).
oSet direction for strategic business and technology challenges.
Missing: Successful Return on Investment (ROI) discussion: with client Board, C-Level, Business, stakeholders, Sr Management, etc.
Missing: Reduce Security, Risk expenses. Improve level of Security, Privacy, Risk productivity.
Missing: Implement Successful client Return on Investment (ROI) per client cost center.
Missing: High Priority: Transform Client Security from Cost Center to Profit Center.
Missing: High Priority: Security, Privacy, Risk as enablers to increase client Business Value, Worth
Missing: Federal/Government: Security/Privacy/Risk: Daily Gaps/Custom client Solutions: “Missing in Market”, “Proven in Production”:
oSecurity Obligations/Hybrid Work
oCyber Security Interruptions
Ransomware
Client organization-wide cybersecurity policy and review contracts.
oThird Party Vendor Management: Annual vendor risk assessment.
oReview/Secure: Current/Target: Minimum standards: Application Security: client internal Software Development Lifecycle (SDLC).
Leads: client Information Security: foundation, approach, architecture, networks, end-points, etc aligned with client Business/Risk management.
Metrics: Key Security operational metrics from service and financial area via:
oUnique: Cybersecurity Metrics (Measure how well client is achieving Client’s Target Cyber Security Risk Reduction and Information Security goals).
oSuccessful Return on Investment (ROI) per client cost center.
Define, Lead, help client adopt transformational change (i.e., Digital Transformation Security) within Business/Technology aligned with client, custom Security/Privacy/Risk foundation.
oManage Security/Privacy/Risk within Functional/Business/Technical level.
oTechnology/Security planning for Business Stakeholders, Board, IT, stakeholders, etc.
oComplex problem solving for business.
Expert: Information Security, Governance, Risk, Compliance (GRC); Privacy.
Expert: client, custom Security: frameworks, infrastructure, certification requirements. (See Skills Summary).
(See Digital Transformation/Federal/Government/Healthcare/Financial/Technology/Fortune 500 client Assessments: Security Problems/Security Recommendations/Security Solutions).
Security Subject Matter Expert: Proactive Cyber Defense: Reduce Client Attack Surface via “Predictive Security” approach. (i.e. See Prevention/Security Solutions for Ransomware).
Digital Transformation Phases: Develop client Business, Security definitions/support. (See Value): I. Phase 1: Digitization (transitioning from analog or manual process to digital data). II. Phase 2: Digitalization (processing, analyzing digital data). III. Phase 3: Digital transformation (building on digitalization to optimize client target business).
CERTIFICATIONS:
CISSP certification (Since 2004) (Gold Standard IT Security certification) (Re-certified 1 year ahead of schedule--- each 3 year certification cycle since 2004).
Skills Summary: Deliverables:
25+ yrs Hands-on Cloud/Non-Cloud: Security Thought Leader/Chief Security Architect
I.Design, implement, maintain: Governance, Risk and Compliance (GRC) framework.
II.Security Best practices: Expert Knowledge: Custom Client Federal/Government/Insurance
/Healthcare/Security/ Privacy/Risk/Technology/Digital/Digital Transformation/Fortune 500 Assessments via:
NIST Cyber Security Framework (CSF), NIST (National Institute of Standards and Technology) 800 publications, NIST 800-53r4 (Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans), NIST 800-39 Under Cyberspace, NIST Special Publication 800-171(Protecting Controlled Unclassified Information in Non-federal Information Systems and Organizations)
PCI (Payment Card Industry) (large enterprises), ISO 27001 (Information Security Management System), ISO 27002 (Code of Practice Security Controls), ISO 27018 (Code of Practice for Protecting Personal Data in the Cloud), ISO 27701 (Privacy Information Management standard), ISO 23001 (Business Continuity Planning), SOX (Sarbanes Oxley Act), SOC (Service Organization Controls), FFIEC (Federal Financial Institution), FDIC (Federal Deposit Insurance Corporation), OWASP Top 10, SANS Top 20, SOC 2 (standard: Cloud Based Service Provider protects Sensitive Information), EU General Data Protection Regulation (GDPR), CCPA (California Consumer Privacy Act), California Privacy Rights Act (CPRA): (Effective: 1/1/23) (alters criteria "for-profit" businesses by defining it to include at least 100,000 consumers or households).GLBA (Financial Modernization Act), NYDFS (New York Department of Financial Service), NAIC (National Association of Insurance Commissioners), DevOps, Agile, COBIT.
HIPAA (Health Insurance Portability and Accountability Act/Security Rule/Privacy Rule), HITRUST (Health Information Trust Alliance), Governance Risk Compliance (GRC), confidentiality, integrity, availability Electronic Protected Health Information (EPHI), Software as a Service (SaaS), Cloud Security Alliance (CSA), Cloud Controls Matrix (CCM), Internet of Things (IoT).
