
Susan Richards
MSIT, CISM
Skills
Risk Management
Threat & Vulnerability Management
Compliance Assurance
Security Strategy & Optimization
About
I have the experience of building world-class Information Security programs from the ground up. Known as “Suecurity“, my superpower lies in transforming information security initiatives from concept to implementation.
As a Certified Information Security Manager (CISM) through the ISACA organization, I have proven expertise in InfoSec policy and governance strategies, information security program development and risk management strategies. I have used the FAIR model for quantifiable risk management assessments, including third party risk assessments for organizations.
I have worked with Legal and Privacy teams to conduct HIPAA risk assessments and audits, and been an advisor on international privacy and security strategies. I’ve facilitated numerous audits and assessments including HIPAA, HITRUST, SOC 2 Type 2 and ISO 27001.
Partnering with Cloud and Infrastructure teams has provided me with the opportunity to mature a comprehensive Threat and Vulnerability Management (TVM) program within the healthcare industry. My experience in this field has allowed me to implement secure strategies tailored specifically for cloud hosted environments. This has involved working with prominent cloud platforms such as AWS, Azure, and Google to ensure that the infrastructure is fortified against potential threats and vulnerabilities. Through careful planning and implementation, I have been able to enhance the security posture of the systems, enabling a safer and more resilient environment for critical healthcare operations.
I completed my MSIT at Lipscomb University, specializing in Information Security at the College of Computing & Technology. The program helped me integrate my work experience and establish a strong foundation for my IT strategy practice. During my practicum, I focused on conducting a HITRUST assessment and a SOC2 audit concurrently, identifying similarities and differences between the two compliance frameworks, and devising an effective approach to meet customer compliance assurance requirements.
Originally an application developer and database administrator, I have led Agile teams, worked with SecDevOps teams and have extensive risk management, compliance assurance and program management experience. I founded Sure IT with the goal of working with companies to assess and improve their Information Technology and Security strategies.
