Security and operating leadership for organizations that cannot afford to fail
I am Robert Keefer. For 25 years I have built the programs mission-driven organizations run on: security, privacy, vendor risk, and the compliance and governance infrastructure that holds them together. I translate risk into decisions boards can act on, and I have done it in enterprise, healthcare, and the social sector. I work in three ways now: in the chair, at the table, and on the page.
Security and operating leadership
Programs built from nothing and programs inherited mid-audit. CISO, COO, and chief of staff seats at organizations where the back office is the mission's foundation: compliance, vendor management, privacy, policy, and budget. Nonprofit and healthcare depth, GDPR and HIPAA fluency, and the habit of explaining all of it to a non-technical board.
Boards and committees
Risk and governance oversight for mission-driven organizations. I have sat on both sides of the audit table, which is the shortest way to say I know what a committee needs to see.
Writing
Mission Critical, a practitioner's guide to building a serious security program on a mission budget, with a volunteer board. In progress. Shorter notes live at insights.rmkeefer.com.
Enterprise, healthcare, and the social sector, most recently as a fractional CISO to mission-driven organizations.
Via a proactive GDPR program built before the regulation applied, not after a finding.
Down from a regular occurrence, and held there for years, at one of the country's largest policy nonprofits.
Critical
Written for the organizations nobody writes for
A practitioner's guide for nonprofits, healthcare providers, advocacy groups, and the foundations that fund them: how to build a serious security program on a mission budget, with a volunteer board, inside a culture that resists the very controls meant to protect it.
Excerpts on requestNotes from the field
Shorter pieces on governance, risk, and what a board actually needs to see, published at insights.rmkeefer.com.
The board approved that risk. They just did not know they did.
Every unfunded control is an accepted risk. The question is whether anyone told the people who accepted it.
ReadThe model didn't escape. Someone left the door open.
Most AI incidents are ordinary security failures wearing a new costume: weak credentials and misconfiguration.
ReadThe people your breach harms are not your employees.
When the data belongs to the vulnerable, the harm lands on them, not on the organization that lost it.
ReadContact
Selectively considering full-time security and operating leadership roles (CISO, COO, chief of staff) and board appointments. Speaking and teaching enquiries welcome.