E

Evan Francen

Co-Founder

Puerto Vallarta, Jalisco, Mexico28 yrs 1 mo experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Founder of a leading information security consulting firm.
  • Authored a book on the information security industry.
  • Developed a widely used information security risk assessment tool.
Stackforce AI infers this person is a seasoned leader in Information Security Consulting with a focus on risk management and compliance.

Contact

Skills

Core Skills

TrainingCisspInformation Security ManagementRisk ManagementIncident Response

Other Skills

TeachingComputer ForensicsComputer SecurityData CenterData SecurityDisaster RecoveryEnterprise Risk ManagementFirewallsGLBAGovernanceHIPAAIDSIPSISO 27001IT Security Best Practices

About

Founder of FRSecure (2008). FRSecure is a world-class, multi-national information security consulting and management company based in Minnesota. Author of The Information Security Industry is Broken (June 2018). Prior to establishing FRSecure, spent more than 15 years as an information security and corporate leader in both private and public companies including Jasc Software, US Bank (USB), Wells Fargo (WFC), United Health (UHN), Corel Corporation (CREL), Mattersight Corporation (MATR), MGI Pharma (MOGN) and Eisai Ltd (TSE). Extensive experience in designing solutions to complex information security problems. As chief executive at FRSecure, I am responsible for driving business results through: - Employee satisfaction - Attracting and keeping good people - Client satisfaction - Supporting a fun and unique culture - Consistent financial performance Other: - Well-versed in governmental and industry-specific frameworks, regulations, standards and guidelines including NIST CSF, ISO/IEC 27000, FISMA, HIPAA, GLBA, PCI-DSS, FDA CFR Part 11, SOX and COBIT. - Chief designer of the FISA™ information security risk assessment and the FISASCORE®. FISASCORE® is the definitive measurement of information security risk used by more than 500 companies - Presented at hundreds of information security conferences and workshops; topics ranging from social engineering, to risk management, to incident response. - Written more than 700 articles about various information security topics. - Developed and taught numerous information security courses, including the FRSecure Mentor Program that mentors more than 300 professionals each year. - Featured in dozens of television and radio interviews with noted organizations such as NBC, USA Today, and CBS Radio. - Led investigations into noteworthy and much-publicized information security breaches. - Provided expert information security advice in numerous high-profile legal proceedings.

Experience

28 yrs 1 mo
Total Experience
3 yrs 7 mos
Average Tenure
18 yrs 3 mos
Current Experience

Security shit show

Co-Host w/Ryan Cloutier and Chris Roberts

May 2020Sep 2022 · 2 yrs 4 mos

  • Weekly live show with real talk about information security industry challenges. No holding things back, and everything/anything goes (except disrespect).

Unsecurity podcast

Co-Host w/Brad Nigh

Nov 2018Jul 2022 · 3 yrs 8 mos · Greater Minneapolis-St. Paul Area

  • Host the UNSECURITY Podcast with FRSecure's Brad Nigh.
  • About the UNSECURITY Podcast:
  • Weekly information security podcast airing Monday mornings hosted by Evan Francen and Brad Nigh. In a unique focus on protecting personal information, Evan and Brad discuss information security as an issue that includes cyber security, physical security, as well as administrative controls. Evan is the CEO of FRSecure and the author of the book UNSECURITY (publish date December, 2018). Brad is the Director of Consulting at FRSecure and a 20+ year veteran of the industry.

Forbes technology council

Member

Apr 2018Aug 2020 · 2 yrs 4 mos

Securitystudio

Founder and CCO (Chief Curiosity Officer)

Jan 2017Present · 9 yrs 3 mos · Greater Minneapolis-St. Paul Area

  • Overall responsibility for the success of the SecurityStudio organization including the development, adoption, and maintenance of business plans related to SecurityStudio and the S2 platform, including (but not limited to), S2Score, S2Org, S2Vendor, S2Me, S2Team, S2School, and S2Gov.
  • The S2 platform and related tools are required for the creation and maintenance of organizational and personal information security risk scoring (S2Score). The S2Score is the definitive information security risk score; calculated on a scale of 300 - 850.
  • We believe that every organization, big or small, should be aware of their most significant information security risks. Drawing on more 20 years of experience, SecurityStudio developed the S2Score and assessment processes to identify and address Information Security risks through a standardized, consistent and efficient process. Leveraging our tools and methodology, we enable trusted partners to help their clients obtain a clear vision into their most significant information security risks and needs. We provide our partners with a turn-key security assessment process and trained security analysts who are on duty to assist with any questions or to provide expert guidance.

Target

Consultant to the Special Litigation Committee

Jan 2014Jun 2015 · 1 yr 5 mos · Minneapolis, Minnesota, United States · Hybrid

  • Updating soon.

Security group inc.

Chief Security Officer and Board Member

Jun 2012Mar 2015 · 2 yrs 9 mos · Minneapolis, Minnesota

  • Developing industry information security solutions and standards for broad industry adoption.
Computer ForensicsEnterprise Risk ManagementFirewallsGovernanceIncident ResponseInformation Security+17

Cloudcover, ltd.

