25+ Years Security ExperienceEnterprise Security Leadership

Cybersecurity Leadership Conversations

Security isn't just technology—it's culture, leadership, and people

Cybersecurity Leadership Conversations

Featured in This Series

BS

Bob Shannon

CEO, Assured Performance 360

Experienced Executive Officer with a demonstrated history in professional training and coaching. Skilled in Public Safety, Emergency Management, and Organizational Development. Graduate of the Los Angeles Fire Department Leadership Academy and founder of the Las Vegas Fire/Rescue Leadership Academy.

Connect on LinkedIn
DP

Dan Pitre

President, Cloud Solutions Consulting

Cybersecurity strategist helping organizations build security-conscious cultures. Focused on making enterprise-level security accessible for small and mid-sized businesses.

Connect on LinkedIn

Episodes

We're Not Protecting Data—We're Protecting People
Part 112:51

We're Not Protecting Data—We're Protecting People

Bob Shannon, CEO of Assured Performance 360 and founder of the Las Vegas Fire/Rescue Leadership Academy, joins Dan Pitre to discuss why cybersecurity is fundamentally about protecting people, not just data. Drawing from decades of emergency management and leadership development experience, Bob shares how leadership principles from high-stakes environments apply directly to building security-conscious organizations.

Leadership mindsetCore valuesPsychological contractPeople-first security
When Employees Make Mistakes: Creating a Culture of Growth, Not Fear
Part 214:55

When Employees Make Mistakes: Creating a Culture of Growth, Not Fear

In Part 2, Bob Shannon and Dan Pitre explore what happens when employees make security mistakes—and why punishment-based approaches backfire. Learn how to build a culture of trust and resilience where people feel safe reporting incidents, leading to faster response times and stronger security posture through a growth mindset rather than fear.

Trust buildingGrowth mindsetIncident reportingChange managementOrganizational resilience

Part 3 Coming Soon

The conversation continues with a deep dive into balancing innovation and security.

Articles & Guides

In-depth analysis and compliance guidance for cybersecurity leaders.

Compliance10 min read

FTC Safeguards Rule for CPA Firms

Most CPA firms miscalculate their FTC Safeguards Rule obligations. The 5,000 consumer threshold counts individual records—not clients. Learn the 9 required elements and what they mean for your firm.

FTC SafeguardsCPA ComplianceGLBA
HIPAA7 min read

HIPAA 2026 Security Rule Changes

OCR's proposed HIPAA Security Rule overhaul eliminates addressable safeguards — everything becomes mandatory. Encryption, MFA, and 72-hour restore requirements will reshape healthcare compliance. Here's what's changing and how to prepare.

HIPAAHealthcare ComplianceSecurity Rule
CMMC6 min read

CMMC Phase 2 Deadline (November 2026)

Phase 1 is already enforcing. Phase 2 hits in 8 months. Most contractors aren't ready. Here's the four-phase timeline, Level 1 vs Level 2 requirements, and the 6 steps you should be taking right now.

CMMCDefense ContractorsCompliance
CMMC12 min read

CMMC Level 1 Self-Assessment Guide

15 controls. 59 assessment objectives. Zero room for POA&Ms. Here's what every defense contractor needs to know about achieving — and maintaining — their Level 1 compliance, from an RP who reviews these assessments every day.

CMMCLevel 1Self-Assessment
CMMC5 min read

CMMC Compliance Consulting

RP-credentialed CMMC compliance consulting for defense contractors. From Level 1 self-assessment support through Level 2 C3PAO preparation — with ongoing vCISO compliance leadership.

CMMCCompliance ConsultingLevel 1
CMMC8 min read

What Is a CMMC Registered Practitioner?

Roles, scope, and how an RP helps defense contractors prepare for CMMC compliance. Understand the CMMC ecosystem, what RPs can and can't do, and when to engage one.

CMMCRegistered PractitionerRP
Decision Framework8 min read

vCISO vs. Full-Time CISO

Compare virtual CISO and full-time CISO models side by side — cost, availability, compliance expertise, and when each makes sense.

vCISOCISOComparison
Services5 min read

vCISO for Healthcare

HIPAA-focused virtual CISO services for healthcare organizations — risk assessment, Security Rule compliance, breach preparedness, and OCR audit readiness.

vCISOHealthcareHIPAA
Resources15 min

HIPAA Readiness Checklist

Interactive self-assessment covering current HIPAA Security Rule requirements and proposed NPRM items. Evaluate Administrative, Physical, Technical Safeguards and Organizational Requirements.

HIPAAComplianceSelf-Assessment

Secure Your Organization's Future With a Partner You Can Trust

Schedule your complimentary strategy session today.