SpitDice Profile Banner
Patrick Norman Profile
Patrick Norman

@SpitDice

Followers
13
Following
0
Media
270
Statuses
297

USX Cyber Chief Risk Officer

Washington, DC
Joined June 2024
Don't wanna be here? Send us removal request.
@SpitDice
Patrick Norman
4 months
September recap: SEC disclosure rules, state privacy laws, AI governance. Regulatory convergence demands legal + technical expertise. How is your organization preparing for continued evolution? 📅 #CybersecurityGovernance #RegulatoryCompliance #GeneralCounsel
0
0
0
@SpitDice
Patrick Norman
4 months
New FTC cybersecurity guidance for financial institutions: Security programs must protect consumer interests, not just institutional assets. How are you aligning security with consumer protection goals? #FTCGuidance #FinancialServices #ConsumerProtection
0
0
0
@SpitDice
Patrick Norman
4 months
Supply chain cyber incidents up 51% YoY (SecurityScorecard). Traditional indemnification clauses are inadequate for cascade incidents. How have you updated vendor contracts for cyber coordination? #SupplyChainRisk #VendorContracts #CyberLiability
0
0
0
@SpitDice
Patrick Norman
4 months
New data: SOC 2 automation cuts audit prep by 70% (Statista, 2024). Companies see 55% fewer critical incidents with automated compliance (Forrester, 2023). Multi-framework reality demands strategic decisions 📊 #ComplianceAutomation #CMMC #NIST #SOC2
0
0
0
@SpitDice
Patrick Norman
4 months
AI governance is moving from voluntary guidelines to regulatory requirements. EU AI Act, NIST framework, and emerging U.S. rules demand systematic approaches. How are you preparing legal frameworks for AI compliance? #AIGovernance #ArtificialIntelligence #AIRegulation
0
1
0
@SpitDice
Patrick Norman
4 months
Multi-state privacy laws creating compliance complexity: CCPA amendments, Virginia CDPA. Unlike GDPR, each state has unique requirements. How are you managing the compliance patchwork? #CCPAAmendments #StatePrivacyLaws #DataProtection
0
0
0
@SpitDice
Patrick Norman
4 months
Clients love WhatsApp for speed, but lawyers see compliance risks. From privilege concerns to data retention and cross-border privacy, GCs must balance convenience with governance. Full article: https://t.co/iiAol9gJnG
0
0
0
@SpitDice
Patrick Norman
4 months
ESG + cybersecurity convergence: Security maturity now viewed as an operational risk indicator. Incidents impact ESG scores. How are you aligning security governance with ESG reporting? 📈 #ESGReporting #CybersecurityGovernance #SustainableFinance
0
0
0
@SpitDice
Patrick Norman
4 months
77% of U.S. legal orgs increased AI spend last year; nearly half now call it essential. As AI moves from pilot to practice, GCs must ensure ethical use, data protection, and oversight frameworks that align innovation with integrity. #AIGovernance #LegalInnovation
0
0
0
@SpitDice
Patrick Norman
4 months
Essential elements of modern board #CybersecurityReporting: 1. Risk appetite alignment & variance analysis 2. Regulatory compliance status & upcoming requirements 3. Vendor risk assessment results & mitigation strategies 4. Incident response effectiveness & lessons learned
0
0
0
@SpitDice
Patrick Norman
4 months
CMMC 2.0 isn't just technical compliance, it's a contractual commitment with liability implications for defense contractors. What approaches are you taking to CMMC legal risk? 🏛️ #CMMC #DefenseContracting #FederalCompliance
0
0
0
@SpitDice
Patrick Norman
4 months
SMBs face 43% of cyberattacks, but only 14% have response plans (Verizon). Resource constraints demand managed security and compliance automation. How are you addressing SMB compliance gaps? #SMBCybersecurity #MidMarketCompliance #ManagedSecurity
1
0
0
@SpitDice
Patrick Norman
4 months
Remembering the 2,977 lives lost on 9/11 and honoring all who were affected. Their memory continues to inspire our commitment to protection and service. #PatriotDay #NeverForget #911
0
0
0
@SpitDice
Patrick Norman
4 months
New SEC rules: report material cyber incidents within 4 days. GCs need pre-established classification protocols and clear materiality frameworks. What protocols are you establishing for rapid assessment? #SECCompliance #CybersecurityDisclosure #GeneralCounsel
0
0
0
@SpitDice
Patrick Norman
4 months
Manufacturing faces unique cyber challenges: OT systems, ERP integration, and supply chains. Traditional IT security often falls short. How is your organization bridging OT/IT security gaps? #ManufacturingSecurity #OTSecurity #ERPSecurity
0
0
0
@SpitDice
Patrick Norman
5 months
Cyber insurance premiums up 74% YoY (Marsh). Coverage exclusions expanding. GCs are now central to translating security controls into policy language. What changes are you making to the insurance evaluation? #CyberInsurance #RiskManagement #GeneralCounsel
0
0
0
@SpitDice
Patrick Norman
5 months
AI governance + data privacy = new compliance complexity for legal teams. Proactive policies beat reactive responses to enforcement. How is your organization preparing for regulatory convergence? #AIGovernance #DataPrivacy #RegulatoryCompliance
0
0
0
@SpitDice
Patrick Norman
5 months
Your security is only as strong as your weakest vendor. Third-party risk requires continuous oversight, not annual check-ins. How is your organization modernizing vendor risk assessment? #ThirdPartyRisk #VendorManagement #SupplyChainSecurity
0
0
0
@SpitDice
Patrick Norman
5 months
Workplace protections, like fair pay, safety, & hours, exist because workers fought for them. Laws followed their lead. Labor Day honors those who turned hardship into progress and built the legal frameworks we now uphold. #LaborDay #EmploymentLaw #WorkplaceRights
0
0
0
@SpitDice
Patrick Norman
5 months
Cyber insurance denials up 34% in 2024. 67% due to inadequate controls. Documented security frameworks reduce denials 45%. Average denial $2.3M. 58% result in litigation. Quarterly reviews cut disputes 41%. #CyberInsurance #InsuranceLaw
0
0
0