Architecture. Governance. Organizational change.

Make security
work.

I help organizations resolve the technical and organizational barriers that keep cyber risk in place.

Connecting security architecture, governance, and the people responsible for change.

Technical depth. Organizational insight. Measurable progress.

2–10 days
Patch latency for high-value systems at a defense contractor, down from more than two months.
6 people · ~$3M
Team leadership and security tooling and team budget responsibility.
Strategy to execution
CISO responsibilities, enterprise architecture, and security consulting experience.

01 / Selected work

Change the conditions.
Move the work forward.

Security improvements depend on technology, operating processes, and people who can act. These examples show how I connect them.

Defense contractor / Organizational change

Making patching a shared responsibility

More than two months 2–10 days

Patch latency for high-value systems

Context & constraint
Patching crossed departmental boundaries and depended on longstanding process constraints.
My contribution
I built a coalition across infrastructure, change management, security, and development to address the dependencies holding remediation back.
Result & lesson
The collaborative effort helped reduce patch latency for high-value systems from more than two months to two–ten days. Improving the operating process made the technical work achievable.

Oil and Gas Services / Program leadership

Turning security priorities into a functioning program

More than 80% reduction

Third-party software vulnerabilities, for most endpoints

Context & constraint
Security initiatives needed forward progress and a clearer way to communicate and manage risk.
My contribution
With CISO responsibilities, I built and executed program strategy, developed a centralized risk management function, led a team of six, and owned approximately $3M in security tooling and team budget.
Result & lesson
The team reduced third-party software vulnerabilities by more than 80% for most endpoints. Clear priorities, accountable ownership, and technical delivery made program improvements tangible.

Healthcare / Security architecture

A modernization path that respects operations

An actionable roadmap

Delivered network modernization strategy

Context & constraint
A healthcare organization needed network hardening that accounted for both conventional IT and life-critical equipment.
My contribution
I developed current- and future-state comparisons, made the tradeoffs explicit, and created a phased migration roadmap around operational constraints.
Result & lesson
I delivered a strategy and implementation path suited to the environment. The engagement’s result was the roadmap; deployment and downstream outcomes were outside that delivered scope.

02 / Approach

Understand the whole problem.
Make change achievable.

I trace security problems across the systems, processes, and decisions that sustain them. Then I help teams agree on what needs to change, who owns it, and what progress will look like.

  1. Understand

    Map material exposures, technical dependencies, business constraints, and decision paths.

    What is keeping the risk in place?

  2. Align

    Establish an accountable sponsor, owners, priorities, and success criteria.

    Who can decide, and who can act?

  3. Deliver

    Sequence improvements so operational teams have the capacity to implement and maintain them.

    What needs to happen first?

  4. Verify

    Examine whether the change improved the intended condition, and adjust based on the evidence.

    What shows that it worked?

Risk decisions need accurate evidence and accountable ownership. People need to be able to report bad news early and challenge assumptions without being punished for doing so.

03 / Writing & talks

The human side of security decisions.

How people assess evidence, share information, and respond to change shapes whether security works.

Recorded talk / Cognitive security

A Brief Introduction to Cognitive Warfare

A look at how adversarial influence targets the way people reach conclusions. For security leaders, it raises practical questions about testing assumptions and protecting the quality of decisions.

Adversarial manipulation is distinct from ordinary organizational resistance. Understanding that distinction helps keep both discussions useful.

Find the recording & resources on LinkedIn Read the conference coverage

Independent study / Questions I’m exploring

Human factors in cybersecurity governance

My independent study connects organizational leadership and cognitive psychology to risk reporting, stakeholder trust, and the adoption of security controls.

  • What happens to risk reporting when bad news is punished?
  • How do decision rights and incentives affect remediation?
  • What makes a security control practical to adopt?

These are ongoing research questions, not a validated methodology.

Follow my writing on LinkedIn

04 / About & contact

Technical depth.
A practical view of change.

I’m Stephen Cravey, a cybersecurity leader who helps organizations move stalled security programs forward. I combine deep technical experience with risk governance and an understanding of how people and organizations change.

My experience includes CISO responsibilities at a major Oil and Gas services firm, enterprise security architecture at a defense contractor, and security strategy and delivery at Accenture. My technical foundation spans software, networks, infrastructure, and security architecture.

I use that depth to examine assumptions and make tradeoffs clear. I work closely with the people responsible for implementation, because lasting improvement depends on their knowledge, cooperation, and ability to act.

Education
MSc in Information Security
Royal Holloway, University of London
Certification
CISSP
Location
Houston, Texas · National remote and Houston-area opportunities