Sign in to view Adam’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Miami, Florida, United States
Sign in to view Adam’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
8K followers
500+ connections
Sign in to view Adam’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Adam
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Adam
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Adam’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View Adam’s full profile
-
See who you know in common
-
Get introduced
-
Contact Adam directly
Other similar profiles
-
Travis Howe
Travis Howe
Alpha Overwatch | vCISO for SaaS, SMBs, and Salesforce ISVs
3K followersHill City, SD -
Stefan Richards
Stefan Richards
A mission-driven, seasoned security executive with over 20 years of experience and a passion for getting things done. <br><br>Stefan currently serves as CISO of CorVel (CRVL), where he oversees security and privacy policy, governance and operations.<br><br>In the past, Stefan served in executive security leadership roles as Chief Information Security Officer (CISO), Chief Security Officer (CSO) and Chief Privacy Officer (CPO) at large and small organizations in both the private and public sector. As the CISO for the State of Oregon, Stefan defined and led transition to a new enterprise security model, building a central security organization from 5 to 60, deploying a number of highly-effective enterprise security programs, establishing security accountability through enterprise metrics and driving passage of major state security legislation. <br><br>Prior to working in operations, Stefan shipped security products at Microsoft and Intel, led solutions architecture and development at a security startup and pioneered the enterprise security incident response team (PSIRT) and security product development lifecycle (SDL) at Intel. <br><br>Stefan has a consistent track record of going after the tough challenges others turn away from and overcoming those challenges with motivating vision, careful strategy, and adaptive execution. Stefan is sought out for his broad security knowledge and experience, high emotional intelligence, effective authentic communication, empathetic team leadership and consistent delivery on aggressive goals.
1K followersPortland, OR
Explore more posts
-
Justin Leapline
Distilled Security Podcast • 5K followers
A deeply researched article dropped this week that should concern every security leader, startup founder, and enterprise buyer who relies on compliance reports to evaluate risk. It details how a well-funded GRC automation platform allegedly generated hundreds of near-identical SOC 2 reports from a single template — pre-written auditor conclusions, fabricated evidence for board meetings and incident response tests that never happened, and trust pages listing security controls that were never implemented. The auditors rubber-stamped the output. Clients were told they were compliant. Many of them process PHI for millions of people. But here's the thing: this isn't just one company's problem. This is the logical endpoint of an industry that has been optimizing for speed over substance for years. We've built a compliance market where: → "Get compliant in days, not months" is a selling point instead of a red flag → Auditor independence is structurally undermined when the platform generates the auditor's own conclusions → Companies adopt templated policies they know are inaccurate because they don't have bandwidth to rewrite them → Trust pages go live before a single control has been verified → The buyer on the other end of a security questionnaire has no way to distinguish a real report from a manufactured one The uncomfortable truth is that the market incentives created this. Startups need SOC 2 to close enterprise deals. They want it fast and cheap. Platforms compete on speed. Auditors compete on price. And somewhere along the way, the actual security outcomes — the entire reason these frameworks exist — became an afterthought. This is what happens when compliance becomes a commodity checkbox instead of an assurance process. If you're a founder relying on a compliance platform: ask hard questions. In writing. How are auditor conclusions formed? What evidence is generated vs. collected? Who actually writes your report? If the answer is "don't worry about it" or "get on a call and we'll explain" — that's your answer. If you're an enterprise buyer evaluating SOC 2 reports: a clean report is not proof of security. It never was. But the gap between report and reality has never been wider. If you're building in GRC: we have to do better. Confidence in compliance outcomes should be earned through evidence, not manufactured through templates. The frameworks themselves aren't broken — but the ecosystem around them is. The full article is worth your time: https://lnkd.in/eEej8sAy #GRC #Compliance #SOC2 #InfoSec #CyberSecurity
11
4 Comments -
Karen Stanford
Archstone Security LLC • 4K followers
TL:DR: The DoW officially issues guidance to contracting officers to remove references to independent assessment requirements and primes lose their ability to flow down certification requirements to subs. We are not expecting to hear anything after the 60-day review of CMMC concludes, as the output is simply recommendations, which will likely remain internal until direction is solidified.
