M&A Without Mayhem: Cyber Lessons from CISO Frank DePaola
Manage episode 480227651 series 3559712
Frank shares how building a playbook for consistent M&A integration became critical—not just for operations, but for cybersecurity and regulatory alignment. He details his framework built on the Three Cs: Cybersecurity (identity, MFA, EDR, cloud visibility), Compliance (mapping tools across frameworks like ISO, NIST, and CMMC), and Collaboration (unifying communications across platforms). That consistent process, he says, has gained the trust of legal, corporate development, and executive teams—and it's led to full integration across all subsidiaries.
Frank also breaks down how his team uses AuditBoard to map once and apply controls across all frameworks, creating scalability for compliance. He emphasizes the need to lead with tools you already own (like AD and Azure) before buying new ones, and why good GRC starts with simplicity and consistency. He’s passionate about hiring people with broad skill sets and investing in training, building a cybersecurity team that is both agile and deeply loyal.
As a former Army servicemember, Frank attributes much of his leadership style to military experience: from practicing extreme ownership to celebrating individual wins and leading with empathy. He argues that team diversity, training, and shared purpose are what set high-performing security organizations apart.
122 episodes