george-gerchow

George Gerchow

IANS Faculty

Expertise

  • Cloud Security
  • DevSecOps
  • Compliance & Governance (PCI, HIPAA, ISO 27001, CSA Star, SOC 2 Type 2, FedRamp)
  • Management (Building teams, automation, auditing)
  • Privacy

Profile

George is currently chief security officer at Bedrock Data, an organization specializing in AI-driven data protection. Before that, he was head of trust and interim CISO at MongoDB and Sumo Logic's chief security officer & SVP of IT. George possesses more than 20 years of leadership experience in the domains of cybersecurity, compliance and cloud operations. He has actively participated at the forefront of secure architecture, privacy and DevSecOps since co-founding the VMware Center for Policy & Compliance.

A recognized authority in the industry, George is a frequent keynote speaker at significant security forums, including RSA, Black Hat and TEDx. He actively provides advisory services to various cybersecurity startups and enterprise technology companies, assisting in the development of product and go-to-market strategies. Additionally, George serves on several advisory boards and is a co-founder of XFoundation, a nonprofit organization dedicated to raising awareness about fentanyl poisoning.

Expertise

  • Cloud Security
  • DevSecOps
  • Compliance & Governance (PCI, HIPAA, ISO 27001, CSA Star, SOC 2 Type 2, FedRamp)
  • Management (Building teams, automation, auditing)
  • Privacy

Qualifications

Achievements & Contributions
  • Co-Founder of VMware Center for Policy and Compliance
  • Co-Author of Center for Internet Security QuickStart Cloud Infrastructure Benchmark v1.0.0
  • Author of the MIS|TI Fundamentals in Cloud Security course
  • Speaker at information security conferences such as RSA, AWS reInvent, Cloud Expo Silicon Valley, SANS Institute Cloud Security Summit
  • Former Global Director of Security Evangelism and Product Strategy and Director of VMware Policy and Compliance at VMware
  • Former Cloud Business Director at EMC
Telerik.Sitefinity.Libraries.Model.Image?.AlternativeText

August 18 2026

New York Insight Exchange: Secure MCP and Agentic AI Adoption

MCP is becoming the connective tissue for agentic AI, creating both opportunities and risks. Opportunity includes the ability for security teams to wire AI straight into their stack and go from a plain-English question to a real answer, or even remediation, in seconds. However, every MCP connection is a new non-human identity (NHI) and a new data path, so the real exposure is less about the model and more about what an agent can reach, tool poisoning and standing access no one is watching. How do we benefit from MCP while managing the risk? Adopt fast, but govern first. During this highly interactive session focused on peer learning and practitioner exchange, IANS Faculty George Gerchow shares his expertise, facilitates discussions and shows a live demo to help you accelerate MCP adoption while managing security risks.

Telerik.Sitefinity.Libraries.Model.Image?.AlternativeText

September 10 2026

2026 Q3 Symposium: MCP Risks and Opportunities in an AI World

The Model Context Protocol (MCP) is an open standard defining how AI systems and agents connect to external data sources and tools. As organizations rapidly adopt these capabilities, MCP is becoming the connective tissue for agentic AI, creating both opportunities and risks. Opportunity includes the ability for security teams to wire AI straight into their stack and go from a plain-English question to a real answer, or even remediation, in seconds. However, every MCP connection is a new non-human identity (NHI) and a new data path, so the real exposure is less about the model and more about what an agent can reach, tool poisoning and standing access no one is watching. How do we benefit from MCP while managing the risk? Adopt fast, but govern first. In this symposium, IANS Faculty George Gerchow shares his practical experience and expertise to help you navigate this rapidly changing space.

Portal Publications