AI Is Raising a Critical Question: Who Owns Cybersecurity Risk?
As organizations adopt AI tools and rely more heavily on data, one question becomes increasingly important: Who is responsible for governing the policies, risks, and...
Michael Anderson is a white hat ethical security hacker and business continuity advisor with extensive experience in designing and implementing security-focused audit and control programs. In his role providing virtual CISO support, he works closely with organizations to strengthen IT security governance, resilience, and oversight across complex technology environments including managed services.
Clients depend on his leadership for security architecture reviews, penetration and vulnerability testing, business resiliency, disaster recovery, and remediation planning. Michael’s technical background spans hardware system selection and configuration, cloud and hybrid application security reviews, and wireless security assessments. A core area of his work includes advising organizations on the secure adoption and governance of artificial intelligence (AI), with an emphasis on responsible use, protection of sensitive data, and alignment with established control environments.
He is well-versed in industry standards and internal controls evaluation including COSO, COBIT, ITIL, ITGCC, GLBA, ISO, and SOX 404 requirements spanning planning, evaluation, documentation, testing, and remediation. He also advises organizations on compliance with the Payment Card Industry Data Security Standard (PCI) and HIPAA privacy and security rules.
Michael holds several globally recognized certifications including The Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), Cisco Certified Network Professional (CCNP), and AWS Cloud Security Assurance Program (AWS CSAP). Working closely with internal stakeholders, he tests and monitors IT environments including network topologies, firewalls, VPN configurations, hardware infrastructure, and IT policies and standards. Through this work, control weaknesses and system integrity exposures are identified, with practical guidance provided to support risk mitigation, regulatory compliance, and reliable technology operations.
Education
Professional Associations
As organizations adopt AI tools and rely more heavily on data, one question becomes increasingly important: Who is responsible for governing the policies, risks, and...
Proposed changes to the HIPAA Security Rule would introduce more specific cybersecurity requirements and raise expectations for how organizations protect electronic protected health information.
Artificial intelligence is reshaping how organizations think about system security and operational oversight. Unlike traditional tools built on fixed rules and reactive triggers, AI systems...