15 yrs Sr Security Specialist/Sr Security Architect/Digital Disruption, Digital Transformation Security, Digital Infrastructure Security/Cyber Security posture. Federal/Government/Insurance/Healthcare/ Technology/Fortune 500: Security/Privacy/Risk Assessments/Solutions.
15 yrs Senior Security Software Developer Federal/Government/Healthcare/Digital/Technology: (Applications/Systems).
11 yrs Hands-on CISO/virtual CISO (vCISO)/Sr Director, Information Security Governance, Risk, Compliance (GRC).
25 yrs Security Subject Matter Expert (SSME), Security Assessments, Chief Security Architect. 25 yrs Information Security Risk Management program/Security Foundation initial development, maintenance.
5 yrs Proprietary Security Tools (In-House: my hands-on created client customized tools) No-Public.
5+ yrs Systems Programmer (Support: Applications/Systems).
Value: Proven in Production. Missing from Market: CISO: Initial Development: Problem/Priority: #1: Understand huge difference between “Proven in Production” versus “Proven in Production”, “Missing in Market”.
#2: NIST Cyber Security Framework (CSF) became available: 2015. Since 2003, (12 years prior to 2015): Hands-on experience: Building Information/Cyber Security foundations with deeper 2003 version, NIST CSF, which is “Proven in Production”, “Missing in Market”:
#3: Security Experts now say: In order to stay competitive, following verticals (Federal/Government/
Financial/Insurance/Healthcare/Digital, Digital Transformation/Technology, Fortune 500) required to “Re-Think” their core business processes regularly to remain competitive. As a result of Re-Thinking their core business processes, traditional Security/Privacy/Risk foundations per client asset in these industries has changed and now original client Security/Privacy/Risk foundations and design no longer works.
Solution: Re-think not necessary. To save client needless wasted time, effort, resources, capital, human error, etc due to my 12 years at client site, Federal/Government/Financial/Insurance/
Healthcare/Business/Technology/Security/Privacy/Risk/Digital/Transformation/Technology/Fortune 500: client Maturity Assessments, I have “Proven in Production”, “Missing from Market”, experience, initial development, custom building client Information Security/Cyber Security/Cloud Security/Privacy/Risk foundations, approach, infrastructure, etc.
(See Digital Transformation/Federal/Government/Healthcare/Financial/Technology/Fortune 500 client: Security/ Privacy/Risk Assessments: Problems/Security Recommendations/Security Solutions).
My custom client solutions (Client Deliverables) can be Independently Verified regularly via following items “Missing from Market”, “Proven in Production”:
I.See successful Client Deliverables: (Page#1 thru Page#5), (Ransomware). (See Value), (Security Recommendations).
II.Business Budget: Transforming Security from Cost center to Profit center.
III.Business Alignment: client target Business Model aligned with client target Security/Privacy/ Risk foundation, architecture, approach, infrastructure, defense, etc.
IV.Increase in global client Business Value via Security, Privacy, Risk.
V.Oversight: Business Support: Definition: Digital Transformation phases (See page 2).
VI.Transforming client Non-Working Security/Privacy/Risk approach, foundation, Business Continuity planning (BCP), Disaster Recovery (DR), etc to successful.
VII.Develop, execute Security, Privacy, Risk strategies global Governance, Risk, Compliance (GRC).
VIII.Business Budget: reduce client global GRC, Organization, Tool, Process, Operating expenses. Successful Return on Investment (ROI) per client cost center.
IX.Verify, continuous, on-going, increasingly efficient, productive, Security/Privacy/Risk model.
PROFESSIONAL EXPERIENCE:
Integracion Technologies, Plano, TX May 2018 to Present Managed Systems Security Provider (MSSP)
Hands-on Security Specialist/virtual Chief Information Security Officer (vCISO)/Director, Information Security, Governance, Risk, Compliance (GRC). Work, collaborating with, stakeholders, C-Level management, IT, Business Executives, non-technical, etc to custom client define, develop, implement, maintain:
Digital Transformation/Federal/Government/Healthcare/Financial/Technology/Fortune 500 client: Security/ Privacy/Risk Assessments: Security Problems/Security Recommendations/Security Solutions):
Security Subject Matter Expert (SSME): Client Deliverables: I. Implement, maintain, regular client Security/Privacy/Risk: Maturity Assessments:
II. Review: client Target Foundation/Approach versus Current Client Security/Privacy/Risk posture: III. Identify, solve gaps in cyber security: strategy, policy, processes, procedures, architecture, etc to reduce organizational risk and prevent security gaps, failures, problems, concerns, etc.
