You don't need a million-dollar security team to think like one. James McQuiggan brings 25+ years of CISO-level expertise — including 18 years in industrial control systems — as a keynote speaker, vCISO, and Human Risk Management advisor who actually makes security training stick.
As seen at & affiliated with
Whether you need a fractional CISO, a keynote speaker, or a team that finally understands why your employees keep clicking phishing links — there's a right-sized engagement for every organization.
Strategy should come before tools. James works directly with security teams to assess your current posture, identify gaps in your human risk program, and build a prioritized roadmap that accounts for emerging AI-driven threats — including agentic AI and polymorphic attack vectors your current framework likely isn't ready for.
Start a Conversation →The weakest link isn't your employees — it's the training that bores them into ignoring it. James designs and delivers Human Risk Management programs that shift behavior by treating people as your first line of defense, not your biggest liability. Measurable outcomes, not compliance checkboxes.
Upgrade Your Training →You need a CISO-level mind in the room — just not a full-time CISO salary on the books. As a fractional CISO, James gives growing businesses access to the same strategic oversight that Fortune 500s rely on: policy development, vendor due diligence, incident response planning, and board-level reporting that translates risk into language executives understand.
Schedule a vCISO Consultation →James has spoken at security conferences across the country and earned a reputation as an "edutainer" — someone who makes audiences actually lean in. From deepfakes and agentic AI threats to the psychology of phishing, every session blends technical depth with storytelling that makes the material stick long after the applause fades.
View Speaking Profile →There's no shortage of cybersecurity consultants. There's a real shortage of ones who've been in the field for 25 years, understand industrial systems, and can hold an audience's attention without putting them to sleep.
While others are still debating whether AI is a threat, James is already presenting on agentic AI attacks and polymorphic phishing at national conferences. He's not chasing the trend — he's helping organizations get ahead of it.
A background in musical theatre sounds like an odd credential for a cybersecurity advisor — until you watch him work. James's storytelling ability means clients actually remember his recommendations, and conference audiences actually stay awake.
18 years securing industrial control systems at Siemens Energy gives James a perspective on operational technology risk that most security consultants simply don't have. If your organization touches critical infrastructure, that background is invaluable.
Most security professionals talk about protecting systems. James McQuiggan spent 18 years actually doing it — for industrial control systems at Siemens Energy, where a misconfiguration isn't a data breach headline; it's a power grid outage. That foundation shaped everything: the way he thinks about risk, the way he talks to boards, and the way he refuses to oversimplify the things that actually matter.
"The biggest threat in most organizations isn't the hacker in the hoodie. It's the employee who got a convincing email at 4:57 on a Friday."
After building his career in operational technology security, James turned his focus to the human side of the equation. As an Advisory CISO, he now helps organizations evolve from checkbox security awareness training into genuine Human Risk Management programs — ones that actually change behavior and show measurable results. He's also one of the few advisors already helping clients prepare for the next wave of threats: agentic AI systems that act autonomously and polymorphic attacks that look different every single time.
Here's the part that surprises people: James has a background in musical theatre. It sounds unrelated until you watch him deliver a keynote on deepfakes and notice that nobody in the room is looking at their phone. His "edutainer" approach — equal parts educator and entertainer — is what separates a session people tolerate from one they actually talk about afterward.
As a CISSP, ISC2 chapter leader, adjunct instructor at Full Sail University (where he teaches Cyber Threat Intelligence), and host of the Simply Secured podcast, James stays active in the community not because he has to — but because the field genuinely fascinates him.
James doesn't read from slides. He builds sessions around the questions your audience is already losing sleep over — then answers them in a way that's technically credible, immediately applicable, and genuinely entertaining. Attendees leave with frameworks they can use Monday morning.
What happens when AI doesn't just assist attackers — it acts for them. Built for security conferences, enterprise all-hands, and tech leadership events.
Video is no longer proof. Audio is no longer reliable. This session shows audiences how to verify — and build organizations that don't assume.
Why compliance-based awareness training fails and what a behavior-focused HRM program looks like in practice. Ideal for HR leaders and security teams.
For industrial, energy, and critical infrastructure audiences. Built on 18 real years of doing this work at scale — not theory.
What the threat landscape shift means for the next generation of practitioners. Designed for university programs and early-career events.
Articles, podcast episodes, and takes on what's actually happening in cybersecurity — at jamesmcquiggan.com
Recent Topics
Whether you're exploring a vCISO engagement, want to book James for your next event, or just need a second opinion on your security strategy — the conversation starts here.
Conference organizer?
For fastest response on speaking availability,
submit your request on Sessionize →
Serving clients nationwide · Available for travel