Fractional CISO and risk management consulting for healthcare and regulated industries. Deployed into high-pressure environments—breach response, OCR audits, and program transformations—and trusted by cyber insurers to stabilize what went wrong.
I have spent 15 years as a fractional and acting CISO for healthcare organizations, most often stepping in after a breach, a leadership departure, or an OCR data request forces the issue. My job is to quickly assess an unfamiliar environment, set priorities, and build a security program that holds up under regulatory scrutiny.
Cyber insurers and breach-response law firms refer clients to me because of my track record: across my entire client history, not one organization has received an OCR fine following my involvement. None have appeared on the HHS “Wall of Shame” a second time after corrective action.
I adapt to each client’s environment, resource constraints, and risk tolerance—no one-size-fits-all binders, no bias imported from other organizations.
Rapid stabilization and corrective action for HIPAA breaches. Includes OCR data request responses, forensics coordination, and remediation plans executed under mandatory reporting timelines.
Embedded security leadership for organizations without a full-time CISO. Covers team management, executive briefings, vendor oversight, policy governance, and ongoing operating cadence.
NIST CSF and NIST SP 800-53 aligned risk analyses mapped to your actual environment. Findings are prioritized and delivered in plain language, not generic templates or compliance checklists.
Security policy suites, standards, procedures, and GRC platform builds grounded in real operational constraints. Includes charters, documentation cadences, and the governance rhythms that keep programs audit-ready year-round.
Risk-tiered vendor programs covering onboarding, periodic reevaluation, and offboarding. Includes evidence-based reviews, vulnerability scanning prior to network access, and standardized procedures that maintain an assurance posture between audits.
Targeted phishing simulations and training programs designed for behavior change, not checkbox compliance. Includes gamified engagement, newsletter content, and materials tailored to your workforce and threat landscape.
Available for fractional CISO engagements, breach response, risk assessments, and GRC program work. I typically respond within one business day.
contact@ardentinfosec.comNo social media presence by design. References available upon request.