


Greg Bee is an accomplished CISO with extensive IT and business administration qualifications. He brings over thirty-nine years of experience in IT and risk management, with twenty-four years specifically as a CISO in leading insurance and financial firms. His career showcases a healthy skill set in managing complex security infrastructures and implementing information security best practices.
Bee's educational background includes an IT degree, MBA and certifications like C|CISO, CISM, CISA, CRISC and CGEIT. He is recognized as a top 100 CISO by Security Connect for three consecutive years from 2021 to 2024. This highlights Bee's cybersecurity expertise and significant contributions to his organizations and the broader community. He is known for his commitment to nurturing future cybersecurity leaders through teaching at secondary institutions and serving on cybersecurity boards.
How has been your journey so far?
I began my career journey as a CISO in 2000 at Country Financial in Bloomington, Illinois. I initially focused on application development before transitioning to information security management. Over the years, I have grown our security program from a small team to leading a division of 75 professionals by 2018. This experience equipped me for positions at Horace Mann Insurance and Pekin Insurance, where I successfully integrated cyber risk management into enterprise strategies, focusing particularly on SOX compliance and meeting the expectations of public companies.
Finally, in late 2023, I moved to Hagerty, where we are currently continuing efforts to establish a comprehensive information security program that would be considered a leader in the insurance industry. Emphasizing GRC, we are pursuing ISO certification while addressing SEC and SOX requirements. Our proactive approach includes implementing advanced security controls like zero trust architectures to systematically safeguard organizations. Throughout my career—from foundational security development to strategic risk integration—continuous learning and growth have defined my approach to protecting organizations in the evolving cybersecurity landscape.
What specific challenges or pain points do you encounter as a CISO?
One of the primary challenges I face as a CISO is keeping pace with bad actors’ evolving tactics aimed at compromising organizational assets. Adversaries possess significant resources and motivation to exploit vulnerabilities, making it essential for our security programs to be resilient and multi-layered. While preventing every incident is ideal, our readiness to swiftly respond and contain breaches is crucial to safeguarding the organization's reputation. Beyond technical defenses, my role extends to aligning cybersecurity initiatives with business objectives and fostering collaboration across departments like legal, HR and finance. The security program not only is designed to protect company reputation from bad actors, but also aligned to business to support overall company objectives.
“Stay proactive and keep pushing forward to safeguard your organization against evolving threats and challenges in the cybersecurity landscape.”
Effective communication with stakeholders is crucial to ensure they understand how cybersecurity measures support and protect the company's reputation and compliance obligations. This is critical in heavily regulated sectors such as insurance and a publicly traded company like Hagerty. Navigating these dual challenges of technical agility in cybersecurity and strategic alignment with business goals defines my role, requiring constant adaptation to adversary tactics while advocating for risk management strategies across the organization.
What strategies or innovations have you implemented to address challenges in emerging technological trends?
As a public company, we focus on ensuring stakeholder confidence and credibility while complying with regulations. However, as a seasoned CISO and lecturer with over 24 years of experience, I stress that adherence alone does not ensure security. Leveraging compliance frameworks to cultivate resilient security practices and infrastructure is vital. This approach integrates security measures into compliance efforts, ensuring they are not just checkboxes but strategic steps toward enhancing overall security and resilience. By aligning compliance with effective controls and policies, we strengthen the organization's security posture and resilience across our ecosystems.
Could you share any recent project initiatives you have been involved in?
I’m focusing on implementing external assessments of Hagerty’s security program to identify gaps and improve security posture. These assessments provide valuable insights and expertise, enabling informed discussions with executive management. The goal is to mitigate these gaps through resource acquisition, tool refinement or process enhancement. We believe these assessments are about compliance and continuous improvement in maintaining a defense strategy, ensuring better protection and stakeholder trust.
How do you foresee the future role of a CISO amidst ongoing transformations?
The role of CISOs is evolving due to technological disruptions, necessitating their integration into IT development and ecosystem transformations. AI can enhance security practices, particularly in GRC, by enabling proactive risk management, agile control development and alignment with project frameworks. This approach strengthens organizational defenses, fosters innovation and supports business growth. AI is also pivotal in navigating threats and enabling forward-looking security transformations.
What is your advice to fellow peers and aspiring professionals in the industry?
My advice to CISOs and aspiring professionals is to prioritize continuous improvement in their security programs. Continuous improvement efforts should emphasize the importance of embracing external and internal assessments to identify vulnerabilities and areas for improvement. This also emphasizes aligning security initiatives with the company's broader goals and reputation. I encourage assertive, cautious and proactive efforts to safeguard against evolving threats and challenges in the cybersecurity landscape.