15
-
Juan Pablo Castro
TrendAI • 36K followers
COSO (Committee of Sponsoring Organizations of the Treadway Commission) just told the entire risk profession something cyber risk already learned the hard way. In 2026, COSO, the body that has set the standard for enterprise risk management since 1985, published new guidance called From Guidance to Action. Its finding: most ERM programs fail not because they lack frameworks, but because they run on a calendar. Quarterly heat maps. Annual registers. Reports that arrive months after the conditions they describe have changed. "In many programs, output arrives too late, or in a form that doesn't help leaders choose between options, trigger meaningful action, or impact decisions." Here is the line that stopped us: "Risk becomes performative, we scored it, or a paperwork exercise, we documented it. The result is the same: the hard conversations happen after the window to act has already closed." That is the exact problem we built CyberRiskOps to solve. You cannot control what you only assess twice a year. CyberRiskOps replaces the periodic checklist with continuous operations, the same way DevOps replaced periodic software releases with continuous delivery. A risk report produced once a quarter is not risk management. It is closer to checking your blood pressure once a year and calling it cardiovascular health. COSO now says the same thing in different words. It calls for triggers that force a reassessment the moment conditions shift, not on a fixed schedule. "Triggers only work when they can be monitored with minimal friction... Even simple automation — standard thresholds, exception flags, trend views, and alerts — can shift ERM from episodic assessment to continuous awareness." And this: "Without triggers, risks remain observations. With triggers, risk becomes a series of defined decision points." It also draws a hard line between a framework, which describes what good risk management should achieve, and an operating system, which is how an organization actually lives it. "The Framework is a map. The operating system is the vehicle." That is the architecture behind CRQ, CyberRiskOps, and CROC. CRQ measures exposure. CyberRiskOps keeps that measurement alive, recalculating the moment a control goes offline. CROC is that discipline fully operationalized, where "what is our risk right now" comes from this week's telemetry, not last quarter's slide deck. Enterprise risk management is arriving at the operating model cyber risk was forced to build first, because cyber never had the luxury of a slow clock. The uncomfortable part for risk leaders is not the diagnosis. COSO's own survey found only 7 percent of ERM programs are fully integrated into strategy decisions, while 98 percent of leaders say ERM should play a bigger role. Everyone agrees on the destination. Almost no one has built the operating system to get there. https://lnkd.in/eRDT9m2Q #CyberRiskOps #CyberRisk #CROC #ERM #RiskManagement #CRQ #CISO
15
-
Dan Ricci
Industrial Data Works LLC • 5K followers
Good morning! Here is this week's ICS Advisory, Other CERT, and Vendor vulnerability advisories weekly summary for 23 - 27 February 2026. This past week, CISA released 12 new CISA ICS Advisories for the following vendors: Copeland, InSAT, CloudCharge, EV Energy, Chargemap, SWITCH EV, Mobility46, EV2GO, Gardyn, Johnson Controls, Inc. Pelco, Inc. and Schneider Electric. One update was released this past week for Honeywell Schneider Electric, Mitsubishi Electric, Hitachi Energy, ICONICS and Mitsubishi Electric. Based on the new CISA advisory, #Energy, #TransportationSystems, #Commercial #Facilities, #Healthcare and #PublicHealth, #Defense #Industrial Base, #Food and #Agriculture, Critical #Manufacturing, #Government #Facilities, #Financial #Services, #InformationTechnology, #Water and #WastewaterSystem are the potentially affected critical infrastructure (CI) sectors. The ICS Advisory Project identified 16 new ICS Advisories for Festo, ARC Informatique, Moxa, Phoenix Contact, ABB, Bosch Rexroth, Hitachi Energy, Ubiquiti Networks, Trumpf, PDUexperts, Socomec and one update for Hitachi Energy. View the summary details of other CERT & Vendor product advisories identified last week (23 - 27 February 2026) at: https://lnkd.in/efKiMsxs This past week, CISA added 3 new Known Exploited Vulnerability (KEV) Catalog. None added this week correlated to a CISA ICS Advisory. ICS Advisory Project identified one CVE: CVE-2020-11023 – JQuery Cross-Site Scripting (XSS) Vulnerability listed in the Festo advisory for CODESYS vulnerabilities in Festo Automation Suite [VDE-2025-108]. This week, ICS Advisory Project, powered by Industrial Data Works LLC, in collaboration with EmberOT, released our 2024–2025 ICS/OT Vulnerability Intelligence Report. Check it out at: https://lnkd.in/ehG4DNPs Thank you all at EmberOT for your amazing support in getting this report out this year. Acknowledgement: Thank you Mikael Vingaard at the ICSRange for sharing with ICS[AP] the new ICS Advisory for PDUexperts. Visit the ICS[AP] CISA KEV Catalog Dashboards: https://lnkd.in/emzXBbBw View previous ICS Advisory Project weekly summaries: https://lnkd.in/eQKxhAEi To view the updated ICS Advisory Project Dashboards, visit: icsadvisoryproject.com Sign up to receive ICS[AP] Weekly Summary Slides & Other CERT and Vendor Advisory Summaries via email every Monday https://lnkd.in/eUwQrrj4 I appreciate everyone's comments & support. Have a great week! #CISA #ot #ics #otsecurity #icssecurity #cybersecurity #cybersecurityawareness #industrialautomation #buildingautomation #oilandgas #maritime #vulnerabilitymanagement Disclaimer: The views expressed in my LinkedIn posts and profiles are my own, not those of my employers or LinkedIn.
