← Back to paulfalor.com

Paul Falor

Practice Lead, Secure, Responsible AI & Data Protection, Americas, Accenture

Atlanta, GA · paul@falor.net · linkedin.com/in/pfalor · paulfalor.com

Georgia CIO of the Year (InspireCIO)

Leadership across four disciplines

  • CIO: Technology is an operating discipline: a digital core that holds, a cost base you can defend, and a team that stays.
  • CTO: Build like it will be audited: explicit boundaries, tests that run against reality, and evidence before claims.
  • CISO: Security the business can move at: measured detection, fast remediation, and certifications passed on the first audit.
  • AI: Adopt AI boldly, then close the gap between how fast you adopt it and how fast you can control it.

Summary

I have run technology as a CIO, built and shipped software as an engineer, owned security from the audit floor to the executive table, and now lead Accenture's Secure, Responsible AI and Data Protection practice across the Americas. Twenty years of that work share one thread: the gap between what an organization adopts and what it can actually control.

Experience

Managing Director, Secure, Responsible AI & Data Protection Practice Lead for the Americas

March 2026 - Present

Accenture · Atlanta, GA

  • Lead the Secure, Responsible AI & Data Protection practice across the Americas (US, Canada, and LATAM), helping enterprises adopt AI safely while protecting the data underneath.
  • Advise C-suite, CISO, and CDO clients on Security for AI, AI for Security, and Data Protection, translating fast-moving technical risk into business-aligned roadmaps.
  • Drive growth across a rapidly expanding practice spanning AI governance and guardrails, AI-augmented security operations, and data protection.

Chief Information Officer, Senior Managing Director, Security & Technology

October 2014 - March 2026

North Highland · Atlanta, GA

  • Led global technology operations across 5 countries and time zones, overseeing security, compliance, product development, infrastructure, data & analytics, and enterprise applications.
  • Established global secure digital core spanning cloud, network, data, and platform security. Reduced MTTD by 75%, MTTR by 60%, decreased average vulnerability age from 45 to 12 days, and achieved 99% critical patch compliance.
  • Led multi-year digital transformation, replacing 19 legacy systems with comprehensive ERP, HRIS, PSA, FIN, and CRM implementation.
  • Led technology due diligence and post-deal integration for 6 acquisitions, creating a repeatable M&A playbook to execute at scale.
  • Built and led high-performing technology team with 86% engagement scores, consistently 15% above organizational average. Reduced attrition by 40%.
  • Championed AI-assisted product development methodology, reducing cost and time to market by over 90%.
  • Created comprehensive risk and compliance program aligned with ISO27001, HITRUST, HIPAA, GDPR, and UK CyberEssentials. Achieved certification on first audit with zero critical findings.
  • Executed full-scale cloud migration, reducing TCO by 30%. Architected near real-time disaster recovery, achieving 99.95% uptime and reducing RTO from 48 hours to 4 hours.

Director, Threat & Vulnerability Management

April 2013 - October 2014

Global Payments · Atlanta, GA

  • Led the Threat & Vulnerability Management (TVM) program for one of the world's largest payment processors, transforming cyber risks into actionable data-driven insights.
  • Built and managed high-performing security teams, including vulnerability analysts, application security assessors, penetration testers, and data loss prevention specialists.
  • Developed a robust governance framework with policies, standards, and procedures to ensure regulatory compliance with PCI-DSS and SOC2 guidelines.
  • Optimized security operations by implementing advanced vulnerability assessment methodologies. Reduced time to remediate by 87% and time to detect by 91%.
  • Served as a strategic security advisor, integrating security best practices into all phases of software development lifecycle.

Vice President, IT Audit Manager

March 2012 - April 2013

Truist · Atlanta, GA

  • Led end-to-end technology audit engagements, including planning, scoping, risk assessment, control testing, results validation, and reporting.
  • Served as the primary liaison and trusted advisor to Truist's Technology & Risk teams, strengthening collaboration and risk mitigation strategies.
  • Provided strategic technology audit insights to executive leadership, leveraging prior security leadership experience and industry best practices.
  • Engaged with technology leadership in steering committees, project meetings, and strategic planning sessions.
  • Conducted quarterly enterprise risk assessments to identify emerging threats and inform the IT audit roadmap.

Director, Information Security

May 2008 - March 2012

TRX · Atlanta, GA

  • Established the first Information Security program for a leading SaaS travel provider, building a strong security foundation to protect global technology assets.
  • Led a team of cybersecurity professionals safeguarding critical information assets for a global technology hosting company.
  • Owned and maintained compliance programs, including PCI-DSS and NIST SP 800-53.
  • Designed and implemented an enterprise Threat & Vulnerability Management program, enhancing risk detection, mitigation, and security posture.
  • Served as the primary security liaison for customers and conducted vendor security assessments.

Information Protection Senior Associate

May 2005 - May 2008

KPMG · Atlanta, GA

  • Conducted and managed internal and external vulnerability assessments and penetration testing, leveraging both manual and automated tools.
  • Supported compliance initiatives for PCI-DSS, HIPAA, and ISO 17799, driving readiness assessments and remediation efforts.
  • Developed and deployed enterprise-wide Security Policies and Procedures, enhancing governance and security best practices.
  • Led strategic Identity and Access Management (IAM) planning and implementation.
  • Provided subject matter expertise for Security and Logical Access controls in Financial Statement and SOX audits.

Expertise

Chief Information Officer: Global operations across 5 countries, ERP, HRIS, PSA, FIN, and CRM programs, Cloud migration and disaster recovery, M&A technology diligence and integration, Board and PE communication, Budget optimization (23% cost reduction), Vendor negotiation, Talent development and retention

Chief Technology Officer: TypeScript, React, Next.js, PostgreSQL, Drizzle, row-level security, Local-first sync (Rocicorp Zero), Terraform, Fly Machines, Cloudflare, Blue/green releases, SBOM and image policy, Playwright against production images, Architecture decision records, AI-assisted engineering

Chief Information Security Officer: ISO 27001, HITRUST, HIPAA, GDPR, PCI-DSS, SOC 2, NIST SP 800-53, UK Cyber Essentials, Threat and vulnerability management, Security operations and incident response, IT audit and SOX controls, Penetration testing and IAM

Secure and Responsible AI: NIST AI RMF, ISO 42001, EU AI Act, OWASP LLM and agentic Top 10, AI governance and guardrails, Model and pipeline security, AI-augmented SOC design, Encryption, tokenization, data minimization, AI-assisted development

Education

Master of Science in Business Administration, Decision & Information Systems

2005

University of Florida, Gainesville, FL · GPA 4.0

Bachelor of Science in Finance, Minor in Decision & Information Systems

2004

University of Florida, Gainesville, FL