← Back to paulfalor.com

Paul Falor

Practice Lead | Secure, Responsible AI & Data Protection | Americas

Atlanta, GA · paul@falor.net · linkedin.com/in/pfalor · paulfalor.com

Georgia CIO of the Year (InspireCIO)

Summary

I lead Accenture's Secure, Responsible AI & Data Protection practice across the Americas, covering the United States, Canada, and Latin America, helping enterprises adopt AI boldly without outrunning their ability to secure it. My work spans three fronts: building the foundation, guardrails, and controls that let the business use GenAI and frontier models safely; reimagining security operations with AI to match adversaries who now move faster and at lower cost; and protecting the data itself, so that when something does go wrong the exposure and blast radius stay contained. With more than 20 years leading global security and technology operations, including time as a CIO, I bring a practitioner's perspective to every engagement: strategy grounded in operational reality.

Experience

Managing Director, Secure, Responsible AI & Data Protection Practice Lead for the Americas

March 2026 - Present

Accenture · Atlanta, GA

  • Lead the Secure, Responsible AI & Data Protection practice across the Americas (US, Canada, and LATAM), helping enterprises adopt AI safely while protecting the data underneath.
  • Advise C-suite, CISO, and CDO clients on Security for AI, AI for Security, and Data Protection, translating fast-moving technical risk into business-aligned roadmaps.
  • Drive growth across a rapidly expanding practice spanning AI governance and guardrails, AI-augmented security operations, and data protection.

Chief Information Officer, Senior Managing Director, Security & Technology

October 2014 - March 2026

North Highland · Atlanta, GA

  • Led global technology operations across 5 countries and time zones, overseeing security, compliance, product development, infrastructure, data & analytics, and enterprise applications.
  • Established global secure digital core spanning cloud, network, data, and platform security. Reduced MTTD by 75%, MTTR by 60%, decreased average vulnerability age from 45 to 12 days, and achieved 99% critical patch compliance.
  • Led multi-year digital transformation, replacing 19 legacy systems with comprehensive ERP, HRIS, PSA, FIN, and CRM implementation.
  • Led technology due diligence and post-deal integration for 6 acquisitions, creating a repeatable M&A playbook to execute at scale.
  • Built and led high-performing technology team with 86% engagement scores, consistently 15% above organizational average. Reduced attrition by 40%.
  • Championed AI-assisted product development methodology, reducing cost and time to market by over 90%.
  • Created comprehensive risk and compliance program aligned with ISO27001, HITRUST, HIPAA, GDPR, and UK CyberEssentials. Achieved certification on first audit with zero critical findings.
  • Executed full-scale cloud migration, reducing TCO by 30%. Architected near real-time disaster recovery, achieving 99.95% uptime and reducing RTO from 48 hours to 4 hours.

Director, Threat & Vulnerability Management

April 2013 - October 2014

Global Payments · Atlanta, GA

  • Led the Threat & Vulnerability Management (TVM) program for one of the world's largest payment processors, transforming cyber risks into actionable data-driven insights.
  • Built and managed high-performing security teams, including vulnerability analysts, application security assessors, penetration testers, and data loss prevention specialists.
  • Developed a robust governance framework with policies, standards, and procedures to ensure regulatory compliance with PCI-DSS and SOC2 guidelines.
  • Optimized security operations by implementing advanced vulnerability assessment methodologies. Reduced time to remediate by 87% and time to detect by 91%.
  • Served as a strategic security advisor, integrating security best practices into all phases of software development lifecycle.

Vice President, IT Audit Manager

March 2012 - April 2013

Truist · Atlanta, GA

  • Led end-to-end technology audit engagements, including planning, scoping, risk assessment, control testing, results validation, and reporting.
  • Served as the primary liaison and trusted advisor to Truist's Technology & Risk teams, strengthening collaboration and risk mitigation strategies.
  • Provided strategic technology audit insights to executive leadership, leveraging prior security leadership experience and industry best practices.
  • Engaged with technology leadership in steering committees, project meetings, and strategic planning sessions.
  • Conducted quarterly enterprise risk assessments to identify emerging threats and inform the IT audit roadmap.

Director, Information Security

May 2008 - March 2012

TRX · Atlanta, GA

  • Established the first Information Security program for a leading SaaS travel provider, building a strong security foundation to protect global technology assets.
  • Led a team of cybersecurity professionals safeguarding critical information assets for a global technology hosting company.
  • Owned and maintained compliance programs, including PCI-DSS and NIST SP 800-53.
  • Designed and implemented an enterprise Threat & Vulnerability Management program, enhancing risk detection, mitigation, and security posture.
  • Served as the primary security liaison for customers and conducted vendor security assessments.

Information Protection Senior Associate

May 2005 - May 2008

KPMG · Atlanta, GA

  • Conducted and managed internal and external vulnerability assessments and penetration testing, leveraging both manual and automated tools.
  • Supported compliance initiatives for PCI-DSS, HIPAA, and ISO 17799, driving readiness assessments and remediation efforts.
  • Developed and deployed enterprise-wide Security Policies and Procedures, enhancing governance and security best practices.
  • Led strategic Identity and Access Management (IAM) planning and implementation.
  • Provided subject matter expertise for Security and Logical Access controls in Financial Statement and SOX audits.

Expertise

Security & Compliance: ISO 27001, HITRUST, HIPAA, GDPR, PCI-DSS, SOC 2, NIST SP 800-53, UK CyberEssentials, Threat & Vulnerability Management, Security Operations

Digital Transformation: Cloud Migration, ERP Implementation, Legacy System Modernization, Global Standardization, Disaster Recovery, Infrastructure Optimization

AI & Emerging Tech: AI-Assisted Development, Product Development Methodology, Data & Analytics, Process Automation, Technology Innovation

M&A Technology Integration: Technology Due Diligence, Post-Deal Integration, M&A Playbook Development, Cost Takeout Analysis, Enterprise Value Maximization

Executive Leadership: Global Team Leadership (5 countries), Board & PE Communication, Budget Optimization (23% cost reduction), Vendor Negotiation, High-Performing Teams (86% engagement), Talent Development & Retention

Education

Master of Science in Business Administration, Decision & Information Systems

2005

University of Florida, Gainesville, FL · GPA 4.0

Bachelor of Science in Finance, Minor in Decision & Information Systems

2004

University of Florida, Gainesville, FL