Turning Security Operations Into Board-Ready Metrics

Virtual Council

March 17, 2026 - National

Panelists

Timothy Swope Lighthouse Cyber Risk Management
Timothy Swope

CISO

Lighthouse Cyber Risk Management

About Me

Mr. Swope brings over 20 years of experience in IT Project Management, BI Solutions Development, IT Security, IT Controls (CoBIT, SOX 404/MAR, etc) IT Risk Management, and HealthCare Compliance, to both the public and private sectors. His focus is on identifying gaps relating to key IT security processes and the implementation of IS Security and Risk Management programs to Health Care, Pharmaceutical and various commercial clients. Has a proven track record of delivering the following: • Interpreting and applying 21 CFR Part 11, GLP, GMP, GCP, and QSR regulations • MDM and Data Governance • Identity Access Management • HIPAA Risk Assessments and GAP analysis • Information Assurance Program Management - SCRUM, AGILE, SDLC, Six Sigma • Implemented large security, risk and compliance initiatives of SOX-404 IT, HIPAA/HITECH, including security policies, procedures and controls. • "Big Data", Data Management and Health Care Data Analytics • Federal Information Security Management Act (FISMA) Compliance Reviews • Implemented the security standards - 45 CFR Parts 160, 162, and 164 Health Insurance Reform: Security Standards; Final Rule He has supported these Information Assurance and IS Security initiatives for organizations that include: Excellus BCBS, Medimmune/Astra Zeneca, ENDO Pharmaceuticals, Novo Nordisk, Daiichi-Sankyo Solutions, Catalent Pharma Solutions, Johnson and Johnson, District of Columbia Government office of the Chief Financial Officer, District of Columbia Water and Sewer Authority, City of Richmond, Virginia Department of Public Utilities, Virginia State Department of Health, and the Kentucky Department of Health Services, as well as the U.S. Department of Labor.

March 17, 2026

Agenda

All times Eastern Time

3:00 PM - 4:15 PM

Turning Security Operations Into Board-Ready Metrics

Security and compliance teams collect more information than ever—from control test results and audit evidence to cloud and operational signals. But when this information reaches the board, it often fails to answer the questions executives care about most: What risk do we carry today? Are controls working as intended? How are AI systems and AI-driven workflows impacting our risk posture? And what has changed since the last review?

For organizations navigating M&A, that last question carries the highest stakes — inherited control gaps and unknown compliance posture demand answers boards can trust, not point-in-time snapshots assembled under pressure.

This executive council brings together security leaders from AWS, Drata, and Emburse to discuss how leading organizations are building board-ready security and compliance metrics grounded in continuous assurance. The conversation will focus on moving beyond activity reporting to metrics that reflect control health, risk exposure, and verifiable assurance.

Attendees will learn how leading teams translate continuous control monitoring and centralized evidence into clear, defensible metrics that boards trust. We’ll share practical approaches to simplifying board-level reporting, strengthening executive confidence, and enabling faster, better-informed decisions—without adding manual reporting overhead.


Together With