David J. Tortora
Summary
Cybersecurity leader who builds programs that outlast any one person. Sole Incident Commander providing 24/7 coverage for Thrive, an international MSSP serving 2,000+ clients globally; 200+ P1/P2 incidents directed since June 2025.
Background spans the U.S. Marines (three tours in Iraq, platoon-scale leadership) and a decade as a senior detective in financial crime, cybercrime, and digital forensics, bringing an investigator's lens to enterprise risk. Coordinates with FBI, CISA, and the UK NCSC on multi-jurisdictional matters.
Author of State of the Threat, State of the Attack, and State of the Defense. One intelligence shop, three perspectives: the threat brief tells your board what's coming, the attack analysis shows your SOC what it looks like, and the defense case study shows your team why the controls that should have been there weren't.
Leadership Highlights
- Built a function from zero. Stood up Thrive's Incident Commander capability and directed 200+ incidents through it. Built trust with internal teams and client executives. Built the processes that hold up under pressure. Led every major engagement since.
- Led the ransomware recovery that converted a $500K contract. Led incident response for a non-Thrive prospect during an active ransomware event. The trust earned during the engagement converted the relationship into a $500K contract.
- Compressed industry-standard recovery timelines. Led ransomware recovery for a client with 10 encrypted servers: containment through restoration in 24 hours against the 5-to-7-day industry standard. Operations restored by the next business day.
- Designed Thrive's IR program architecture. Authored the CRU (Containment & Remediation Unit) business proposal. Designed the Deputy IC role to scale CIRT capacity. Built the CIRT Readiness program with executive tabletop exercises (TTX) for client decision-making under real-incident pressure.
- Initiated Thrive's NCSC partnership. UK client notifications now arrive at Thrive ahead of NCSC's direct outreach, enabling coordinated response before the client is contacted.
Core Competencies
Security Strategy & Program Design · Incident Response & Crisis Command · Executive Risk Communication · Breach Counsel & Cyber Insurance Coordination · Federal Agency Coordination (FBI, CISA, NCSC) · Financial Crime & Fraud Risk · Digital Forensics Program Leadership · Threat Intelligence Strategy & Publication · NIST CSF · CMMC · PCI-DSS · MITRE ATT&CK · Team Development & Mentorship
Experience
Sole Incident Commander for a global client base. Direct every P1 and P2 incident from the West Coast to Hong Kong, from declaration through restoration. Build the function alongside the casework: playbooks, automation, supporting roles, and partnerships.
- Program build. Shipped processes, playbooks, and knowledge base articles for the Incident Commander function. Tested playbooks. Post-incident reviews that change behavior. Includes the CRU business proposal, Deputy IC role design, and CIRT Readiness program with executive TTX.
- Executive advisory during incidents. Translate threat data into business impact for C-suite leadership during active incidents. Deliver facts, options, and pathways forward in real time.
- Breach response coordination. Run the breach-response coalition during active incidents: in-house and external breach counsel, third-party forensic firms, and the cyber insurance carrier. Read where the matter is heading (litigation, regulator, or claim) and preserve the evidence, chain of custody, and privilege each party needs before they ask for it, so the coalition works from a clean foundation instead of rebuilding it after the fact.
- Federal and international coordination. Coordinate with FBI, CISA, and UK NCSC on multi-jurisdictional matters. Initiated Thrive's NCSC partnership; UK client notifications now arrive ahead of NCSC's direct outreach.
- Cross-region program leadership. Stood up IC Office Hours as a recurring engagement for vCISOs and Service Delivery UK, aligning incident response practices across regions.
Hundreds of cases over a decade, from graffiti to homicide, with specialization in financial crime, cybercrime, and digital forensics. Worked million-dollar fraud cases using digital forensics, OSINT, and blockchain analysis. Coordinated with FBI and federal partners on complex matters.
- Built the department's digital forensics program from zero. Established procedures, acquired tooling, and trained detectives to handle digital evidence independently. No prior capability or budget.
- Secured grant funding for cryptocurrency tracing tooling. Identified the need, coordinated funding, integrated into investigative workflows, and trained the team. Zero cost to the department.
- Designed and ran a fraud awareness program for local businesses. Deployed detection tooling and ran workshops that measurably reduced fraud vulnerability across the community.
- Closed a cold case missing persons case dating to the 1970s. Maintained continued engagement with the family over years; coordinated with NamUs to secure a DNA match that closed the case.
- Designed and delivered an active-shooter response program for 40+ personnel. Scenario design, facilitated drills, and readiness measurement.
- Court testimony, evidence handling, and chain of custody across financial crime, cybercrime, and digital forensics cases.
- Made scene-level decisions during criminal incidents, domestic violence, and mental health crises. Ran preliminary investigations, directed scene preservation, and coordinated handoffs to detectives.
- Drove patrol operations compliance that contributed to the department's successful CALEA national accreditation.
- MADD Enforcement Award recipient for DUI enforcement results.
- Designed and launched a cross-training program across housing units that reduced overtime costs and improved shift coverage facility-wide.
- Responsible for security and regulatory compliance across a 1,000+ inmate population.
- Three tours in Iraq. Led teams scaling from a handful of Marines to a full platoon across domestic and international deployments. Each tour brought more responsibility; earned accelerated promotions across the deployment cycle.
- Developed 50+ junior Marines and Naval officers through cross-branch mentorship; 10 promoted under supervision.
- Supported systems, networks, and servers across six schools.
- Contributed to district-wide upgrades including hardware refresh, software, and security tool deployments.
Certifications
Specialized Training
- Threat Modeling: Embracing Worst-Case Scenarios
- Critical Infrastructure Resilience
- Critical Asset Risk Management
- FBI Basic Historical Cell Site Analysis
Community & Industry Leadership
Publishing
State of the Threat (stateofthethreat.com). A weekly brief for the executive who has to answer to the board, the one asking "What am I missing?" Most risk intelligence is written for technical readers. Between the threat feed and the CFO, the translation breaks down. Boards do not speak CVSS or OFAC. They speak risk, revenue, and reputation. Each week, connect the dots on the forces outside their control: wars, state actors, regulatory shifts, supply chain cascades, energy markets, undersea cables, and translate what those forces mean for the business they are protecting.
State of the Attack (stateoftheattack.com). Step-by-step kill chain analysis built from first-party observations. The payload they dropped, the commands they ran, the infrastructure they built, the mistakes they made. Every piece is published because we watched the attack happen. For the detection engineer writing signatures, the incident responder trying to figure out if they've seen this before, and the CISO who wants to show the board what the threat actually looks like when it lands.
State of the Defense (stateofthedefense.com). Real attack patterns rebuilt through fictional companies to expose where people failed, where process failed, and where technology failed. The three-legged stool. Most incidents don't happen because all three legs break at once. They happen because one leg was never there and the other two were expected to compensate.
Awards
Various awards, medals, and commendations across U.S. Marine Corps, Bergenfield Police Department, and PBA Local 309.