Tom Garrubba, Senior Director/CISO, is an internationally recognized subject matter expert, lecturer, author, and blogger on third party risk, and is the head instructor for the Certified Third Party Risk Professional (CTPRP) certification program. He is a contributor to Future of Sourcing, blogged for the Huffington Post’s Business section, and for Government Health IT, ISACA, Risk.net, and numerous eGRC websites. Previously, Tom was the Senior Privacy Manager at a Fortune 10 healthcare company where he established policies and procedures governing their vendor assessment program, overseeing all assessments for existing and potential third party service providers who were exposed to personally identifiable information (PII), protected health information (PHI), credit card/card holder (PCI), and proprietary data. Tom has over 20 years experience in IT security and privacy controls, as well as audit and compliance in both private industry and public consulting. You can also connect with Tom via LinkedIn.
Our Core Team
Recent Blogs & Resources
Failed Risk Controls – The Wells Fargo Saga, Part Two
By: Bob Jones, Senior Advisor, The Santa Fe Group and Gary Roboff, Senior Advisor, The Santa Fe Group The Sales Practices Report released…
Tone at the Top: Culture Counts – The Wells Fargo Saga
The Santa Fe Group and the Ponemon Institute recently concluded a research study examining tone at the top and the importance of culture within…