Managing Director, Cyber Security and Investigations
Managing Director, Cyber Security and Investigations, Kroll
Stacy Scott is a Managing Director in Kroll’s Cyber Security and Investigations practice, based in Dallas. In addition to founding and operating her own consultancy, Stacy has served in high-profile roles with a leading cyber security consulting firm, a Big Four accounting firm, and the largest not-for-profit healthcare system in Texas. She joined Kroll with over 16 years of experience, during which she built a successful track record of developing and implementing strategic information security initiatives that help organizations better safeguard data, manage risk, and enhance business operations.
Prior to joining Kroll, Stacy was the President and Founder of Wisterwood Advisory Services. From 2014-2016, Stacy served as Vice President, Security Science for Stroz Friedberg in Dallas. She was the firm’s HIPAA Security Rule subject matter expert. From 2006-2014, Stacy was Director, Enterprise Architecture and Security, for Baylor Scott & White Health, the largest not-for-profit healthcare system in Texas, with over 34,000 employees, 5,400 licensed beds, and 43 locations. In this role, which was the healthcare system’s highest-ranking information security position, Stacy directed and oversaw the development and implementation of the enterprise’s overall information security architecture as well as security strategy and programs, managing a multimillion-dollar budget. Stacy’s accomplishments included developing and executing the plan to overhaul security tools in order to mature monitoring processes and rules to enable rapid detection and response to potential security incidents. These efforts reduced the risk of compromise to enterprise systems, including the possible loss of financial data and personal health information.
During this time, Stacy also served as the healthcare system’s HIPAA Security Officer. She possesses a deep understanding of financial and healthcare regulations, including NIST Policy, Federal Trade Commission Red Flag Rules, HIPAA Security Rules, PCI (Payment Card Industry) Data Security Standards, and the American Recovery and Reinvestment Act (ARRA) Health Breach Notification Rule. Stacy also chaired the system’s information security council that worked to assist business users in making the appropriate security risk decisions consistent with the organization’s goals and risk levels. Earlier in her career with Baylor Scott & White, Stacy was Director, Standards, Audit, & Integration; Manager, Internal IT Audit; and Information Security (IS) Security Engineer. Stacy began her professional career as a Senior Information Risk Management Consultant for KPMG, where she conducted assessments of information system security access, change and lifecycle development management, and computer operations for major ERP systems, such as SAP, Oracle, JD Edwards, and PeopleSoft.