Board of Advisors, Member

May 2011Oct 2012 · 1 yr 5 mos · Greater Minneapolis-St. Paul Area

Frsecure cissp mentor program

Creator and Instructor

Mar 2010Present · 16 yrs 1 mo · Global · Remote

  • Updating soon.
TrainingTeachingCISSPComputer ForensicsComputer SecurityData Center+38

Frsecure llc

Founder and CCO (Chief Curiosity Officer)

Jan 2008Present · 18 yrs 3 mos · Greater Minneapolis-St. Paul Area

  • Lead a dynamic and growing information security consulting company.
  • Own the culture of the FRSecure business.
  • Work closely with corporate/organizational leadership to define, develop, and implement information security strategy that manages acceptable information security risks and aligns with business objectives.
  • Provide thought and practical leadership to other information security professionals within our industry.
  • Develop and maintain numerous information security risk assessment and management methodologies that differentiate FRSecure from our competition:
  • Information Security Assessments
  • Compliance Assessments (i.e. HIPAA, GLBA, etc.)
  • Customer Required Assessments
  • Internal Network Vulnerability Assessments
  • External Network Security Assessments
  • Penetration Testing
  • BC/DR Plans
  • Policy Creation
  • Outsourced Security Resources
  • Information security training and awareness
  • CISSP certification training
  • Incident response
  • Provide strategic and day-to-day direction to a team of highly-skilled information security consultants.
  • Oversee and ensure quality of all FRSecure deliverables.
  • Active information security public preacher/speaker and evangelist.

Mgi pharma

Director of Information Security/Information Security Officer

Oct 2006Jan 2009 · 2 yrs 3 mos

  • Designed, developed and implemented MGI PHARMA’s first formal information security program based on a thorough analysis of risk to MGI’s information resources, industry standard best practices and various governmental rules and regulations including Sarbanes-Oxley (SOX) and FDA 21 CFR Part 11.
  • Led numerous information security control projects including policy, standards and procedures development, training & awareness, laptop encryption, data in transit and at rest encryption, network access control, automated patching, secure configuration standards, internal and external security audits, and disaster recovery planning.
  • Provided direction to a highly skilled team of engineers that substantially improved MGI’s network and server infrastructure by implementing and supporting scalable and highly-available solutions

Eloyalty corporation

Director of Information Security

Jan 2006Oct 2006 · 9 mos

  • Developed, implemented, and managed eLoyalty’s first formal information security program, a progressive information security life-cycle program that met the needs of our business, customers, and various governmental and industry regulations

Unitedhealth group

Information Security Consultant

Oct 2005Jan 2006 · 3 mos

  • Technical project manager dedicated to a project to deploy full-disk encryption to 46,000 laptops across six business divisions within UnitedHealth, to address data at rest HIPAA concerns.
  • Coordinated all aspects of the project, including vendor selection, testing, deployment strategies, end-user support, and back-end architecture design

Us bank

Data Security Consultant III

Mar 2005Oct 2005 · 7 mos

  • Develop, implement and support enterprise-level solutions created to reduce the impact of realized threats, and decrease the number of vulnerabilities in an environment that spans more than 100,000 computers and devices
  • Respond to, investigate, and provide remediation to a wide variety of realized security incidents, including DDoS attacks, network intrusions, phishing and Internet fraud attacks, and unauthorized access attempts among many others
  • Lead Threat and Vulnerability team projects, including VISA CISP Auditing and Logging Remediation for 532 servers, and GLBA Intrusion Detection Monitoring of 86 host intrusion detection systems and 31 network intrusion detection systems
  • Lead forensic investigations into embezzlement, ethics violations, computer misuse, Internet abuse, email misuse, and other InfoSec policy violations
  • Consult with all levels of the organization in regards to security issues, interpretations and reviews

Jasc software

Information Security/Network Services Manager

Mar 2000Mar 2005 · 5 yrs

  • Jasc made PaintShop Pro
  • Designed, developed, implemented and managed all aspects of technical and non-technical security within the network management facilities and IP network infrastructure including data center, management center, and administrative areas
  • Started a company-wide communication initiative in an effort to provide both formal and informal dialog between Information Services and the department managers with the ultimate goal of providing better service to our customers
  • Developed an all-encompassing and fully redundant alerting and monitoring architecture utilizing local and off-site sensors.
  • Maintained 99.9989% availability while providing for 3.6 billion web hits, 122 million trial downloads, and 556 thousand ecommerce orders through our Internet architecture
  • Responsible for analyzing, reporting on, and effecting change in the state of Internet and local network security

Valley view microsystems

Senior Consultant

Jan 1999Jan 2000 · 1 yr

International decision systems

Windows Network Administrator

Jan 1998Jan 1999 · 1 yr

Education

University of Minnesota

Geology

Jan 1988Jan 1990

Stackforce found 100+ more professionals with Training & Cissp

Explore similar profiles based on matching skills and experience