John Cusimano

Chief Strategy Officer | OT Cybersecurity Risk & Resilience Leader | Creator of CyberPHA® & CyberBowtie® Methodologies | ISA/IEC 62443 Expert | Protecting Critical Infrastructure

Greater Philadelphia

About

I help operators of critical infrastructure identify, prioritize, and reduce OT cybersecurity risk that could impact safety, reliability, production, and business performance. For more than 35 years, I have worked at the intersection of process automation, functional safety, and industrial cybersecurity, helping some of the world's largest energy, chemical, manufacturing, pharmaceutical, and infrastructure organizations improve operational resilience. I am best known for pioneering the CyberPHA, CyberHAZOP, and CyberBowtie methodologies and for leading development of ISA/IEC 62443-3-2, the international standard for OT cybersecurity risk assessment.

Experience

  • Armexa ()
    • Chief Strategy Officer (CSO) and VP GRC & Training Services
      Feb 2025 - Present · 1 yr 6 mos

      *Member of Armexa Executive Leadership Team. •Responsible for OT cybersecurity strategy, growth, partnerships, marketing, and business development. •Established strategic alliances with technology and industry partners. •Expanded adoption of consequence-based OT cybersecurity risk assessment methodologies. •Supports Fortune 500 and multinational industrial organizations across energy, chemical, manufacturing, and infrastructure sectors.

    • Vice President OT Cybersecurity
      Aug 2023 - Present · 3 yrs

      John serves on the Executive Leadership team, oversees business development and marketing, and leads the Assessment, Governance, and Training (AGT) services delivery practice for Armexa. Many of his clients are Fortune 500 multinational companies with both domestic and international operations. His practice's flagship ICS cybersecurity service is OT cybersecurity risk assessments per the ISA/IEC 62443-3-2 (aka CyberPHA, CyberHAZOP, Cyber Bowtie) but their services range from cybersecurity program development, CyberFAT and SAT testing, ICS and IIoT cybersecurity risk assessments, and training.Guide and assist operators of industrial facilities of all sizes to identify, rank, and mitigate the cybersecurity risks that could impact the safety, reliability, and integrity of their operations.

  • Managing Director | Risk & Financial Advisory | Cyber & Strategic Risk | CyberIoT at Deloitte
    Aug 2021 - Aug 2023 · 2 yrs 1 mo

    Leader of OT cybersecurity practice serving clients in oil, gas, chemicals, mining, metals, pharmceuticals, and other critical infrastructure sectors. Lead and support sales/pipeline management, go-to-market, marketing/eminence, alliance partnerships, and service offering development for the firm's overall cyber-physical systems (CPS) cybersecurity practice which encompasses OT, IoT, IIoT, and Product Security market offerings. .

  • aeSolutions (7 yrs 6 mos)
    • Vice President Industrial Cybersecurity
      Aug 2018 - Aug 2021 · 3 yrs 1 mo

    • Director of Industrial Cybersecurity
      Mar 2014 - Aug 2018 · 4 yrs 6 mos

      Responsible for the company's Industrial Cybersecurity line of business which provided cybersecurity services for clients in critical infrastructure sectors where process safety is paramount such as oil & gas (upstream, midstream and downstream) as well as hydrocarbon/chemical processing and power generation. The division's expertise was in Operational Technology (OT) which encompasses the plant computing systems such as industrial control systems (ICS) and SCADA systems as well as the interfaces between OT and enterprise IT. Developed the business from the ground-up and in less than 2 years established the company as a leader in this segment. Selected by several Fortune 500 companies to assist them at the corporate-level through services such as vulnerability & risk assessments, development of mitigation plans, development of policies, standards and procedures and implementation and maintenance of cybersecurity countermeasures. The division's differentiator was the team's decades of experience working in the process industries and deep knowledge of industrial control and safety systems, coupled with their deep knowledge of industrial networking, industrial protocols, platform security, and certified IT security skills. This rare combination of skills combined with their strong references and vendor neutral, customer focused posture enabled them to successfully compete against much larger organizations such as IT security firms, management consulting firms and major automation vendors.

  • Managing Director at Security Incidents Organization
    Oct 2009 - Mar 2014 · 4 yrs 6 mos

    Oversaw the operation of the Repository of Industrial Security Incidents (RISI) database and publications.

  • Director of Security Services at exida.com
    Feb 2009 - Mar 2014 · 5 yrs 2 mos

    Responsible for the development and execution of exida’s consulting and certification services for cyber security. Developed the methodology and performed countless Industrial Control System (ICS) / SCADA Cybersecurity Vulnerability and Risk Assessments in the Oil & Gas, Chemical, Water/Wastewater and Power industries per ISA/IEC 62443 and NERC CIP standards. Assisted several Fortune 100 companies in developing their corporate ICS cybersecurity strategy. Instrumental in the ANSI/ACLASS accreditation of exida as a Certification Body for the program. Personally qualified as an assessor/auditor for the ISASecure and Achilles™ security certification programs.