Kelly O’Brien

Kelly O’Brien

Kelly O’Brien is the Senior Vice President of Risk & Compliance at Compass IT Compliance, bringing more than 20 years of experience in information technology and cybersecurity. She has built her career around helping organizations manage cyber risk, strengthen compliance programs, and align security initiatives with business strategy. Ms. O’Brien holds several distinguished certifications, including CISM, CRISC, CISA, CDPSE, CFE, and CMMC CCP. She is an active contributor to the professional community through organizations such as ISACA, Infragard, where she serves as a Board Member, and the Association of Certified Fraud Examiners. Her expertise spans a broad range of industries and encompasses key cybersecurity frameworks, regulatory standards, and specialized assessments, including CJIS. She has also authored articles for industry publications, delivered webinars for ISACA, and shared her expertise as a panelist and speaker at conferences on cybersecurity, risk management, and compliance. Beyond her professional work, Kelly volunteers with The Honor Foundation as a career coach, guiding transitioning U.S. Special Operations Forces personnel into private-sector careers. In this role, she focuses on helping veterans explore opportunities in Cyber Risk & Compliance, where her mentorship and practical insight make a meaningful impact.

Posts by Kelly O’Brien

Securing Sea & Road: Cyber Threats in Maritime & Logistics

Cybersecurity on Sea & Road: Protecting Maritime & Logistics Operations

The shipping, trucking, and logistics sectors are increasingly in the crosshairs of cyber attackers. In the past few years, both major and minor incidents have shown that no size or mode of transport is immune. Whether it is a vessel navigating global trade routes or a fleet hauling f …

Read Story

Understanding AI: What It Is, How It Works, & Why It Needs Oversight

Understanding AI

Artificial Intelligence (AI) is no longer a futuristic concept; it is a reality. It’s already reshaping how we live, work, and interact with technology. From voice assistants and personalized ads to self-driving cars and automated customer support, AI is quietly becoming a core part o …

Read Story

CIS or NIST CSF? Choosing the Right Cybersecurity Framework (Or Both)

CIS vs NIST CSF

The Center for Internet Security (CIS) Critical Security Controls are a prioritized set of best practices designed to help organizations defend against common cyber threats. Version 8.0, released in 2021, introduced major changes to better reflect modern IT environments, including sup …

Read Story

HIPAA Compliance in 2025: What’s Changing & Why It Matters

HIPAA Compliance in 2025

Healthcare privacy is evolving rapidly, and 2025 is poised to be a year of significant developments. From how artificial intelligence is handled to increased scrutiny around reproductive health data, the boundaries of HIPAA compliance are expanding. This blog post highlights the most …

Read Story

Reporting Your DoD Self Assessment (SPRS) Score: What to Know

Reporting Your DoD Self Assessment (SPRS) Score

If you contract with the Department of Defense (DoD)—directly or indirectly—you’re likely required to report a cybersecurity self-assessment score to the Supplier Performance Risk System (SPRS). SPRS is a web-based system used by the DoD to track and assess contractor performance and …

Read Story

What Makes an Industry-Leading Cyber Insurance Policy Today?

Cyber Insurance Policy

Cyber insurance is no longer a niche product or an optional safeguard—it has become a critical pillar of enterprise risk management. As cyberattacks grow more sophisticated and regulatory pressures tighten, organizations of all sizes are reevaluating what they expect from their cyber …

Read Story

Subscribe by email