Norman Kromberg
Chief Information Security Officer (CISO) | VCISO | Fractional CISO | CISO Advisor / Mentor | Governance Risk & Compliance (GRC) SME | Business Aligned Security / GRC Innovation
- Role
- Member of the Board of Advisors at Trustcloud
- Location
- Omaha, NE, US
- LinkedIn followers
- 500 followers
About Norman Kromberg
Most cybersecurity leaders start with technology and learn business later.I started with business, and learned security where risk becomes real.My career began in banking and federal regulation as a National Bank Examiner with the Office of the Comptroller of the Currency, where I evaluated technology controls long before cybersecurity became a boardroom topic. That experience shaped how I lead today: security succeeds only when it speaks the language of strategy, finance, and growth.I operate as a translator between worlds — executives, boards, regulators, technologists, and clients — turning complex risk into decisions organizations can confidently act on.Over the past three decades, I have built and transformed security, risk, and audit programs across more than 100 organizations in over 20 industries, ranging from small firms to global enterprises exceeding employees. I’ve served as CISO, audit executive, and trusted advisor, helping organizations move from reactive security to business-aligned resilience.What I do best:Build security programs that enable revenue and trust, not frictionAlign cybersecurity investment with measurable business outcomesMature governance and risk programs executives actually understandSimplify regulatory and compliance complexity into operational realityLead calmly and decisively when incidents test leadership mostI’ve developed enterprise security programs from scratch, doubled organizational security maturity within two years at multiple companies, reduced audit costs while expanding coverage, and led incident response efforts involving regulators, law enforcement, insurers, and executive leadership — including coordination that recovered $2M in diverted funds and prevented financial loss in active business email compromise events.Today, I serve as a Virtual CISO, guiding multiple organizations simultaneously through security strategy, investment decisions, and maturity transformation. Exposure to hundreds of environments gives me a market-wide lens on what actually works — and what creates noise.My philosophy is simple:Security is not about fear.It is about trust.And trust is built when security understands the business it protects.Outside the office, I recharge through great food and wine, Nebraska athletics, music, film, and Broadway — reminders that creativity and curiosity remain the strongest drivers of innovation and leadership.
Experience
Member of the Board of Advisors
Jul 2024 — Present · Omaha, NE, US
Education
University of Nebraska-Lincoln
BS, Finance and Management
1981 — 1985
Skills
- Application Security
- Auditing
- Governance
- Ffiec
- Business Process Improvement
- Compliance
- Offshore Management
- Business Continuity
- IT Risk
- Project Portfolio Management
- Compliance Management
- Information Security
- Data Security
- Enterprise Risk Management
- Testing
- Security Awareness
- Sox
- Outsourcing
- Risk Management
- IT Management
- Information Security Management
- Security Audits
- Itil
- Risk Analysis
- Security
- Internal Audit
- Iso 27001
- Pci Dss
- Risk Assessment
- Sarbanes-Oxley Act
- Information Security Policy
- Hipaa
- IT Outsourcing
- Sas70
- Disaster Recovery
- Computer Security
- Operational Risk Management
- IT Governance
- Audit
- Process Improvement
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.