{"id":21,"date":"2017-05-30T17:32:08","date_gmt":"2017-05-30T16:32:08","guid":{"rendered":"http:\/\/becem.net\/infosec\/?page_id=2"},"modified":"2026-05-22T10:50:49","modified_gmt":"2026-05-22T09:50:49","slug":"about_the_author","status":"publish","type":"page","link":"https:\/\/www.auravere.com\/insights\/about_the_author\/","title":{"rendered":"About the Author"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>About Matt Mason<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Twenty years is a long time to spend doing anything. Long enough to see trends come and go, technologies rise and fall, and organisations make the same avoidable mistakes over and over again, occasionally in spectacular fashion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I have spent the last two decades working in Information Security and IT leadership, the majority of that in higher education. It is an environment that is uniquely demanding. Open by nature, complex by design, under-resourced by default, and an attractive target precisely because of the data it holds and the people it serves. It is not an easy place to do security well, and that is exactly why I found it worth doing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">My background covers Information Security Management, Cyber Security, Risk Management, Governance, Risk and Compliance, Data Protection, Cloud Security, Security Architecture, Solution Architecture, and IT operational leadership. Each one represents years of real decisions, real incidents, real budget arguments, and real consequences.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I hold the CISSP, CCSP, and CGRC certifications from ISC2, and I am a Chartered IT Professional and Fellow of the British Computer Society. I have contributed to ISC2 Exam Item Development, sit on the BCS Information Security Specialist Group committee, serve on the BCS Nottingham and Derby Group Committee, and co-authored a paper for the Cloud Security Alliance on ERP security in the cloud.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">None of that is why I write here.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I write because the gap between what organisations know they should do and what they actually do remains enormous. Because security and governance are still treated as problems to be solved once rather than disciplines to be maintained. Because too many leaders inherit broken estates and are expected to fix them without the visibility, the budget, or the mandate to do it properly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I am not done learning, and I am not done building. This site is part of how I think out loud while I do both.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What you will find here is honest analysis of real problems, written by someone who has sat in the chair and had to make the calls. No vendor marketing. No frameworks presented as though understanding them is the same as implementing them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If something here is useful to you, that is enough. If you want to continue the conversation, you can find me on LinkedIn.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/mattmasoncissp\">Connect with me on LinkedIn<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>About Matt Mason Twenty years is a long time to spend doing anything. Long enough to see trends come and go, technologies rise and fall, and organisations make the same avoidable mistakes over and over again, occasionally in spectacular fashion. I have spent the last two decades working in Information Security and IT leadership, the&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"open","template":"","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_seo_schema_type":"","_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"class_list":["post-21","page","type-page","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/pages\/21","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/comments?post=21"}],"version-history":[{"count":5,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/pages\/21\/revisions"}],"predecessor-version":[{"id":360,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/pages\/21\/revisions\/360"}],"wp:attachment":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/media?parent=21"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}