#747 The State of IT and Technology Leadership for 2024 with Brian Grouzos, Adam Bahret, and Tony Davis

Today, we’re bringing you a special Modern CTO panel episode! Brian Grouzos, Adam Bahret, and Tony Davis join in to discuss their biggest challenges over the past year, where their focus lies in the new year, and how they’re gearing up to take on all that 2024 has to bring.

All of this right here, right now, on the Modern CTO Podcast! 

For more about Brian's company, Prescient Assurance, check out their website here.

For more about Adam Bahret and his work, visit his website here.

For more about Tony's company, AIOps, visit their website here.

Have feedback about the show? Let us know here.

Produced by ProSeries Media.

For booking inquiries, email booking@proseriesmedia.com

About Brian Grouzos

In my previous role, I was responsible for managing a dynamic, agile team of 15 people that covered a variety of risk and compliance areas including PCI, HITRUST, government compliance (NIST 800-171, 800-53, FEDRAMP), etc. These security and compliance efforts stretched across a wide list of technologies from internal and external cloud to mainframe and everything in between. My team implemented controls, identified gaps, and partnered with business areas to drive remediation efforts. We were also responsible for supporting internal and external PCI assessments across the company, HITRUST audits, various government audits, etc.

As part of my work on this team, I created a consolidated list of standardized controls to simplify and streamline security and compliance. We leveraged these controls to implement a robust risk-based controls assessment process to better identify gaps proactively. I created a dedicated remediation team to partner with business units to help with prioritization, implement the right controls to effectively manage risk with the least amount of impact to the business, and ensure the full life cycle of risk management is considered. We standardized scoping using our GRC tool to gain insight into changes in the environment and prioritize our work to add the most value. We also created a dedicated resource site to communicate control expectations and guidance to stakeholders.

My goal with security is to work with the business to ensure they have all the tools they need to be successful. I take a very customer-oriented approach to security and I am always working to limit waste in processes. I am constantly trying to drive a more security-aware culture and build strategic relationships at all levels of the company. Through this work we built security champions and ran a lean and efficient security and compliance group. The team values were speed, excellence, service, value creation, and team work. I also started a career development book club that met every two weeks, developed our team coaching process, and emphasized skill development with all members of my team.

About Prescient Assurance

Prescient Assurance is a licensed CPA Firm which provides Audits and Examinations for SOC2 attestation, ISO, PCI, GDPR, HIPAA, CCPA, GDPR, GBLA, NIST 800-53, NIST 800-171, FERPA, FISMA, PIPEDA, SWIFT CSP, HITRUST, Google OAuth, Microsoft SSPA, CSA STAR, and Privacy Shield . Prescient Assurance is the leader in security certifications for B2B SAAS companies worldwide. We are global Top -10 cloud security auditors by cloud security alliance STAR program.

About Adam Bahret

I live in Massachusetts with my wife and two daughters. When I’m not designing and testing highly reliable products for my clients, I’m trying out my own at home. I typically use cars as my test beds, adding extreme features into unusual places. On our wedding day, my wife included her own unique vows, ‘’I’m well aware that my life going forward will be filled with constant modifications and disassembly of everything in our house.’’

About Tony Davis

I serve as a Sr. Engagement Manager for A&I Solutions. I have spent over 30 years implementing and leading Fortune 100 IT Operations technologies, and now work with A&I clients to design monitoring strategies that combine selective NetOps, Infrastructure, and AIOps data into meaningful observability.