Richard Rees is a nationally recognized expert in how information security trends and technologies effectively support business operations. Richard works with SunGard’s customers to define and architect reliable, independent and timely information security solutions designed to keep them out of harm’s way – combating both external and internal threats against the enterprise. When things go awry, he helps deploy SunGard’s forensic team to investigate and address computer incidents. Richard’s experience ranges from mentoring Chief Security Officers in implementing security programs to conducting enterprise security assessments of global organizations, regulatory reviews (HIPAA, GLBA, SOX), vulnerability assessments, and penetration testing.
Prior to joining SunGard, he was the Security Practice Lead for the Midwest at a well-known professional services organization. He was responsible for the development and delivery of specialized security services, including industry benchmarking security assessments and HIPAA compliance solutions, as well as mentoring and managing security consulting teams. He brings to SunGard more than a decade of diversified information security experience with both public and private enterprises in industries including financial services, healthcare, government, consumer products, education, manufacturing, retail and energy.
Richard received a B.S. in Electrical Engineering from Michigan State University. He has been a Certified Information Security Systems Professional since 1999, and also holds Novell Certified Network Engineer (CNE) and Microsoft Certified Systems Engineer (MCSE) certifications. Richard is also a frequent presenter and panelist on a range of information security topics at events throughout the U.S for the military and law enforcement as well as private industry.
Commentary:
Over the past four years, the business impact of information security has changed significantly. Today, more than one-third of Chief Security Officers have responsibility for Information Availability, and are reporting outside of the traditional Information Technology group. The pursuit of virtualization technology is creating security challenges for which there are only partial solutions. Organizations that store, process, and transmit personal information are discovering that meeting compliance targets offers little assurance of avoiding a data breach, which can quickly put them in the news spotlight and under public scrutiny.. Today’s businesses need to focus on determining what reasonable and cost-effective approaches to information security provide the greatest real reduction in liability. The goal is to create an environment of intelligent risk management that supports practical security investment for risk mitigation, transfer, and acceptance.
Areas of Expertise:
information security, managed security services, compliance, security assessments, virtualization security, risk management, hacking, data breach, information availability