Cyber Risk Experience from the Boardroom to the Model

Freund Advisory Group is an independent advisory practice focused on cyber risk strategy and decision science. We help organizations measure risk, design better risk methodologies, challenge models and assumptions, modernize risk programs, and translate complex technical information into better business decisions.

The firm is led by Dr. Jack Freund, whose career has crossed many of the disciplines that now make up modern cyber risk management: security, enterprise risk, quantitative analysis, data science, GRC, third party risk, insurance, governance, and executive decision support.

Jack Freund

Jack Freund, Ph.D., is a cyber risk executive, author, researcher, and advisor with more than 20 years of experience in technology and cybersecurity risk management.

His career has included senior practitioner and executive positions across financial services, insurance, cybersecurity technology, and risk analytics. He has served as a Chief Risk Officer, led cyber risk methodology and quantitative modeling functions, built and operated enterprise technology risk programs, advised organizations implementing FAIR- and non-FAIR-based cyber risk quantification, and developed cyber risk methodologies incorporated into commercial technology platforms.

Practitioner

Jack has led technology and cyber risk programs within large and complex enterprises, with responsibilities spanning application risk, third-party risk, AI governance, cyber insurance, regulatory risk, records management, privacy, GRC, and second-line oversight.

That experience provides an important grounding for his advisory work. Risk methodologies ultimately have to operate inside real organizations, with imperfect information, limited resources, competing priorities, regulatory obligations, and executives who have decisions to make.

Methodologist

Jack is best known for his work in cyber risk quantification and risk methodology.

He is coauthor with Jack Jones of Measuring and Managing Information Risk: A FAIR Approach, which helped establish FAIR as a leading approach to quantitative cyber risk analysis. His subsequent work has included quantitative and qualitative model development, scoring methodologies, cyber risk algorithms, model validation, sensitivity analysis, security ratings, aggregation, cyber insurance, and financial materiality.

He has also taken cyber risk methodology through formal model risk management review and certification processes. 

Researcher, Author, and Advisor

Jack holds a Ph.D. in Information Systems and maintains an active research and publishing agenda focused on cyber risk measurement, decision science, emerging risk, and the reliability of risk assessment methods.

He is an IANS Faculty member and Executive Fellow at the Cyentia Institute and has served in leadership and editorial roles across the cybersecurity profession. He is also an inventor on a U.S. patent related to cyber risk technology. Jack has served as a professional advisor to several cyber startups.

His professional recognition includes induction into the ISACA Hall of Fame, the ISSA Distinguished Fellow designation, the ISC2 Global Achievement Award, and ISACA’s John W. Lainhart IV Common Body of Knowledge Award.

Independent Advice for Difficult Problems

Freund Advisory Group is intentionally specialized. We can work with common frameworks and standards, but our primary focus is on problems requiring deeper analysis, stronger methodology, and judgment.

Clients typically engage the firm when they need to quantify an important exposure, challenge an existing methodology, redesign a risk program, understand a portfolio of risks, evaluate uncertainty, or help senior leaders reach a defensible decision.

Begin Your Transformation

Submit the inquiry form to discuss your objectives and determine how a tailored consulting engagement can advance your strategic priorities.