David Tortora

Cyber Risk Advisory · Security Program Leadership · Incident Command · Investigations

I build security programs and advise the leaders who own the risk. When the incident nobody planned for comes, I can run that too.

I build security programs and run the incidents nobody planned for. I built an incident command function from nothing at an international MSSP and ran it, after ten years as a detective working financial crime, cybercrime, and digital forensics. Before that, three tours in Iraq as a Marine.

200+
P1 and P2 incidents directed, declaration through restoration, teams of up to 20
2,000+
Clients at the international MSSP whose incident command function I built from zero
10 years
Detective in financial crime, cybercrime, and digital forensics. Court-qualified expert witness
3
Security newsletters, written for the board, the responders, and the teams closing the gaps

Certifications: CISSP · CCP (CMMC) · CFCI · CCCI · TEEX PER-371 Cybersecurity Incident Response & Management · TEEX Infrastructure Protection

What I Do

01

Executive and Board Advisory

Translating threat and risk into business impact for the executives and boards who own the decision: the facts, the options, and the path forward, so leadership decides on evidence instead of guessing. During active incidents I brief the C-suite in real time, under pressure, when the call cannot wait. Away from the crisis I put leadership teams through executive tabletop exercises before a real incident arrives, and my State of the Threat newsletter runs the same translation in writing for the boardroom every week.

02

Security Program Leadership

Built an Incident Commander function from zero: methodology, playbooks, escalation model, and knowledge base, so the response did not depend on whoever happened to be awake. Authored the Containment and Remediation Unit business proposal and designed the Deputy IC role to scale capacity beyond one person. The point was always the same: leave behind something that runs as a function, not a hero.

03

Cyber Risk Assessment and Readiness

Finding where the risk actually sits and building the readiness to meet it, sized to the organization in front of me. Built the CIRT Readiness program of executive tabletop exercises that put client leadership through an incident before a real one arrives. Through ADS Risk Solutions I run controls reviews against recognized frameworks and CMMC position analysis, so a company knows where it stands before an insurer, a customer, or an attacker tells it.

04

Incident Command

The advisory work rests on having actually run the emergencies, from routine outages through full-scale ransomware. When a critical incident is declared I command it from declaration through restoration, across time zones from the West Coast to Hong Kong, with teams of up to 20 on the long ones. On a breach there are a lot of people at the table: breach counsel, the outside forensic firms, the cyber insurance carrier, sometimes the FBI, CISA, or the UK NCSC. Somebody has to pull all of it together so each party gets what it needs and the client has one person to deal with while they get back up and running. That is the job.

05

Investigations and Financial Crime

Ten years as a detective working fraud, money laundering, cryptocurrency, and cyberstalking. I built the department's digital forensics capability from nothing and secured grant access to crypto-tracing tooling. Court-qualified expert witness. The full investigations record is here.

06

Publishing

Three newsletters, written for three different people: State of the Threat for the board, State of the Attack for the responders, and State of the Defense for the teams who have to close the gaps. More on each of them below.

Background

I started in IT, managing networks and servers for a school district. That gave me a foundation in how systems are built and where they break. When I joined the Marine Corps, I went from maintaining infrastructure to leading people. I rose to Staff Sergeant across three tours in Iraq, leading teams that scaled from a squad to a full platoon, and developed more than 50 junior Marines and Naval officers along the way.

Law enforcement was a natural next step. I came in through corrections and patrol, but the cases that pulled me in were all digital: fraud, identity theft, cybercrime. I made detective, then senior detective, and built the department's forensics capability from nothing. I secured grant access to cryptocurrency tracing tools, trained other detectives to use them, and spent ten years working those cases. There is no cybercrime without crime, and understanding both sides matters.

At Thrive I commanded incident response for a global client base, building the Incident Commander function while the casework ran: methodology, playbooks, escalation model, and the readiness program behind it. The job underneath has not changed across IT, the Marine Corps, the detective bureau, and the incident bridge. Figure out what is actually true, take charge, protect people.

Experience

Security Incident Commander
Thrive · International MSSP · 2025 to 2026

Built the Incident Commander function from zero and directed the full P1 and P2 incident load through it, from routine outages through full-scale ransomware, for an international MSSP serving 2,000+ clients globally, from declaration through restoration, coordinating teams of up to 20 across time zones from the West Coast to Hong Kong. Pulled breach counsel, the outside forensic firms, and the cyber insurance carrier together so each got what it needed and the client had one person to deal with while they got back up and running. Worked with the FBI, CISA, and the UK NCSC when a matter crossed borders.

Detective, Cybercrime & Financial Crimes
Bergenfield Police Department · 2015 to 2025

Ten years of financial crime, cybercrime, and digital forensics. Built the department's forensics capability from nothing, secured grant access to cryptocurrency tracing tooling and trained the team on it, and drove complex cases through to charges, prosecution, or federal referral.

Staff Sergeant
U.S. Marine Corps · 2003 to 2007

Three tours in Iraq. Led teams scaling from a squad to a full platoon, with accelerated promotion each deployment cycle. Developed 50+ Marines and Naval officers, 10 of them promoted under supervision.

Principal
ADS Risk Solutions · 2025 to Present

Independent security risk assessment practice at adsrisk.com: controls review against recognized standards, cyber insurance and customer security questionnaire verification, CMMC position analysis, and executive incident-readiness tabletops.

I publish three cybersecurity newsletters: State of the Threat, State of the Attack, and State of the Defense.

Writing

Essays and analysis on cybersecurity, AI, investigations, and leadership: the pieces that do not fit the State-of newsletters.

Get in Touch

Always interested in connecting with people working in cybersecurity operations, incident response, and security leadership.

Connect on LinkedIn