29
-
Colton Porter
SAINT Technology Services • 3K followers
Ransomware groups earned less money in 2025 despite launching 47% more attacks. The math forced evolution. When volume doesn't drive revenue, operators adapt their model. I'm tracking three shifts that matter for our planning. First, ransomware-as-a-service now includes DDoS attacks as standard bundles. Second, these groups actively recruit corporate insiders rather than waiting for opportunistic contacts. Third, they're exploiting gig economy workers who unknowingly move money and equipment. The insider recruitment piece concerns me most. Traditional security assumes external threat vectors, but https://lnkd.in/gsCaw27Z shows organized campaigns targeting employees with financial pressure. We're not talking about sophisticated social engineering anymore. We're talking about direct cash offers to people who already have access. The gig worker angle is clever operational security. Using legitimate freelancers to handle logistics creates attribution problems and legal complications for law enforcement. These aren't criminals in the traditional sense. They're people picking up what looks like normal contract work. Our clients need to understand that 2026 threat models include coordinated recruitment campaigns targeting their own staff. Background checks and security clearances don't protect against someone who becomes compromised after hiring. The operational sophistication is maturing faster than most organizations are prepared to handle. #GreyShield #ThreatIntel #Security #RiskManagement #Leadership
-
Nitin Bhatnagar
PCI Security Standards Council • 25K followers
The PCI Security Standards Council (PCI SSC) has released a new information supplement, PCI DSS v4.x: Guidance for Compensating Controls and the Customized Approach. The document provides practical guidance to help assessed entities and assessors navigate two options in PCI DSS v4.x that provide flexibility but are often misunderstood – the use of compensating controls and the customized approach. PCI SSC developed this guidance in collaboration with industry stakeholders, including the Global Executive Assessor Roundtable (GEAR) and the Board of Advisors (BOA). PCI Security Standards Council https://lnkd.in/dTV5EwB3
47
-
David Townsend
Corporate Information… • 7K followers
✳️DFARS Update Alert ✳️ DoW’s new class deviation (DARS 2026‑O0025) reorganizes—not expands—cybersecurity requirements. DFARS Part 240 and new clause 252.240‑7997 now centralize NIST SP 800‑171 Medium/High assessment access, precedence, and SPRS posting when the deviation is used. Key point: 7012, 7008, and all CMMC requirements remain fully in force. CMMC Level 2 (Self) is not eliminated. What changes is how DoW manages and prioritizes its own NIST 800‑171 assessments At CorpInfoTech, we closely track regulatory changes to help defense contractors navigate compliance with confidence and strengthen their security posture. DFARS Assessment Changes Explained: Practical Impacts for Contractors https://hubs.li/Q042vp4Q0 #CMMC #DefenseContractors #DFARS #NIST800171 #DoW #DoD #DiB
4
-
Tim Callan
7K followers
As certificate lifespans become extremely short, new methods of delivery become functionally necessary. Jason Soroko explains RFC 9345 and how delegated credentials play a role in CDNs to deliver very short-lived certificates on the Root Causes Podcast. https://lnkd.in/gtQtGcAG
16
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content