David Tortora

Security Incident Commander · Former Cybercrime & Financial Crimes Detective · Publisher, State of the Threat · Attack · Defense

Building teams and processes that outlast any one person.

What I Do

01

Incident Command

Single point of command for critical security incidents at Thrive. Direct internal teams, external partners, and client leadership through containment and remediation. Coordinate with FBI, CISA, the UK's NCSC, and other national agencies when required.

02

Investigations

Ten years of financial crime, cybercrime, and digital forensics experience. That background drives how I approach incident response and threat analysis today.

03

Executive Advisory

Translate technical threat data into business impact during active incidents. Advise C-suite executives on exposure, options, and next steps so leadership can make informed decisions under pressure.

Background

I started in IT, managing networks and servers for a school district. That gave me a foundation in how systems are built and where they break. When I joined the Marine Corps, I went from maintaining infrastructure to leading people. I rose to Staff Sergeant, directing teams of 60+ on security and electrical projects stateside and overseas.

Law enforcement was a natural next step. I came in through corrections and patrol, but the cases that pulled me in were all digital: fraud, identity theft, cybercrime. I made detective, then senior detective, and built the department's forensics capability from nothing. I secured grant funding for cryptocurrency tracing tools, trained other detectives to use them, and spent ten years working those cases. There is no cybercrime without crime, and understanding both sides matters.

Now I command incident response at Thrive. The job is the same job it's always been: figure out what happened, take charge, protect people. Just at a different scale.

Experience

Security Incident Commander
Thrive · 2025 to Present

Sole incident commander for a global client base. Direct every critical incident from declaration through restoration, and build the function alongside the casework: playbooks, automation, and federal coordination with the FBI, CISA, and the UK's NCSC.

Detective, Cybercrime & Financial Crimes
Bergenfield Police Department · 2015 to 2025

Ten years of financial crime, cybercrime, and digital forensics. Built the department's forensics capability from nothing, secured grant funding for cryptocurrency tracing, and worked a caseload spanning graffiti to homicide.

I publish three cybersecurity newsletters: State of the Threat, State of the Attack, and State of the Defense.

Writing

Essays and analysis on cybersecurity, AI, investigations, and leadership: the pieces that do not fit the State-of newsletters.

Get in Touch

Always interested in connecting with people working in cybersecurity operations, incident response, and security leadership.

Connect on LinkedIn