Reducing Delays Across a Global Cybersecurity Portfolio
Managing more than 15 cybersecurity initiatives for the Disney vice president’s information-security office, I established a common process for tracking delivery, overdue actions, dependencies, risks, and decisions across technical and business teams. Within six months, portfolio delays fell 30%, based on delayed initiatives, overdue actions, and schedule variance. I also built executive reporting and led a 10-analyst reporting effort to develop more than 20 performance measures for the information-security organization.
Challenge
The vice president’s office managed more than 15 concurrent cybersecurity initiatives covering compliance, testing, remediation, training, business readiness, and related security work. Delivery responsibilities spanned several technical and business functions, while the information needed to manage the portfolio sat across different teams, systems, and recurring discussions.
That fragmentation made it harder to see which initiatives were falling behind, where overdue actions required intervention, how dependencies affected schedules, and which issues needed a leadership decision. The office needed a more consistent way to manage the portfolio.
Approach
I established a common process for reviewing the portfolio. I grouped initiatives for review, clarified owners and deadlines, tracked delayed work and dependencies, separated active issues from future risks, and maintained records of actions and decisions. I also changed the reporting structure so reviews focused on work requiring a decision, assigned action, priority change, or escalation.
Additionally for executive reporting, I consolidated technical, compliance, operational, and delivery information into recurring briefings and dashboards. I verified inputs before presenting them, separated general status from decisions and required actions, and directed leadership attention toward matters requiring intervention. Through this process, I produced more than 20 executive briefings and dashboards.
I also led a 10-analyst team effort that developed more than 20 KPIs for the information-security organization. We focused the measures on information that leaders could use to assess performance and make decisions rather than producing metrics simply because data existed.
My Role
I served as Chief of Staff within Disney’s information-security organization, directly supporting a vice president’s office. My leadership relied on portfolio, project, and matrix authority rather than formal direct reports.
I held delegated authority over portfolio-management processes, executive briefing structure and content, meeting design, documentation, follow-through, and recommendations. I coordinated employees, contractors, security specialists, engineers, compliance personnel, application owners, and business teams across the portfolio. Corporate and technical leaders retained final policy and technical authority.
Results
The portfolio-management changes produced measurable improvements in delivery, decision speed, and performance measurement:
Reduced portfolio delays by 30% within six months across more than 15 cybersecurity initiatives by clarifying ownership and deadlines, tracking overdue actions and schedule variance, and restructuring portfolio reviews.
Improved the speed of supported leadership decisions by 20% through more than 20 executive briefings and dashboards that separated general status from decisions and required actions.
Led a 10-analyst reporting effort that developed more than 20 KPIs, improving leadership’s ability to quantify information-security portfolio performance by 40% within six months.