Some companies see cybersecurity as a cost center. We see things a little different. LEARN MORE >

Our seasoned Chief Information Security Officers bring strategic guidance to your leadership team, helping you right-size your cybersecurity operations.


A full suite of manage solutions from our US-based Security Operations Center (SOC)—staffed 24x7x365 by a full team of experienced analysts.


You can count on our IR team to contain the damage from a cyberattack, investigate the origins of the breach and build better protections for the future.


Why Inversion6

With an abundance of solutions and providers, the task of choosing the right option is critical and can sometimes be overwhelming.

Contact Us
BLOG

6 Questions with Troy Stairwalt

city scape with code above it

Like the rest of our CISO advisory team, Troy Stairwalt is a walking example of what our CISO solutions deliver. How else can a growing small business with a stretched security budget afford to hire the former CISO of Westfield Insurance and the State of Wisconsin?

We sat down with Troy to discuss his diverse industry background, his passion for helping people make sense of cybersecurity and his predictions for the future.


1. You've spent your career leading security teams inside large organizations. What drew you to the advisory side of the field, and to Inversion6 specifically?

I have been a fan of Inversion6 for more than a decade, originally as a client. When I was promoted to my first CISO role, our team evaluated several reputable firms and selected Inversion6 as our strategic partner. Over the years Inversion6 has consistently focused on doing the right things for the right reasons. Plus, "Eliminate Reactive" matches how I approach risk. I am proud to join this talented team.

My personal reason for joining Inversion6 is more direct. I do not like bullies.

Criminals hit soft targets of opportunity. That means the damage lands hardest on those least able to absorb it. Plus, victims are often concerned about brand impact or regulatory repercussions, or simply feel embarrassed, so they say nothing, which in turn provides no warning to the next target.

I spent most of my career in the financial services industry, but a CISO role at a children's hospital also gave me firsthand understanding of the challenges across the healthcare industry: assessing risk and architecting controls with limited funding in a high-risk environment, where loss of systems and services directly impacts quality of care. Then as CISO for the State of Wisconsin, you add in the government challenges of dealing with many state entities and municipalities with very tight budgets and limited security staff.

Across all these roles, I have seen that one of the greatest challenges is not a lack of understanding or will. It is making well informed decisions early enough to make a difference. Inversion6 is built to help with that, which is why their mission resonates with me.


2. For a company that can't justify a full-time CISO, what does bringing in a fractional CISO actually look like in practice?

The relationship starts with an honest conversation about where you are and where you want to be, even if you're not quite sure yet. We can walk through the state of cybersecurity in your industry, trends in the market, relevant examples and data and any questions you may have.

Second, we run a current state assessment of your business outlining where you are right now. The assessment acts as a baseline and an important basis for candid conversations around your vision and the steps to get there. No two organizations are alike, and we pride ourselves on establishing trusted relationships in order to uncover and openly discuss the best options for you.

Next we establish target state maturity levels. The right target is often not the highest level available. Instead, we will discuss with you the level of cybersecurity maturity that is reasonable and prudent given the regulations that genuinely apply to your organization and what is truly mission critical.

Then we walk you through the alternatives, with pros and cons for your consideration. Most engagements have three or four credible paths, each with its own investment level and level of risk. Choosing the right one from a security, risk, and financial perspective creates a path specialized for your organization and your needs.

From there we right size the path toward appropriate security controls, resources and budget on a stable yet living roadmap. The agile nature of the roadmap is vital, given that the threat landscape, your business, regulatory requirements and even your risk tolerance may evolve over time. A stable basis is the key to fast change when and where you need it.

The appropriate security controls accomplish two jobs. First, they mitigate risk. Second, they provide artifacts that can be leveraged as evidence to demonstrate adherence to regulatory requirements. Many organizations run their security programs separately from their compliance efforts, which can result in two separate investment areas. Inversion6 helps you build your security program so compliance is a byproduct of ongoing operations rather than a reactive scramble to meet regulatory deadlines.


3. You've been a CISO in the private sector and for the State of Wisconsin. What surprised you most about the difference between protecting a government and protecting a business?

