Evolving Cybersecurity: Strategies for Success in Governance, Risk, and Compliance
CIOREVIEW >> Cyber Security >> NEWS

Director of Security at viiz communications

Michael P. O'Hara

Evolving Cybersecurity: Strategies for Success in Governance, Risk, and Compliance

Michael P. O'Hara
Michael P. O'Hara, Director of Security at viiz communications

Michael specializes in cyber risk and business impact analysis, focusing on governance, risk, and compliance across multiple sectors. With expertise in enterprise transformation, he guides organizations in transitioning to hybrid and cloud infrastructures while implementing robust security measures. Michael excels at translating complex business needs into actionable, fiscally sound solutions that promote growth and efficiency, combining technical acumen with an understanding of organizational dynamics to align technology investments with business objectives.

Through this article, Michael P. O'Hara outlines critical strategies for effective governance, risk, and compliance (GRC) in cybersecurity. He emphasizes the importance of understanding regulatory challenges, integrating security frameworks, and leveraging technology for efficient operations. Michael also discusses the necessity of a proactive security posture during hybrid and cloud transformations and offers insights on managing stress and advancing in the cybersecurity field.

Career Journey to Viiz Communications

I began pivoting heavily into the cybersecurity and compliance fields in 2013 while serving as head of IT at a compliance and due diligence company. The SEC OCIE requirement was a revelation. Many clients had questions about the “cybersecurity thing,” which I saw as both a business opportunity and the next big trend in tech.

If the SEC took this seriously, it would capture everyone’s attention—any business would soon be scrutinized. Coupled with my curiosity about cybersecurity and my experiences in IT security (dating back to my first firewall in 1999), I shifted my focus entirely.

Since then, I've immersed myself in Cyber/InfoSec and GRC, which have a symbiotic relationship. There's a maxim that states, “You can have cybersecurity without GRC, but you cannot have GRC without cybersecurity.” This perfectly ties their fates together.

Challenges in Maintaining Compliance with Regulations

One of the biggest challenges is staying current with the regulations you must follow, depending on where and how much you do business. Questions arise about your operational locations, future expansions, and whether your company meets any thresholds. For example, CCPA has specific requirements for the number of records and revenue, meaning one company may be subject to it while another is not.

When you multiply all the requirements from state, federal, and regulatory bodies, the amount of person-hours spent on audits becomes tremendous. Completing a whole ROC (PCI Report on Compliance) is grueling, even for medium-sized organizations.

Additionally, managing the overlap among these requirements is nearly impossible without leveraging technology to integrate with platforms that collect security and compliance metadata from your various systems. Each audit often shares significant overlap, creating a substantial logistical challenge.

Integrating Frameworks into Our Security Posture

We use NIST 800-53 as our foundation, recognizing that it’s more of a journey than a one-time implementation. If you break out all the requirements, we’re looking at around 5,400 distinct asks rather than just the 1,190 commonly cited. That’s quite extensive.

We incorporate MITRE into Qualys to help establish metrics and formalize our risk posture. However, technology alone doesn’t magically eliminate all risks, particularly those specific to our industry. Metrics drive some aspects of risk assessment. Savvy organizations recognize that simplifying these frameworks can reduce the total cost of ownership (TCO) for Governance, Risk, and Compliance (GRC) efforts—simpler is often better and more cost-effective.

The Role of Security Tools in Operations

Tools provide the essential visibility we need for effective security operations. For instance, without Qualys conducting vulnerability scans every four hours, we wouldn't know if malicious software was running on our servers or desktops. Managed Detection and Response (MDR) is critical because, without it, our ability to react swiftly is compromised—speed is crucial in cybersecurity. The adversaries are highly skilled and can move laterally in the blink of an eye.

Threat intelligence, including feeds from platforms like OpenCV, keeps our information fresh and actionable. We utilize multiple feeds from OpenCVE to ensure that different IT groups receive CVEs relevant to their specific areas, enhancing our proactive stance against potential threats.

  ​Cybersecurity is an arms race; every time the good guys find a solution, the bad guys are already seeking ways to circumvent it. Be curious and ensure your leadership aligns risk with the evolving technology and compliance needs. 

Key Security Considerations for Hybrid/Cloud Transformation

When transforming enterprise infrastructure to a hybrid or cloud environment, there are several key considerations:


  • Understand the Shared Responsibility Model: Be mindful of the "shared responsibility model" outlined in your Master Services Agreement (MSA) with cloud providers. You are responsible for ensuring that everything is configured correctly. Never assume anything is secure when it's newly deployed.

  • Integration with Existing Tools: Consider how the cloud provider will integrate with your current set of tools.

  • Compatibility of Security Tools: Ensure the servers you migrate will still support compatible agents and tools for antivirus, malware protection, Endpoint Detection and Response (EDR), and monitoring.

  • Avoid Lift and Shift: I strongly advise against the lift-and-shift model. The goal of moving to a new environment should be to leave behind outdated operating systems, applications, and any gaps that could trigger concerns during a GRC audit, such as poor segmentation and lack of encryption.

Staying Ahead in Cybersecurity Innovations

I engage in extensive research and subscribe to numerous newsfeeds to stay ahead of the curve with the latest innovations in cybersecurity technologies and practices. Additionally, I actively participate in cyber events as an attendee, presenter, and panelist. These events provide valuable opportunities to connect with brilliant minds eager to discuss their challenges and the solutions they've implemented.

Managing Stress and Maintaining Team Morale During High-Pressure Situations

Managing stress during high-pressure situations, such as a security breach, is easier said than done. I’ve faced many incidents, from minor fires to crises, that I wish I’d never had to endure. The latter makes it nearly impossible to remain calm, especially when working around the clock for extended periods, which takes a mental and physical toll.

The critical lesson is to do your best without losing your mind. In those intense situations, I’ve realized there will often be imbalances between what the business perceives as a threat and what the metrics and assessments reveal. As long as you've conducted your due diligence, presented the facts to the decision-makers, and defined potential outcomes (using outage scenarios via FAIR is effective), you can trust that you’ve done your job.

Advice for Advancing in Cybersecurity and GRC

Entering the cybersecurity field requires a realistic perspective—it's challenging but full of opportunities to outsmart adversaries. I've often noted that describing cyber as an "arms race" is entirely accurate; every time the good guys find a solution, the bad guys are already seeking ways to circumvent it. The technology evolves alongside the compliance considerations that accompany it.

Be curious and assess whether your leadership truly supports aligning risk (both inherent and residual) with the current and future needs in tooling, processes, and personnel. If they do, that’s fantastic. If not, consider seeking opportunities elsewhere.

Metrics are essential in this field. Cybersecurity doesn’t function effectively without solid data (Qualys provides precise vulnerability risk assessments). Steer clear of guesstimates; find ways to assign value to various elements instead. For risk assessment, the FFIEC is excellent—answering its 550 questions with "Yes," "No," or "N/A" offers an unbiased maturity level.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.