drj logo
drj logo

Welcome to DRJ

Already registered user? Please login here

Create new account
(it's completely free). Subscribe

x

Career Spotlight: Jason Harrell

Leadership: Culture & Workforce Resilience
Jason Harrell, cybersecurity thought leader and public policy advocate

Tell us about yourself – your name, company, title, and responsibilities?

My name is Jason Harrell. I am a thought leader within the cybersecurity risk management and non-financial risk public policy space. Over the last 25 years, I have held numerous roles as both a director and executive within information technology, cybersecurity, and public policy/advocacy. In my last role, I was responsible for developing and executing a public policy and advocacy strategy for cybersecurity, operational resilience, third party/supply chain management, and emerging technology. My career superpower has been the ability to build new functions within organizations that enhance resilience and manage risks.

How did you get into the business continuity industry?

I was a young network engineer when my boss, concerned about the different email viruses, asked me to provide a solution for developing alternate network connectivity in the event our primary internet connection was unavailable. We didn’t call it business continuity then, but it was the first time I can remember having to consider business workarounds of this kind.

Since that time, my work has increasingly required partnerships with my business continuity colleagues. Whether it was to understand the business impact assessment of applications and processes to prioritize application penetration testing, threat assessment, or other risk management activities or to help bolster our cyber assessment recommendations, the link between cyber risk and business continuity has always been strong. The industry has grown immensely, and with the emergence of operational resilience as a regulatory priority, the connective tissue between these areas has increased. As my work continues, our primary focus is to determine how to best prepare for severe-but-plausible operational events.

Tell us about some of the challenges you have encountered in your career?

The biggest challenge I’ve encountered was expanding my skillset from an information technology and cyber professional to a public policy and advocacy professional. When executive management called on me to develop an internal function to increase our partnership with the financial sector, it was intimidating. While I understood cyber and cyber solutions, I had no idea how to convert this into a policy and advocacy function. I was fortunate to be paired with a colleague who helped me better understand regulatory engagement and together, we were able to build a policy and advocacy function to increase the engagement on a global scale and allowed our organization to be a part of the financial sector dialogue on numerous non-financial risk areas.

What are some lessons learned you still leverage today?

Having worked for systemically important financial institutions and market utilities (SIFI/SIFMU), investment banking, investment management, custodian, clearing/settlement, and trading venue organizations, I have gained a broad understanding of the financial markets; different approaches to managing cyber risks; and how different risk failures may impact these organizations and financial markets. I use what I have learned every time I engage in policy discussions or when I think about the best policy approaches and risk outcomes across the financial services sector. Each of these subsectors have different risks and needs. There are no one-size fits all solutions.

What aspects of working in this industry would you like to see change or evolve?

New technology is arriving at an accelerated pace. I’d like to see the public and private sector entities find a way to shorten the regulatory policy lifecycle while allowing for innovation. As the pace of new technology solutions accelerates, so should the pace to determine principles and rules to manage the risks of this technology. Let’s find a way for firms to receive some level of regulatory certainty while innovating and ensure financial authorities have a good understanding of the potential risks that may be introduced.

I would also like to see the merging of operational resilience into the business continuity organization evolve. There are many aspects of operational resilience where the business continuity organization is not empowered to make changes or drive solutions. We need better solutions. I’ll be speaking more about this at the upcoming DRJ Fall 2025 conference in Dallas.

What gets you excited about your career?

The most exciting part of my career is the ability to work across the global financial service sector on one of the sector’s leading risks. Working with financial authorities on policy solutions, with different institutions on far reaching policy requirements such as the European Union Digital Operational Resilience Act (DORA) and partnering with the trade associations to identify emerging risks to the financial sector, truly excite me. I’m energized and ready to continue to lead these discussions and drive solutions using my extensive knowledge in cybersecurity and IT.

What advice would you give to those embarking on a career in this industry?

In 2023, the US Treasury estimated there are 600,000 more cyber jobs than there are qualified people to fill them. The first piece of advice is for hiring managers in the cyber, business continuity, and technology sectors:

Create opportunities for new talent and provide an environment where the new talent can learn.

In past years, the industry provided opportunity to learn on the job. Today, it feels like we’ve shut the door behind us. I’ve encountered many ambitious and curious, young, talented individuals who want to work in cyber and technology but feel like they can’t get through the door.

My second piece of advice for job seekers is to stay hungry for knowledge.

  • Attend local cybersecurity and technology conferences to meet and interact with professionals who are currently in the field. Be sure to introduce yourself to at least five people while you are there.
  • Stay up to date on cyber/technology events. Demonstrate you are paying attention to current events in this space.
  • Continuing education. Cybersecurity and technology are ever-changing. Great professionals consistently look for learning opportunities and take intentional steps towards increasing their knowledge.
Latest News
DRJ HOT ITEMS
Webinar Spotlight
Fetching Upcoming Webinars...
Journal Categories

AI: Automation & Innovation

Business Continuity Management

Crisis Management & Emergency Response

Cyber Resilience & IT Disaster Recovery

Leadership: Culture & Workforce Resilience

Operational Resilience

Risk Management & Quantification

Sector-Specific & Critical Infrastructure Resilience

Supply Chain & Third-Party Resilience

Governance: Compliance & Regulatory Readiness

Incident Management & Response Coordination

Resilience Strategy & Program Maturity

Data Protection: Backup & Recovery

Exercises: Testing & Scenario Planning

Emerging Threats: Geopolitical & Climate Risk

Contact Us

Newsletter

The Journal, right in your inbox.