Co-founder, Managing Principal, W Risk Group
Greater Seattle Area
Co-founder, Managing Principal, W Risk Group
Greater Seattle Area
W Risk Group
Managing Principal
Complex risk management decisions must be addressed through integrated frameworks that incorporate comprehensive risk assessment and governance processes. The broad view for today's executive assimilates legal and regulatory, technology and financial risk management systems. This practice has been dubbed "GRC" Governance, Risk and Compliance. We bring integrated governance, risk and compliance methods, techniques and processes to executives and their Boards.
Recent Publications:
Ritter, Jeffrey, and Karen Worstell. Evaluating the E-Discovery Capabilities of Outside Law Firms, A Model Request for Information and Analysis. Silver Spring: Pike & Fischer, 2006.
Contributor, Kabay, Mich., ed. Computer Security Handbook, 5th ed. (Pending Publication)
Microsoft
CISO
Feb 2005 - April 2006
Lead Microsoft's internal Information Security program: identity and access management, policy, governance, compliance strategy and monitoring, security engineering, IDS, technical investigations and forensics.
AT&T Wireless
VP, IT Risk Management and CISO August 2003 - January 2005
• Oversee 300+ senior directors, managers, analysts, project managers and consultants for delivery of improvements in company-wide security and risk management program
• Developed comprehensive program for third party vendor risk management, vulnerability management, access management and general operations control environment with a first year budget over $28 million
• Led compliance effort for Sarbanes-Oxley General Computer Controls and Application Controls
Governance, Risk and Compliance Integrated Frameworks, Risk Assessment, Security Program Development, ISO 27001 Pre Certification, Security Architecture and Secure Data Management/Records Management. Specializing in consulting to Fortune 500 Clients.
(Public Company; 10,001 or more employees; MSFT; Computer Software industry)
February 2005 — April 2006 (1 year 3 months)
Responsible for protection of all Microsoft internal computing assets - infrastructure, applications, data. Security policy and regulatory compliance, network security, investigations, strategy and architecture, education and awareness, customer interface, Identity and Access Management, Application Security and Performance Testing.
(Public Company; 10,001 or more employees; Wireless industry)
November 2004 — January 2005 (3 months)
Responsible for SOX compliance, Information Security, Business Continuity, Emergency Response, Disaster Recovery and Risk Management for IT organization of largest wireless company post-merger (Cingular and AT&T Wireless). Led merger organization change for security, business continuity and disaster recovery functions.
(Public Company; Computer & Network Security industry)
2003 — 2005 (2 years)
(Public Company; Computer & Network Security industry)
2004 — 2004 (less than a year)
(Public Company; Computer Software industry)
2003 — 2004 (1 year)
(Public Company; Computer & Network Security industry)
2002 — 2003 (1 year)
(Computer & Network Security industry)
1999 — 2001 (2 years)
(Computer & Network Security industry)
1999 — 2001 (2 years)
(Computer & Network Security industry)
1998 — 1999 (1 year)
(Computer & Network Security industry)
1998 — 1999 (1 year)
(Public Company; Computer & Network Security industry)
1987 — 1997 (10 years)
(Computer & Network Security industry)
1996 — 1997 (1 year)
MA, Hebrew scriptures, Biblical studies, 2002 — 2010 (expected)
Northwest Campus Extension, Seattle, WA
MS, Computer Science, 1985 — 1987
Chemistry, Biochemistry, Molecular Biology, 1976 — 1978
Biology, Music, 1972 — 1976
ISSA, ISACA, ASIS International,AIIM, ARMA, The IIA, BSI, I-4, IT Compliance Institute, Agora, Executive Women's Forum (EWF), Women2Women