$ whoami
Paul Falor

Practice Lead, Secure, Responsible AI & Data Protection, Americas, Accenture

Twenty years across the CIO, CTO, and CISO chairs. Now closing the AI control gap.

I have run technology as a CIO, built and shipped software as an engineer, owned security from the audit floor to the executive table, and now lead Accenture's Secure, Responsible AI and Data Protection practice across the Americas. Twenty years of that work share one thread: the gap between what an organization adopts and what it can actually control. This site is the portfolio. The resume is one page of it.

⌘Kto open command palette

Selected work

Platforms built, systems retired, programs certified, teams led.

Cinch: a production collaboration platform built on evidence, not demos

Independent · 2025 to present

A multi-tenant Slack alternative in production at cinchme.app, with tenant isolation proven in the database, a browser suite run against the production image, and a release gate that refuses to promote traffic without evidence.

2,566
Unit and integration tests
92
Browser scenarios against the production image

Replacing 19 legacy systems with one enterprise core

North Highland · 2014 to 2026

A multi-year transformation that retired 19 systems in favor of an integrated ERP, HRIS, PSA, finance, and CRM platform for a global consultancy.

19
Legacy systems retired
5
Countries on one standard

Five certifications, first audit, zero critical findings

North Highland · 2014 to 2026

A risk and compliance program aligned to ISO 27001, HITRUST, HIPAA, GDPR, and UK Cyber Essentials that certified on the first pass and opened more than a billion dollars of revenue.

5
Standards certified on the first audit
0
Critical findings

Building the secure digital core

North Highland · 2014 to 2026

A global security foundation spanning cloud, network, data, and platform that cut mean time to detect by 75%, mean time to respond by 60%, and average vulnerability age from 45 days to 12.

75%
Reduction in mean time to detect
60%
Reduction in mean time to respond

Writing

Long-form points of view on security, technology leadership, and AI.

AI

Securing the Enterprise Rush to GenAI

Adoption is outrunning governance by a wide margin. The defining risk of this era is not an exotic zero-day. It is the debt between how fast we deploy AI and how slowly we learn to control it.

7 min read

CISO

Rebuilding the SOC for an AI-Speed Adversary

Attackers compressed breakout time to minutes and deleted the cost of expertise. You cannot defend a machine-speed adversary at human speed.

8 min read

CISO

Shrinking the Blast Radius

You cannot guarantee a breach will not happen. You can decide how much it costs when it does. Encryption, tokenization, and minimization are blast-radius controls, not prevention controls.

8 min read

AI

The AI Control Gap

The danger is not the AI. It is the gap between how fast you adopt it and how fast you can control it. Locate your organization on the model in 90 seconds.

Interactive

Career

Two decades from penetration tester to CIO to practice lead.

Accenture

Managing Director, Secure, Responsible AI & Data Protection Practice Lead for the Americas

March 2026 - Present

Lead the Secure, Responsible AI & Data Protection practice across the Americas (US, Canada, and LATAM), helping enterprises adopt AI safely while protecting the data underneath.

North Highland

Chief Information Officer, Senior Managing Director, Security & Technology

October 2014 - March 2026

Led global technology operations across 5 countries and time zones, overseeing security, compliance, product development, infrastructure, data & analytics, and enterprise applications.

Global Payments

Director, Threat & Vulnerability Management

April 2013 - October 2014

Led the Threat & Vulnerability Management (TVM) program for one of the world's largest payment processors, transforming cyber risks into actionable data-driven insights.

Truist

Vice President, IT Audit Manager

March 2012 - April 2013

Led end-to-end technology audit engagements, including planning, scoping, risk assessment, control testing, results validation, and reporting.

TRX

Director, Information Security

May 2008 - March 2012

Established the first Information Security program for a leading SaaS travel provider, building a strong security foundation to protect global technology assets.

KPMG

Information Protection Senior Associate

May 2005 - May 2008

Conducted and managed internal and external vulnerability assessments and penetration testing, leveraging both manual and automated tools.

Get In Touch

Let's connect and explore opportunities

Contact Information

Quick Connect

Interested in discussing securing AI adoption, AI-driven security operations, or data protection strategy? I'd love to connect.

© 2026 Paul Falor. All rights reserved.

Built with Next.js, Tailwind CSS, and Framer Motion