Turning Security Operations Into Board-Ready Metrics

Virtual Council

March 17, 2026 - National

Panelists

Ashley Hyman Drata Inc
Ashley Hyman

VP, Customer Experience

Drata Inc

About Me

Ashley Hyman is Vice President of Customer Experience at Drata, where she leads teams to deliver exceptional customer support and success across technology platforms. With a background in health promotion and behavioral science, Ashley is passionate about building customer-centric strategies that help clients achieve their goals while maximizing platform adoption and impact. She has extensive experience growing and mentoring teams, implementing best practices, and leveraging customer insights to drive strategic growth. Previously, as an early team member at Portfolium, she contributed to its successful acquisition by Instructure, guiding the full customer journey from business development to implementation and customer success. Ashley now applies this expertise to empower Drata’s clients and teams, ensuring scalable, innovative, and meaningful customer experiences.

Jessie Franks Skibbe AWS
Jessie Franks Skibbe

Principal Security Strategist

AWS

About Me

Jessie Franks Skibbe is a Principal Security Strategist at Amazon Web Services (AWS), where she leads complex security initiatives that drive broad organizational impact. She serves as a trusted advisor to AWS leadership and enterprise customers, developing innovative solutions for cloud adoption, regulatory compliance, and risk management. With over 25 years of experience across manufacturing, financial services, and healthcare, Jessie brings deep expertise in information technology, security, and compliance. She previously built AWS Security Assurance Services, LLC, a PCI QSA company, growing it into a global team serving over 250 regulated customers. Jessie’s leadership experience spans roles as Information Security Officer, Chief Compliance Officer, and Senior Vice President, enabling her to guide enterprise clients in addressing critical security challenges while shaping strategic security programs at AWS.

Timothy Swope Lighthouse Cyber Risk Management
Timothy Swope

CISO

Lighthouse Cyber Risk Management

About Me

Mr. Swope brings over 20 years of experience in IT Project Management, BI Solutions Development, IT Security, IT Controls (CoBIT, SOX 404/MAR, etc) IT Risk Management, and HealthCare Compliance, to both the public and private sectors. His focus is on identifying gaps relating to key IT security processes and the implementation of IS Security and Risk Management programs to Health Care, Pharmaceutical and various commercial clients. Has a proven track record of delivering the following: • Interpreting and applying 21 CFR Part 11, GLP, GMP, GCP, and QSR regulations • MDM and Data Governance • Identity Access Management • HIPAA Risk Assessments and GAP analysis • Information Assurance Program Management - SCRUM, AGILE, SDLC, Six Sigma • Implemented large security, risk and compliance initiatives of SOX-404 IT, HIPAA/HITECH, including security policies, procedures and controls. • "Big Data", Data Management and Health Care Data Analytics • Federal Information Security Management Act (FISMA) Compliance Reviews • Implemented the security standards - 45 CFR Parts 160, 162, and 164 Health Insurance Reform: Security Standards; Final Rule He has supported these Information Assurance and IS Security initiatives for organizations that include: Excellus BCBS, Medimmune/Astra Zeneca, ENDO Pharmaceuticals, Novo Nordisk, Daiichi-Sankyo Solutions, Catalent Pharma Solutions, Johnson and Johnson, District of Columbia Government office of the Chief Financial Officer, District of Columbia Water and Sewer Authority, City of Richmond, Virginia Department of Public Utilities, Virginia State Department of Health, and the Kentucky Department of Health Services, as well as the U.S. Department of Labor.

Upcoming events

Agenda

All times Eastern Time

3:00 PM - 4:15 PM

Turning Security Operations Into Board-Ready Metrics

Security and compliance teams collect more information than ever—from control test results and audit evidence to cloud and operational signals. But when this information reaches the board, it often fails to answer the questions executives care about most: What risk do we carry today? Are controls working as intended? How are AI systems and AI-driven workflows impacting our risk posture? And what has changed since the last review?

For organizations navigating M&A, that last question carries the highest stakes — inherited control gaps and unknown compliance posture demand answers boards can trust, not point-in-time snapshots assembled under pressure.

This executive council brings together security leaders from AWS, Drata, and Emburse to discuss how leading organizations are building board-ready security and compliance metrics grounded in continuous assurance. The conversation will focus on moving beyond activity reporting to metrics that reflect control health, risk exposure, and verifiable assurance.

Attendees will learn how leading teams translate continuous control monitoring and centralized evidence into clear, defensible metrics that boards trust. We’ll share practical approaches to simplifying board-level reporting, strengthening executive confidence, and enabling faster, better-informed decisions—without adding manual reporting overhead.


Together With