Turning Security Operations Into Board-Ready Metrics

Virtual Council

March 17, 2026 - National

Attend this event

Company is Required

By clicking the “Register" button, you are agreeing to the Privacy Policy and Terms of Use

Panelists

Jeevan Lobo Citi
Jeevan Lobo

VP Security & Governance

Citi

About Me

Citigroup Inc., a diversified financial services holding company, provides various financial products and services for consumers, corporations, governments, and institutions worldwide. The company operates through two segments, Citicorp and Citi Holdings. The Citicorp segment offers traditional banking services to retail customers through retail banking, commercial banking, Citi-branded cards, and Citi retail services. It also provides various banking, credit card lending, and investment services through a network of local branches, offices, and electronic delivery systems. In addition, this segment provides wholesale banking products and services, including fixed income and equity sales and trading, foreign exchange, prime brokerage, derivative services, equity and fixed income research, corporate lending, investment banking and advisory services, private banking, cash management, trade finance, and securities services to corporate, institutional, public sector, and high-net-worth clients. As of December 31, 2016, it operated 2,649 branches in 19 countries. The Citi Holdings segment provides consumer loans; and portfolio of securities, loans, and other assets. Citigroup Inc. was founded in 1812 and is based in New York.

Timothy Swope Lighthouse Cyber Risk Management
Timothy Swope

CISO

Lighthouse Cyber Risk Management

About Me

Mr. Swope brings over 20 years of experience in IT Project Management, BI Solutions Development, IT Security, IT Controls (CoBIT, SOX 404/MAR, etc) IT Risk Management, and HealthCare Compliance, to both the public and private sectors. His focus is on identifying gaps relating to key IT security processes and the implementation of IS Security and Risk Management programs to Health Care, Pharmaceutical and various commercial clients. Has a proven track record of delivering the following: • Interpreting and applying 21 CFR Part 11, GLP, GMP, GCP, and QSR regulations • MDM and Data Governance • Identity Access Management • HIPAA Risk Assessments and GAP analysis • Information Assurance Program Management - SCRUM, AGILE, SDLC, Six Sigma • Implemented large security, risk and compliance initiatives of SOX-404 IT, HIPAA/HITECH, including security policies, procedures and controls. • "Big Data", Data Management and Health Care Data Analytics • Federal Information Security Management Act (FISMA) Compliance Reviews • Implemented the security standards - 45 CFR Parts 160, 162, and 164 Health Insurance Reform: Security Standards; Final Rule He has supported these Information Assurance and IS Security initiatives for organizations that include: Excellus BCBS, Medimmune/Astra Zeneca, ENDO Pharmaceuticals, Novo Nordisk, Daiichi-Sankyo Solutions, Catalent Pharma Solutions, Johnson and Johnson, District of Columbia Government office of the Chief Financial Officer, District of Columbia Water and Sewer Authority, City of Richmond, Virginia Department of Public Utilities, Virginia State Department of Health, and the Kentucky Department of Health Services, as well as the U.S. Department of Labor.

Agenda

All times Eastern Time

3:00 PM - 4:15 PM

Turning Security Operations Into Board-Ready Metrics

Security and compliance teams collect more information than ever—from control test results and audit evidence to cloud and operational signals. But when this information reaches the board, it often fails to answer the questions executives care about most: What risk do we carry today? Are controls working as intended? How are AI systems and AI-driven workflows impacting our risk posture? And what has changed since the last review?

For organizations navigating M&A, that last question carries the highest stakes — inherited control gaps and unknown compliance posture demand answers boards can trust, not point-in-time snapshots assembled under pressure.

This executive council brings together security leaders from AWS, Drata, and Emburse to discuss how leading organizations are building board-ready security and compliance metrics grounded in continuous assurance. The conversation will focus on moving beyond activity reporting to metrics that reflect control health, risk exposure, and verifiable assurance.

Attendees will learn how leading teams translate continuous control monitoring and centralized evidence into clear, defensible metrics that boards trust. We’ll share practical approaches to simplifying board-level reporting, strengthening executive confidence, and enabling faster, better-informed decisions—without adding manual reporting overhead.


Together With