George Bakalov
George Bakalov
CvCISO, CC
Senior Consultant
George Bakalov is uniquely adept at aligning security initiatives with organizational goals stemming from his many years of working with distributed, cross-functional teams and a focus on cybersecurity, risk management and regulatory compliance.
Certifications
- Certified virtual Chief Information Security Officer (CvCISO)
- Certified in Cybersecurity (CC)
- Certified in Cybersecurity from the University of Wisconsin
Career Accomplishments
- Designed and implemented comprehensive information security programs that enhanced the overall security posture and operational resilience
- Identified and mitigated project risks, resolving issues swiftly to avoid delays or cost overruns
- Contributed to strategic initiatives by participating in the development and execution of company strategies related to client delivery and service offerings
- Optimized high-quality delivery by implementing quality control measures to ensure services met or exceeded client expectations
- Gathered and analyzed customer feedback to continually improve service delivery and client satisfaction
Skills and Expertise
- Client Delivery, including client relationship management, project management, quality assurance and strategic planning
- Executive Advisory. Provides strategic guidance to the executive leadership team on information security risk management, leading to informed decision-making and improved risk mitigation
- Reporting and Metrics Capabilities. Develops reporting capabilities based on risk metrics as defined by the executive leadership team
- Policy and Procedure Development. Authors and enforces security policies and procedures, facilitating the seamless integration of the security program across the organization
- NIST Compliance Achievement. Directs an organization through NIST compliance as a self-reporting Managed Service Provider, ensuring adherence to industry standards and best practices
- Risk Management and Remediation. Conducts thorough risk assessments and managed remediation roadmaps, achieving high comprehensive organization level risk scores based on S2SCore
- Security Stack Management. Oversees the selection, implementation, and maintenance of the security technology stack, optimizing the company’s defense capabilities
- Cybersecurity Awareness Training. Develops and delivers cybersecurity training programs for employees and customers, significantly improving security awareness and behavior
- Incident Response Preparedness. Leads tabletop exercises to enhance incident response readiness, ensuring rapid and effective responses to potential security incidents. Develops incident triage process and documentation for service desk and the security team
- Security Offerings Development. Plays a key role in developing and marketing new security services, streamlining the on-boarding process for new customers and driving revenue growth
- Client Collaboration: Partners with CIOs to support compliance initiatives, including HIPAA and PCI-DSS attestation gap analysis and remediation, ensuring customers met regulatory requirements
- Ransomware Demonstration. Designs and presents a live ransomware simulation, demonstrating advanced threat tactics and defenses
Professional Affiliations
- International Information System Security Certification Consortium (ISC2)
- Information Systems Audit and Control Association (ISACA)
- CvCISO CommUnity, Minnesota chapter
How Can We Help?
Our advisory, consulting and second-party audit services are tailored to each company we serve.
- Trust
- Plain Dealing
- Tailored Services
- Safety First
- Attention to Details
© JBW Group International, LLC | A Member of Griffin Family Companies | Privacy Policy