Board & Advisory
Board and advisory work
Boards and investors bring me in when AI and security risk needs a straight answer from someone who has had to give one under real pressure. I was the most senior information security leader at MarkWest through its roughly $20 billion combination with MPLX and Marathon, and nearly three decades of carrying that accountability is what makes the advice worth taking. I sit as a cybersecurity board advisor and AI governance advisor, I am the outside read for CEOs and executive teams on the calls that are hard to walk back, and I run AI risk diligence for the venture capital (VC) and private equity (PE) funds behind them. You get an operator who has answered for these decisions, so the judgment in the room has already been tested.

What I do as your board advisor
- I take independent board seats and advisory board roles where AI and security risk is real enough to belong on the agenda, not buried in an appendix. As an independent board member I press on the AI and security assumptions no one else in the room has thought to test, and I hold management to answers a director can defend.
- I am the second set of eyes for CEOs and executive teams on the AI and security calls that are expensive to get wrong. You bring me the decision before it is made, we talk it through as peers, and you walk into your own boardroom already knowing where the risk sits and how you will explain it.
- I map your AI governance to the frameworks your auditors and regulators already recognize, the NIST AI Risk Management Framework (NIST AI RMF), the EU AI Act, and ISO 42001, and I hold your security program to the NIST CSF at the same time. That way the board sees one coherent picture of AI risk and cyber risk instead of two teams telling two stories.
- I put cyber risk quantification to work and give the board, the audit committee, and the risk committee AI and security exposure in dollars and probabilities the room can price. When a director asks what a given risk would cost, there is a number on the table and a defensible way we got to it.
- For a fund, I run technical due diligence and M&A due diligence on a target company's AI and security posture, and I take that same lens across a whole portfolio for venture capital (VC) and private equity (PE) firms. You come away knowing which portfolio companies are carrying exposure they cannot see, roughly what remediation costs, and where a finding is serious enough to reopen the valuation.
- When a portfolio company needs hands on the problem, I place fractional leadership into it, a virtual CISO to run security or a fractional Chief AI Officer to own the AI mandate, and I stay close enough to make sure the work matches what the board was promised.
- I keep the board ahead of where AI regulation and attacker behavior are heading, from OWASP's work on LLM and agentic-AI risk to the next rule coming out of the EU AI Act, so a new law or a competitor's launch never lands as a surprise the directors have to scramble to answer for.
What I bring to the boardroom
- The advice holds up because I have had to answer for it. When MarkWest went through its roughly $20 billion combination with MPLX and Marathon, I was the senior-most person accountable for its information security, so the risk was mine to carry and defend to people with a lot riding on the answer, and nearly three decades in security and technology sit behind that. That is the difference between an advisor who has read about the seat and one who has held it.
- I help write the standards other people cite. I co-lead the OWASP Top 10 for LLMs, I sit on the core team of the OWASP Agentic Security Initiative, and I co-led the 2026 State of Agentic AI Security and Governance report. I am a named author on the AAGATE and LAAF papers, and I co-wrote The CISO Evolution with Matthew K. Sharp (Wiley, 2022), a book on getting a board to treat cyber risk as a business decision it owns rather than a briefing it sits through.
- As a Distinguished Fellow of the Enterprise Risk Quantification Institute, I put AI and security risk in the units a board already budgets against, which is dollars. I turn a long list of technical findings into a short list of dollar-denominated decisions the room can weigh against everything else competing for the budget.
- I am finishing a master's in Applied Data Science and Artificial Intelligence at the University of Denver, expected December 2026, so when I set the guardrails on an AI program they come from someone who has read the architecture, not from a checklist. I hold the CISSP, CCSP, AIGP, and QTE, which cover security, cloud, AI governance, and risk quantification.
Current seats and standings
- Board Member, Chambers Capital Ventures
- Advisor, Valusync
- Distinguished Fellow, Enterprise Risk Quantification Institute
Questions boards and investors ask me
- What does a cybersecurity board advisor do?
- A cybersecurity board advisor gives the board of directors independent judgment on cyber and AI risk, so the directors can govern it instead of taking management's word for it. I sit on boards and advisory boards, quantify the exposure in dollars for the audit and risk committees, and make sure the security and AI decisions on the table are ones the board can defend later.
- What is AI governance at the board level?
- AI governance at the board level is the board owning how the company builds, buys, and controls AI, the same way it owns financial and safety risk. In practice that means a clear line on who signs off on a model, exposure mapped to the NIST AI RMF, the EU AI Act, and ISO 42001, and reporting the directors can read without a translator. I stand that up and then keep the board current as the rules change.
- Do you do technical due diligence for VC and PE firms?
- Yes. I run technical due diligence and M&A due diligence for venture capital and private equity investors, and portfolio-wide AI-risk diligence across the whole portfolio. You get a plain read on which portfolio companies are exposed, what remediation costs, and which AI claims in the data room hold up under a technical advisor who has governed these systems at scale and answered to a board for them.
- How is this different from your virtual CISO or fractional Chief AI Officer work?
- The advisory work is oversight and judgment. I sit on your board, advise your investors, and keep the risk honest from a governance seat. The virtual CISO and fractional Chief AI Officer engagements are the hands-on seats, where I or a leader I place runs the security or AI program day to day. Boards and investors usually want the advisory seat, and when a portfolio company needs an operator, I can take that seat or place the right fractional leader in it.
