george-gerchow

George Gerchow

IANS Faculty

Expertise

  • Cloud Security
  • DevSecOps
  • Compliance & Governance (PCI, HIPAA, ISO 27001, CSA Star, SOC 2 Type 2, FedRamp)
  • Management (Building teams, automation, auditing)
  • Privacy

Profile

George is currently chief security officer at Bedrock Data, an organization specializing in AI-driven data protection. Before that, he was head of trust and interim CISO at MongoDB and Sumo Logic's chief security officer & SVP of IT. George possesses more than 20 years of leadership experience in the domains of cybersecurity, compliance and cloud operations. He has actively participated at the forefront of secure architecture, privacy and DevSecOps since co-founding the VMware Center for Policy & Compliance.

A recognized authority in the industry, George is a frequent keynote speaker at significant security forums, including RSA, Black Hat and TEDx. He actively provides advisory services to various cybersecurity startups and enterprise technology companies, assisting in the development of product and go-to-market strategies. Additionally, George serves on several advisory boards and is a co-founder of XFoundation, a nonprofit organization dedicated to raising awareness about fentanyl poisoning.

Expertise

  • Cloud Security
  • DevSecOps
  • Compliance & Governance (PCI, HIPAA, ISO 27001, CSA Star, SOC 2 Type 2, FedRamp)
  • Management (Building teams, automation, auditing)
  • Privacy

Qualifications

Achievements & Contributions
  • Co-Founder of VMware Center for Policy and Compliance
  • Co-Author of Center for Internet Security QuickStart Cloud Infrastructure Benchmark v1.0.0
  • Author of the MIS|TI Fundamentals in Cloud Security course
  • Speaker at information security conferences such as RSA, AWS reInvent, Cloud Expo Silicon Valley, SANS Institute Cloud Security Summit
  • Former Global Director of Security Evangelism and Product Strategy and Director of VMware Policy and Compliance at VMware
  • Former Cloud Business Director at EMC
Telerik.Sitefinity.Libraries.Model.Image?.AlternativeText

September 02 2026

2026 September Webinar: Beyond Generic AI: How IANS MCP Provides Expert and Peer Insights Directly into Your Workflow

IANS MCP puts the full body of IANS’ intelligence – thousands of insights from IANS Faculty experts and your peers – inside the AI tools your team already uses. Pulling from more than 6,000 summaries of peer-to-peer and expert conversations working through real problems, unbiased vendor selection insights from more than 350 vendor assessments (with zero vendor marketing influence), and instantly usable outputs like checklists, playbooks, board-ready slides and more, IANS Faculty George Gerchow will give you a live demo of how he uses the IANS MCP to support his work as a practicing CISO.

Telerik.Sitefinity.Libraries.Model.Image?.AlternativeText

September 10 2026

2026 Q3 Symposium: MCP Risks and Opportunities in an AI World

The Model Context Protocol (MCP) is an open standard defining how AI systems and agents connect to external data sources and tools. As organizations rapidly adopt these capabilities, MCP is becoming the connective tissue for agentic AI, creating both opportunities and risks. Opportunity includes the ability for security teams to wire AI straight into their stack and go from a plain-English question to a real answer, or even remediation, in seconds. However, every MCP connection is a new non-human identity (NHI) and a new data path, so the real exposure is less about the model and more about what an agent can reach, tool poisoning and standing access no one is watching. How do we benefit from MCP while managing the risk? Adopt fast, but govern first. In this symposium, IANS Faculty George Gerchow shares his practical experience and expertise to help you navigate this rapidly changing space.

Portal Publications