Review/Secure current/target client internal Software Development Lifecycle (SDLC).
Client: Cyber Security/Cloud Security Problems:
Problem#0: Security Obligations not defined and not satisfied.
Problem#1: Increased client attack surface: caused by remote workforces, Digital Transformation, below gaps. The client’s surface area expanded to include any end-point device connecting to client network. Problem#2: Digital Transformation Security failing: 100% existing Security changed. New Security needed
Problem#3: Traditional tools not identifying Security problem source. Problem#4: Custom client Business alignment to client Security/Privacy/Risk not understood. Daily gaps.
Problem#5: Cyber Security Interruptions.
Client organization-wide cyber security strategy/policy review. Review contracts.
Ransomware. (See Security Recommendations).
Problem#6: End to End Security failing. (i.e. Email Security, Intellectual Property theft, etc).
Problem#7: Automated Security/Risk and GRC failing. Result: Security/Privacy/Risk gaps created daily.
Problem#8: Missing Minimum standards: Application Design/Application Security/Testing, etc.
Problem#9: Security Policy not enforced or failing.
Problem#10: Business Continuity/Disaster Recovery failing all applications. Not understood.
Problem#11: Expanded Attack Surface growing. Problem/Solution not understood.
Problem#12: Unauthorized access to sensitive or confidential information (i.e., unauthorized devices).
Problem#13: Third-party Security (Data Sharing) missing from third-party risk/vendor risk management.
My custom Software as a Service (SaaS) client security solutions exceed normal SaaS security definition.
Problem#14: Software as a Service (SaaS) Applications: Risky: #1: SaaS platforms have evolved, but most security tools have not. #2: All access points Not Secured: i.e., Application Programming Interfaces (APIs), third-party connections, external user portals are not visible by Security teams. #2a: SaaS is constantly changing environment and Pen testing is one time, snap shot, and ineffective.
#2b: SaaS subject to misconfiguration/configuration drift. Uncover SaaS sprawl. #2c: As SaaS third-party apps increase, more chance to increase, expand the risk/attack surface.
Problem#15: Cloud Security Problems (i.e. SaaS): #1: Visibility: Lack cloud visibility causes gaps, security failures. (i.e., Shadow IT, cloud operations). #2: Unauthorized Access: Due to digital transformation/remote work, Security Attack Surface expanded. #3: Data Security: No direct control over client data. (Managed by Cloud Service Provider (CSP)). Problem#16: Unsecured Applications/Networks/Endpoints/Web (Internet, Mobile). Unsecured: Data. Problem#17: New Automation Technology: Missing Security. (Artificial Intelligence/Machine Learning). Problem#18: Identity Theft. (No universal unique Digital Identity). (Cloud/Non-Cloud).
VI. Security Recommendations: Client: Deliverables: “Proven in Production”, “Not Found in Market”:
Item#1: (Before Ransomware attack): Real Estate gaps: Missing Ransomware Prevention: Fix#1: Apply my Ransomware custom client: “Proven in Production” Prevention Approach, Foundation. Ransomware Fix#1: See Value. Train Security Ops new procedures pre-Ransomware attack prevention. Ransomware Fix#2: Based on Ransomware Fix#1, reduce pre-Ransomware Vulnerability gaps. (Predictive Security). Fix#2: Updated minimum Application Design/Application Security/Data Security/Architecture standards. Fix#3: Verify Business Continuity/Disaster Recovery plan works per client application.
Item#2: (After Ransomware Attack): Ransomware: Violations: Real Estate: Malware encrypted data found. Pay-or-Get-Breached: Analysis: Immediate Steps: Step#1: Client doesn’t pay attacker. Isolate each problem source. Step#2: After Ransomware cause(s) re-created, isolated: To restore normal state, successfully perform my “Proven in Production”, “Missing in Market”, plan (per infected application, system, data, device, endpoint, etc).
Security Recommendations/Solutions: See Client Deliverables: (Page 1, Page 2), (Ransomware), (See Value).
Look forward to discussing further all “Missing, Not Found in Market “custom, client solutions any Security/Privacy/Risk problem.
Fortify Experts: Houston, TX Jan 2014 - May 2018
Sr Security Specialist/virtual CISO (vCISO)/Director, Information Security, Governance, Risk, Compliance.
See all client deliverables Integracion Technologies.
Previous Experience: Available Upon Request.
Education Northern Illinois University (Graduate School Computer Science) (DeKalb, Illinois). (50% complete: Promoted to: Software Developer, Out of State). Equivalent: Undergrad major completed: Computer Science: Software Developer).
Indiana State University—Undergraduate B.A. (Terre Haute, Indiana).