03
jbrennan:~$ cat /domains/03-risk

Risk & Resilience

The Decisions That Keep the Organization Running

Risk becomes an executive problem when it threatens care, payroll, trust, or the institution's ability to operate. I have carried the combined CIO and CISO accountability, built the programs, led the response, and answered regulators after the incident.

CHAPTER No. 3
Risk & Resilience
THE ACCOUNTABILITYSELECTED WORKNEXT CHAPTER
THE ACCOUNTABILITY
2022 – NOW Stronger Communities NYCIO & CISO · accountable for security, resilience, continuity, trust, and regulatory readiness across two highly regulated human-services agencies25 operating locations · more than 1,100 employees · nearly $115 million in annual operations · programs serving approximately 11,000 New York families
2021 – NOW Oculus ITConsultant CISO & Lead Auditor within a cybersecurity consultancy serving multiple higher-education clients concurrentlyExecutive risk assessments · penetration-testing programs · vendor reviews · GLBA board reporting · AI-security education
2016 – 2022 Hudson Valley Community CollegeChief Information Officer & Chief Information Security Officer · built the college's comprehensive information-security programRisk, compliance, operational resilience, and disaster recovery joined across a $122 million institution, including an Epic EHR clinical environment
2010 – 2016 SUNY DelhiCIO, with CISO accountability · built the information-security and compliance program from the ground upEstablished the first internal phishing-testing program in the SUNY system

CISSP since 2018. Framework fluency earned the hard way: HIPAA, HITECH, FERPA, GLBA, SOC 2, ISO 27001, PCI DSS, CMMC, NIST CSF.

SELECTED WORK
01Service restored in two days, regulators satisfied

Ransomware hit in 2022. Restoring operations within two days meant staff could return to child and family services instead of waiting on technology. I then led the remediation across data ownership, continuity, recovery, and incident response. The federal Office for Civil Rights investigated the event and closed its review without a finding.

02A security program leaders can govern every day

Most security programs become visible to executives only during an audit or incident. I turned ours into a live operating system tied directly to policy. Leaders can see what is protected, what is due, where evidence exists, and which gaps require a decision. Audits now test the same environment used to run the work instead of a binder assembled after the fact.

03Six hours became five minutes

A suspected phishing message or infected computer can force a senior security leader through hundreds of checks before deciding whether the organization is in danger. I built investigation applications that perform those checks consistently and produce the complete after-action record. A near miss that consumed six hours now takes about five minutes, which means faster decisions and less chance that one missed step becomes the next incident.

04Fewer 3 a.m. calls about threats and outages

Security is also the ability to keep working when a system, site, or vendor fails. I built redundancy across datacenters, identity, connectivity, and cloud recovery, then paired it with access controls, data protection, threat detection, and automated response. The result is fewer incidents that need a person overnight and a more resilient organization when something does break.

I built ElectriCISO to change how our own security program operated: one place for compliance, vendor review, threat intelligence, evidence, and day-to-day decisions. The model received national recognition and is now being commercialized for broader distribution. I carried it from the original problem and product design through pricing, channel strategy, MSP partnerships, and go-to-market execution.