Vector is led by a technology and security executive who has spent more than twenty-five years inside insurance distribution — including five as Chief Security Officer and CISO for life and annuity distribution firms placing over $1 billion in annuity business annually.
Most people who assess a distribution firm's cybersecurity come from security and pick up the industry second. I came the other way.
I have spent more than twenty-five years in insurance distribution and financial services technology — building the platforms agencies and advisors run on, leading the operations behind them, and most recently spending five years as Chief Security Officer and CISO for life and annuity distribution firms that placed more than $1 billion in annuity business and $150 million in life insurance annually.
In that role I built the cybersecurity program from the ground up: zero-trust architecture, SOC 2-aligned practices, and the controls required to run distribution programs with major national banking institutions. I have sat on the receiving end of the due diligence questionnaire — the one your carrier or bank partner sends with a deadline attached.
That vantage point is what Vector is built on. A CISO does not get to deliver findings and move on. You carry them into a room with the people who hold the budget, explain what they mean in terms the business cares about, defend the order of the priorities, and then live with what gets decided. It is why the assessment opens with one page written for the principal rather than forty pages written for an auditor, and why every finding has to survive the question I was asked constantly in that chair: what does this actually mean for the business, and what does it cost me to fix it?
Before that I led operations for enterprise insurance distribution platforms at Ebix Exchange, now Zinnia — five business units serving carriers, broker-dealers, banks, BGAs, and advisor networks. Earlier, I built and ran a post-sales consulting practice for carrier and distribution technology implementations, co-founded my own consulting firm, and began my career at Andersen Consulting, now Accenture.
I founded Vector Risk Assessment to do one thing well: give the owners of financial services distribution firms a clear, defensible picture of where their cyber risk sits and what to do about it.
Background
Credentials and Experience
-
CertificationCISSP — Certified Information Systems Security Professional, (ISC)²
-
ExecutiveChief Security Officer and CISO, life and annuity distribution firms — 2021 to 2026. Built the enterprise cybersecurity program: zero-trust architecture, SOC 2-aligned practices, and the controls required for bank distribution partnerships.
-
OperationsVice President of Operations, Ebix Exchange (now Zinnia) — 2013 to 2021. Five business units serving carriers, broker-dealers, banks, BGAs, and advisor networks.
-
ConsultingPrincipal and co-founder, independent strategy and technology consulting practice — 2010 to 2013. Director of Business Consulting, E-Z Data / Ebix — 2006 to 2010. Career began at Andersen Consulting, now Accenture.
-
EducationM.B.A., The University of Texas at Austin, McCombs School of Business — Dean's Award for Academic Excellence. B.S. Engineering Science, Trinity University.
-
FrameworksNIST Cybersecurity Framework; NY DFS 23 NYCRR Part 500; SOC 2
-
FocusFinancial services distribution — life and annuity agencies, brokerage general agencies, and independent marketing organizations
How I Work
Three Commitments
The Person You Meet Does the Work
The assessment is not scoped by one person, executed by a junior team, and reviewed by a third. You deal with me from the first conversation through the walkthrough, and I write what you receive.
Your Information Stays Yours
We collect what an assessment requires and nothing beyond it. Handling, storage, and retention of anything you provide are stated in the engagement letter before the first document moves.
Findings Come With Their Basis
Every conclusion cites what it rests on. Where evidence could not be obtained, the assessment records that rather than crediting a control on assurance alone.
Get Started
The Principal's Introduction
One hour with the principal, at no cost. We walk through what the requirements actually ask of a firm your size, where firms like yours most often carry exposure, and what an assessment would and would not cover. You leave with a clearer view of your own position.