
Cybersecurity, privacy, and responsible AI strategist.
I'm the Chief Information Security Officer at the J. Paul Getty Trust, where I lead the cybersecurity program along with the Trust's identity and AI strategy.
I work on human-centered security: when people keep making the wrong call, that's a design problem, not a people problem.
- 4
- CISO roles
- 3
- inaugural appointments
- 20+
- years in cybersecurity and privacy leadership
Before Getty, I was CISO and Associate Vice President for Information Security at the University of Washington. Earlier, I was the first-ever CISO at the University of Toronto, where I also served as Deputy CIO and helped launch CanSSOC, Canada's first shared security operations centre for higher education. Before that, I spent thirteen years at the University of California, Irvine as Information Security Officer and Campus Privacy Officer, where I chaired the UC systemwide CISO group on two separate occasions.
I've also served on Ontario's Broader Public Sector Cyber Security Expert Panel, sat on the REN-ISAC steering committee, and taught Philosophy of Privacy at UC Irvine. In 2009 I co-led a multi-state identity theft investigation recognized by the International Association of Chiefs of Police, and in 2021 I was named CISO of the Year by CISO Forum Canada.
I bring direct board and executive-reporting experience across four institutions. Through Meridian Forge, I also advise boards and organizations on security strategy, AI governance, and building programs from zero.
02
Initiatives
- 2023 · U of T Information Security Strategy
A four-year security strategy for a $3.2B institution with 120,000 users, led as CISO and built through tri-campus consultation before approval by the Governing Council.
- 2018–2023 · CanSSOC
The Canadian Shared Security Operations Centre, the first shared SOC for Canadian higher education, built with a coalition of universities to pool threat intelligence, expertise, and cost. Founding CISO, later Acting Director; now operating nationally under CANARIE.
- 2020–2022 · Ontario Broader Public Sector Cyber Security Expert Panel
A ten-person panel convened under Ontario's Cyber Security Strategy to assess cyber risk across the province's hospitals, school boards, municipalities, universities, and colleges. A member from its formation in 2020 until the panel's report to the Minister was published in 2022.
- 2021 · Global Cyber Threat Sharing MoU
An international threat intelligence sharing agreement between the national research and education networks of Canada, the UK, the US, and Australia (CanSSOC, Jisc, AARNet, OmniSOC, and REN-ISAC), built on MISP so partners warn each other of attacks in real time. CanSSOC led its creation; a 2026 renewal added New Zealand's REANNZ, bringing it to five countries.
- 2018 · UC Electronic Information Security Policy, IS-3
A ground-up rewrite of information security policy for the entire University of California system (ten campuses, five medical centers, three national laboratories), as chair of the systemwide IT Policy and Security committee and a contributing author. Signed in 2018 and still the governing policy today.
03
Speaking
Talks and presentations
- 2026 · The Modern CISO: Building Human-Centric Security Leadership for Higher Education, EDUCAUSE Cybersecurity and Privacy Professionals Conference (slides)
- 2025 · The Relationship Between IT and Audit, Ontario University Internal Auditors Annual Conference
- 2025 · Cybersecurity and Board Governance in Higher Education, Cybera, Haskayne School of Business
- 2023 · The Value of Collaboration, Canadian SecuR&E Forum, CANARIE
- 2023 · Cybersecurity: Implications for Roboticists, Toronto Robotics Conference (keynote panel)
- 2022 · Community Collaborations in Cybersecurity, CANARIE Summit
- 2022 · A Day in the Life of a CISO, Cybera SecureIT
- 2022 · Security at the Speed of Research, CANARIE (video)
- 2022 · Enough Talk! Making Security and Privacy Reviews Practical and Effective, EDUCAUSE Cybersecurity and Privacy Professionals Conference
- 2022 · A Glimpse Into the World of a CISO, BCNET CONNECT (video)
- 2021 · Security is from Mars; Privacy is from Venus, EDUCAUSE Cybersecurity and Privacy Professionals Conference
- 2021 · Security is from Mars; Privacy is from Venus, CANHEIT
- 2021 · Good Security is Shared Security: A Canadian Approach, CANHEIT (video)
- 2021 · Broader Public Sector Cyber Security Expert Panel, IT@UofT
- 2020 · Cyber security session, NREN National Summit (session title not published)
- 2020 · Cyber Safety in a Pandemic, ORION ON-CHEC Day
- 2020 · Threat Feed Pilot Service Launch, CanSSOC and CANARIE (video)
- 2019 · Getting Cyber Security Out of the Weeds and at the Leadership Table, OHEIT
- 2019 · Managing Risk and Staying Safe Online, OHEIT
- 2019 · Introducing CanSSOC, CANARIE (video)
- 2015 · Lifting the Fog on Instructional Cloud Services, UC Computing Services Conference
- 2015 · Can't Buy Me Love? Privacy, Security, and Vendor Data Protections, UC Compliance Symposium (slides)
- 2014 · The Risks of Click-Through Agreements, EDUCAUSE Annual Conference (slides)
- 2014 · Cloud Sourcing Requires a New Approach, EDUCAUSE Annual Conference
- 2014 · Risky Business: Click-Throughs and You, University of California Office of the President (slides)
- 2012 · FISMA Compliance, University of California Office of the President
- 2008 · Using Encryption to Protect Personal Information, UC Computing Services Conference
Interviews and podcasts
- 2026 · The Economics of Cybercrime and the AI Strategy Behind Getty, The Cyber Business Podcast
- 2025 · Stronger Together: A CanSSOC Conversation, Bytes of Experience: CIOs Unplugged
- 2025 · The CISO Tightrope: Balancing Boards, CIOs, and Campus Culture, Bytes of Experience: CIOs Unplugged
- 2023 · Cyber Resilience Hour, siberX
On Ontario's cyber security expert panels.
- 2023 · Power Hour, siberX
- 2021 · CISO Chat, CISOCast, University of Victoria
04
Writing
- 2022 · On Cybersecurity, We Must Truly Work Together, The Hill Times, Ottawa
Op-ed arguing for defence through partnership over per-institution defence in depth.
- 2022 · Cyber Security Expert Panel Report, Government of Ontario
Contributing member, ten-person panel.
- 2013 · Effective Acquisition and Appropriate Use of Internet-based Services and Software: Vendor Terms and Conditions, Report to the University of California IT Leadership Council
Janine Roeth, William Allison, Lisa Ho, Stephen Lau, Isaac Straley, Thomas Trappler, and others.
05
Service
Recognition
- 2021 · CISO of the Year, CISO Forum Canada
- 2009 · Award for Excellence in Criminal Investigation, International Association of Chiefs of Police
- 2009 · Distinguished Service Commendation, UC Council of Police Chiefs
Committees and boards
- 2024 · Co-Chair, Information Security and Privacy Board, University of Washington
- 2023 · Steering Committee, REN-ISAC
- 2020–2022 · Member, Broader Public Sector Cyber Security Expert Panel, Government of Ontario
- 2020 · Cybersecurity Advisory Committee, CANARIE
- 2020 · Cybersecurity Steering and Advisory Council, Compute Canada Federation
- 2020 · Steering Committee, Ontario Cybersecurity Higher Education Consortium
- Chair, University of California IT Policy and Security Committee (ITPS), University of California
Served on the committee throughout my time at UC Irvine; chaired it on two separate occasions. Also: Member, UC Security Incident Response Committee. IT Policy Coordinator for UC Irvine.
Teaching
- Philosophy of Privacy, University of California, Irvine