Government exists to provide services and resources for everyone who lives there. Keep the lights on. Keep the water running. Commerce, hospitals, schools, transportation, communications, public safety etc. It's all part of critical infrastructure and state government touches nearly all of it.

However, much of the infrastructure is privately owned and operated. So, one of the biggest challenges of the CISO role in state government is being accountable for outcomes you do not control.

In the private sector, security enables the business, so the work demands the same discipline and priority. Impact analysis, then a funding justification somebody can act on.

I found the second part harder in government.

In the private sector you can put a number on how much revenue is at risk and one executive can end the debate. In state government, every competing priority is also mission critical, budgets run on biennial legislative sessions rather than quarters, and thirty-six agencies hold independent statutory authority.

So you learn to lead through persuasion … and funding.

There is one thing the public sector does notably better. It talks. Other states told me what had gone wrong for them in unflattering detail, because a threat that hits one state will usually target the next. Private sector competitors rarely share that level of detail freely, and the silence costs all of us.


4. When you first sit down with a leadership team, what's the most common misconception you have to work through about what cybersecurity is actually for?

That the goal is perfection.

Leadership usually opens with some version of "are we secure." That's the wrong question. Secure is not a destination. It is a continual journey. The better questions are "what would stop this business, how long could we operate without it," and "what have we already decided not to fund."

The real goal is aligning controls to risk appetite and tolerance and right-sizing them against the regulations that actually apply and what is genuinely mission critical. That means a hospital and a professional services firm should not be running the same program.

What I most often see drive funding is an attack, a regulation, or trouble qualifying for cyber insurance. But all three are reactive. The organizations I admire most decided not to wait, and they tend to have the calmest conversations about risk.


5. Your recent work has moved into operational technology, critical infrastructure and AI risk. What emerging threats do you think leaders aren't paying enough attention to yet?

AI and quantum will accelerate the cyber arms race, for attackers and defenders alike.

Organizations with solid cyber hygiene can adopt AI, leverage the efficiency it offers and manage the residual risk to reasonable and prudent levels, because they already know what they own and who has access. But for those who don't have a solid foundation, AI will expose their vulnerabilities faster than they can respond.

Here's one question I would put to any leadership team today. What is your incident response plan for when an AI agent misbehaves? Not when it's attacked, but when it simply does something nobody anticipated. Could you detect it? Could you contain it?

Many organizations have handed AI agents access and credentials with no owner and no lifecycle management or monitoring. That's an issue considering we spent twenty ears learning to govern privileged human, process and application accounts. The encouraging part is we already know what the answer looks like. We simply have to apply it.


6. You teach and mentor the next generation of security professionals. For a leader who knows security needs to be a priority but isn't sure where to start, what's the first thing you tell them?

Learn to defend yourself.

I have studied several martial arts and there are some clear parallels. We train hoping we never have to fight, but we are prepared to defend ourselves and the people we care about when it becomes necessary.

Building a mature program isn't so different.

Adversaries look for soft targets. In cybersecurity, that's any organization missing foundational cyber hygiene.

Start with asset inventory. Know what you have, what is mission critical, where your sensitive data lives, and who has access to it. Then the question that matters most: could you identify and respond if something went wrong?

Another thing I teach. Being targeted is not shameful. Predators count on embarrassment to keep organizations and people quiet. That silence is what lets the same attack work on the next organization. Reporting is not an admission of failure. It's part of defending yourself, and everyone else.

Lastly, know who your trusted advisors are and bring in experts when the situation calls for it. No one has both the breadth and the depth to cover every aspect. I certainly don't.

Cybersecurity is truly a team sport. Attackers work the weakest link, but in a connected economy that weak link becomes everyone's problem. So, those of us who do this for a living need to teach others how to defend themselves. That's really what it's all about.


More from Troy


Hire a CISO you couldn't otherwise afford.

Inversion6's fractional CISO model gives growing organizations access to seasoned security leadership — an honest baseline, a right-sized target, and a living roadmap where compliance is a byproduct rather than a scramble.

LEARN MORE →