Policy design
What to measure, what to prohibit, what to communicate — and to whom
What every program needs before the tools, the policies, and the budget conversation.
Knowing you need an insider risk program is one thing. Architecting one that actually works — across conflicting
organizational priorities, legal constraints, union considerations, and technology stacks — is another challenge entirely.
This episode is the practitioner’s blueprint. We walk through the three pillars of a functional IRM program — policy design, cross-functional human coordination, and technology selection — and address the most contentious question: how to build a program that genuinely protects the organization while earning employee trust rather than destroying it.
What to measure, what to prohibit, what to communicate — and to whom
Legal, HR, IT, and Security — defining ownership and decision rights
Employee monitoring without building a surveillance culture
Matching capability requirements to actual needs, not vendor hype
Which matters more — and when to prioritize each
How human behavior research should inform the tools you choose
CoFounder & CEO Wolfpack Security
CIO - Western Reserve Area Agency on Aging
Field CISO, Teramind