Skip to content
View HarrisonWard's full-sized avatar

Sponsoring

@KelvinTegelaar

Highlights

  • Pro

Organizations

@harrisonwardtechnology

Block or report HarrisonWard

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
HarrisonWard/README.md

Harrison Ward

Security Shouldn't Be Paywalled.

Most of what a company needs to be safer isn't secret and isn't hard. It's just locked up behind a consulting engagement or a form that wants your email before it'll show you a checklist.

So I'm putting the stuff I'd hand a client on day one out here. Free. No form. Licensed so you can use it commercially.


I'm a cyber risk and technology exec. 30 years across financial services, professional services, and critical infrastructure. Ran technology as CTO for a five-office firm. Most recently SVP in Kroll's Cyber Risk practice, sitting as vCISO for enterprise clients.

I work on the boring half of security. The policies, the controls, the habits. The stuff that turns a strategy deck into something somebody actually does on a Tuesday.

Right now a lot of that is AI. How do you govern GenAI and agents without banning them outright or letting them run loose? Most frameworks haven't caught up yet.


Security Programs Are a Continuous Bear Attack

Three lines over twelve months. The sprinter peaks fast then crashes. The straggler drifts down and gets picked off. The steady pace climbs a little and is still going at month twelve.

You don't have to outrun the bear. You have to not be the slowest.

But you can't sprint either. Go all out and you burn your team down in two quarters, and the program dies with your enthusiasm. The job is finding a pace you can hold for years.

That's one of eleven things I say a lot. The rest are in PRINCIPLES.md. Everything here comes out of them.


What I Work On

  • Cyber Risk and Governance. Building programs, running maturity assessments, reporting to boards. NIST CSF, ISO 27001, CIS, CMMC, HIPAA, PCI, NIST 800-82.
  • VCISO Work. Owning cyber strategy and the risk roadmap for enterprise clients, including regulated and critical infrastructure.
  • AI Governance. Acceptable use, controls, oversight for GenAI and agentic systems. New risk model. Most frameworks are behind.
  • Third-party Risk. TPRM and supply chain. Vendor tiering through remediation.
  • Incident Readiness. 50 plus tabletops and IR readiness engagements.
  • Enterprise Tech. Took a 175-person firm from all on-prem to cloud-first. Paid off in March 2020 when everyone went home overnight and nothing broke.

Where I've Been

Kroll SVP, Cyber Risk Advisory Services
Roberts Markel Weinberg Butler Hailey PC Chief Technology Officer
Alvarez & Marsal Manager, Forensic Technology Services
Ernst & Young Senior, Fraud Investigation & Dispute Services

B.B.A. Management Information Systems, Texas Tech EnCE · RCA · Cellebrite CCLO and CCPA


What's Here

Security Lessons is the big one. 727 security lessons from stories people already know. The Simpsons, Shakespeare, Star Wars, the KJV Bible, Breaking Bad, real heists, Greek myth, a century of actual incidents. Every one mapped to NIST CSF 2.0 and ISO 27001.

I talk in analogies because framework language doesn't move anybody. That repo is 727 of them.

The rest gets posted as I finish it. Control mappings, policy sets, tabletop scenarios, board briefing structures, assessment scaffolding.

All of it CC BY 4.0. Use it, change it, sell services on top of it. Just say where you got it.

Notes on a Cocktail Napkin in Sharpie Beat Nothing. Everything here is a napkin somebody already scribbled on. Take it and write over it.

Something you need that isn't here? Open an issue and tell me.


Find Me


Opinions are mine. Not my employers', current or former, and not my clients'. Nothing here comes from a client engagement.

Popular repositories Loading

  1. Security-Program-Starter Security-Program-Starter Public template

    The policy set for a company that has none. ~20 security policies in plain markdown, mapped to CIS Controls v8, written to be read by employees rather than filed for auditors.

    1

  2. HarrisonWard HarrisonWard Public

    My GitHub profile.

  3. Board-Cyber-Briefings Board-Cyber-Briefings Public template

    Board and executive briefing templates for cybersecurity. Slide structures, metrics, and language that non-technical directors actually understand.

  4. AI-Governance-Kit AI-Governance-Kit Public template

    Enterprise AI governance: acceptable use policy, intake workflow, tiering model, risk register, and board oversight for GenAI and agentic systems. Mapped to NIST AI RMF and ISO/IEC 42001.

  5. vCISO-Playbook vCISO-Playbook Public

    How to actually run a virtual CISO engagement. First 90 days, cadence, deliverables, scope boundaries, stakeholder management, and the failure modes nobody warns you about.

  6. Tabletop-Library Tabletop-Library Public template

    Free, facilitator-ready cybersecurity tabletop exercises. Ransomware, vendor compromise, insider, OT/ICS, and AI agent scenarios. Inject timelines and after-action templates included.