Expert Witness, Cybersecurity
Cybersecurity expert witness: standard of care, data breach, security program adequacy
Independent technical opinions from someone who built and ran a security firm for 14 years, then led security operations in a high-stakes, adversarial production environment.
Background
Fourteen years running a security firm, then running security operations
I founded and led Redspin for fourteen years, a penetration-testing and information-security firm serving financial services, gaming, and healthcare clients, through its acquisition by CynergisTek (now Clearwater Compliance) in 2015. Redspin built a HIPAA/HITECH security practice serving covered entities and business associates directly: penetration testing, application and network security assessments, and security audits. Later, as Lead, Security Operations & IT at Polygon Labs, I led the company's first ISO 27001 certification and SOC 2 compliance program, chaired the Information Security Risk Committee, and owned the incident response plan and business continuity framework as ISMS owner of record.
Services
What I can help with
Whether a security program, control, or response met the standard a reasonable organization would be expected to meet at the time.
Technical review of what happened, when it was detected, how the response was handled, and whether the organization's process held up.
For covered entities and business associates, drawing on 14 years of Redspin's healthcare security practice.
Whether a security program, its policies, controls, and governance, was reasonably designed and actually operated as documented.
Credentials
Credentials and publications
- Founder & CEO, Redspin, 2001 to 2015, penetration testing and information security, through acquisition by CynergisTek (now Clearwater Compliance)
- Lead, Security Operations & IT, Polygon Labs, 2022 to 2026: ISO 27001 certification, SOC 2 compliance, incident response, and business continuity and disaster recovery
- MCP Scorecard, an open security scorecard for AI agent (MCP) servers
- The MCP Server Security Policy and the State of MCP Security research
- Published visual guides to security and risk for decision-makers (Medium, @j2abro)
Request Consultation
If you're evaluating a testifying expert for a cybersecurity or data breach matter, reach out for a confidential initial review.
jabraham@bluemotionlabs.com