Hi, I'm Rachel. For more than 25 years I've led information security, governance, risk, and compliance work, including over a decade advising boards and executive teams at the CISO level. Today I serve healthcare organizations, higher education institutions, and growing businesses as their fractional CISO, bringing the trusted security leadership that regulators, insurers, and boards expect, in a way that fits your mission, your people, and your budget.
Regulations like the HIPAA Security Rule and the GLBA Safeguards Rule require a designated, qualified individual accountable for your information security program. I fill that role on a retainer basis, at a fraction of the cost of a full-time executive.
I've spent more than 25 years in information security, governance, risk, and compliance, including over a decade as a CISO-level advisor to boards and C-suite leadership. Today I advise a portfolio of organizations across healthcare, higher education, and other regulated sectors as a fractional CISO. In 2025 I was recognized as one of the Top 25 Women CISOs in the United States, and I regularly bring that perspective to keynote stages at cybersecurity conferences nationwide.
My specialty is right-sized security programs for organizations under real regulatory pressure but without enterprise budgets: community health providers navigating HIPAA and 42 CFR Part 2, higher education institutions facing the GLBA Safeguards Rule and Department of Education oversight, and growing businesses whose cyber insurers keep raising the bar.
I believe security leadership should make your organization's mission easier, not harder: practical controls, honest risk conversations, and documentation that satisfies the people who audit you.
If your organization handles protected data, answers to regulators or accreditors, and doesn't have a dedicated security executive, this practice was built for you.
If you've landed on this page, chances are security has been on your mind: a question from your board or an auditor, a cyber insurance renewal that got harder, or simply the sense that someone should own this and no one quite does. You're in the right place. My work is helping organizations like yours turn that worry into a clear, manageable plan, without the cost or complexity of a full-time security executive. When you're ready, I'd love to hear your story.
A 30-minute conversation with no pitch deck and no pressure. Tell me how security is handled today, and I'll tell you honestly whether a fractional CISO makes sense for your organization.
Book Time on My Calendar