Pedro Perea is a Senior Principal Analyst within Gartner's Risk and Security Management group. he brings extensive experience researching cybersecurity management challenges, and regularly advises CISOs and their teams on maturing security and risk practices.
In particular, he focuses on Cyber Risk Management, Cybersecurity Strategy, Cyber Security Board Reporting, Frameworks, Security Metrics, Security Policies and Third-Party Cyber Risk Management.
Prior to Gartner, Pedro Pablo has worked for Deloitte as a Consultant and for ING as IT Risk Expert.
The main tasks during that time were:
Deloitte:
-IT support in Financial Audits: performing General IT Controls of different technologies over 4 levels
(application, database, operating system, network), identifying and testing automatic controls,
integrity and accuracy validation of relevant reports extracted from systems.
-Designing and implementing IT Control Models based on several standards and legislations. For
instance: SOC I, II, III defined by AICPA (American Institute of Certified Public Accountants), law
Sarbanes-Oxley (SOX), ISO 27001, SII (legislation of Spanish Tax Agency), etcetera.
In ING:
-Leading and performing deep dives and process reviews in different entities around the world in order to see the level of compliance with the IT Security best practices and regulations.
-Documenting, preparing and reporting the results of the reviews to the high management and
different stakeholders of the entities.
-Reviewing, validating and challenging as 2nd Line of Defense the design and implementation for all the controls for the different areas of the ING IT Security Standards.
-Participating in the new Global initiatives about IT Risk, new standards and new technologies to be implemented.
Deloitte, IT risk experienced senior, 5 years
ING, IT Security & Risk Management expert, 3 years
Cyber Risk
Cybersecurity Leadership
Computer Science at Complutense University of Madrid
Certifications: CISA, CISM
Cyber Risk Management Best Practices
Security Frameworks and Certifications
Cybersecurity Policies
Third-Party Cyber Risk Management
Board Reporting