Security Risk Management
CYBER LEADER HUB helps small to mid-size businesses respond and adapt to the continually evolving threat landscape. The changing threat landscape necessitates the implementation of robust strategies and practices to effectively manage security risks and safeguard critical data.
A diverse and interconnected business, encompassing business partners, customers, and third-party providers, inherently introduces areas of security risk that demand specialized expertise in risk management coupled with innovative solutions.
CYBER LEADER HUB’s network of experienced professionals can help you ascertain the current state and pinpoint opportunities for enhanced security risk management. This is a formidable challenge for smaller organizations. We are equipped to assist.

We offer:
Information security and cybersecurity program development and guidance from a practitioner to the C-suite level.
Information security, privacy, and risk management, with primary practice areas in cybersecurity and third-party risk.
Facilitates risk assessment and identification of program enhancement areas.
Develops strategies and implementation methodologies for quantifiable outcomes.
Designed for the unique needs of small to mid-size businesses.


About Us
Jason Frugé
Cofounder and CEO
Jason Frugé is a seasoned global business executive and strategic advisor with over 25 years of experience in digital and cyber risk governance. He has a distinguished background as a four-time CISO, with key roles at major corporations like Upbound Group, Fossil Group, and Signet Jewelers. His career has focused on helping Fortune 500 companies in various sectors, including retail, healthcare, banking, and fintech, establish robust security programs and mitigate risks. Jason’s expertise includes developing comprehensive security strategies, leading cloud security initiatives, and ensuring security measures are fully aligned with business objectives.
Beyond his C-suite experience, Jason is a recognized authority in cybersecurity, holding a Boardroom Certified Qualified Technology Expert (QTE) and CISSP credential. He is a senior faculty member at the Digital Directors Network, where he trains future leaders for board positions. His proven track record includes remarkable achievements like a 31% reduction in downtime at Upbound Group and a 40% reduction in incident response time at Fossil Group.
Jason brings this high-level expertise and a results-driven approach to every client, helping them navigate complex digital landscapes and build resilient, secure organizations.

Shawn Malone
Cofounder and COO
Shawn Malone is an experienced risk consultant and executive advisor with more than 30 years of industry experience in all facets of information security and cyber risk management program development, implementation, and governance. He has delivered strategic consulting, advisory, and fractional/virtual CISO services to companies in several industry verticals, including financial services/insurance, aerospace and defense, textiles/soft goods, printing, and logistics. Shawn’s background includes experience in secure systems strategy, architecture, solution development and implementation, risk management, cybersecurity program assessment, program policy and governance, regulatory compliance reviews, and third-party cyber risk management.
As a seasoned cyber risk professional, Shawn is the CISO in Residence for the Cyber Angel Network, an early-stage investment firm in the cybersecurity market. Shawn holds several industry-recognized certifications, including CISSP and Boardroom Certified Qualified Technology Expert (QTE). He co-developed and is an initial holder of the Certified Third-Party Risk Professional (CTPRP) designation from Shared Assessments and is a Cybersecurity Maturity Model Certification Registered Practitioner (CMMC RP) as designated by the Cybersecurity Maturity Model Certification Accreditation Body (CMMC AB).
Shawn’s extensive experience provides a practical approach to assessing cyber risk, identifying areas for program improvement, and developing strategies and implementation approaches that enable cyber resilience and provide measured results.


