About JBW Group

About Our Compliance & Privacy Advisory Team

We put trusted relationships and quality of work at the heart of all we do.

Who We Are

Compliance Advisory Built for Growing Companies

JBW Group International is a strategic compliance and risk advisory firm serving growing companies navigating increasing regulatory, customer, and AI-driven compliance demands. We specialize in fractional compliance leadership, virtual Chief Privacy Officer services, and ISO 27001 certification support for mid-size organizations.

We work with organizations in the 50–200 employee range — companies large enough to face meaningful compliance exposure from enterprise customers, regulators, and vendor partnerships, but not yet at the scale where a full internal compliance function is practical or necessary.

Our team brings senior-level experience across ISO certification, privacy regulation, vendor risk management, AI governance, and regulatory frameworks including NIST, SOC 2, GDPR, and HIPAA.

Our Approach

Practical Execution Over Theoretical Frameworks

We believe compliance should be an enabler of growth, not an obstacle. Every engagement is scoped to the organization's actual needs, regulatory landscape, and growth trajectory — not a pre-packaged template.

Our Principles

  • Augment, never replace — we strengthen your existing leadership capacity.
  • Structured, not bureaucratic — clear processes without unnecessary overhead.
  • Independent judgment — objective guidance without conflicts of interest.
  • Long-term orientation — relationships built on sustained value, not one-time projects.

Our Team

Experts in Standards-Based
Information Security

All consultants are highly experienced, recognized by the industry, and known for plain-dealing and attention to detail. Click any profile to learn more.

Brock Griffin

Brock Griffin

CDPSE, CISSP, CISA

CEO and Owner

View Profile →

Brock Griffin is an innovative, forward-thinking leader with over 20 years of technical engineering, IT architecture, cybersecurity operations and leadership ex...

John B. Weaver

John B. Weaver

CISSP, CISA, CISM, CPP, CSA — Certified STAR Lead Auditor

Principal Consultant

View Profile →

John is an IRCA-certified ISO 27001 Information Security Auditor and British Standards Institute-qualified in Implementation with more than thirty years' experi...

Cynthia Kriha

Cynthia Kriha

MIM

Chief Operating Officer and ISO Program Manager

View Profile →

Cynthia Kriha has a diverse career in technology leadership focusing on operational excellence, information security, business systems efficiency and continuous...

Robert A. Aanerud

Robert A. Aanerud

Accredited Certifying Body Lead Auditor

Principal Cybersecurity and Privacy Consultant

View Profile →

For over two decades, Robert has been a critical part of the JBW Group family and instrumental in the founding of the company and its success over the years. Ro...

George Bakalov

George Bakalov

CvCISO, CC

Senior Consultant

View Profile →

George Bakalov is uniquely adept at aligning security initiatives with organizational goals stemming from his many years of working with distributed, cross-func...

Kathy Braun

Kathy Braun

MBA, CCE

Principal Consultant, Cybersecurity and Risk Management

View Profile →

Kathy Braun is an experienced cyber risk management consultant, computer forensic investigator, and incident response senior advisor with more than twenty-five ...

Mark Eckel

Mark Eckel

CBCLA, CBCP, ISP, PMP, MBA, MAOM

Principal Consultant

View Profile →

Mark Eckel's business continuity and disaster recovery planning expertise was forged in the aftermath of the 9/11 attacks. For more than 25 years, Mark has appl...

Ainsley A. McKay

Ainsley A. McKay

MAT, Certified ISO 27001 Lead Auditor

Principal Consultant and Knowledge Management Specialist

View Profile →

Ainsley A. McKay is an ISO 27001 lead auditor and knowledge and document management expert with significant experience in the design, delivery, implementation, ...

Keith Parkman

Keith Parkman

CISA, CDPSE, MBA — Certified ISO 9001/27001/42001 Lead Auditor

Principal Consultant

View Profile →

Keith Parkman is an IT professional, information security leader and trainer with proven experience implementing and auditing management systems. He has more th...

Chelsey Pozarnsky

Chelsey Pozarnsky

CIA, Certified ISO 27001 Lead Auditor

Senior Consultant

View Profile →

Chelsey Pozarnsky has extensive internal auditing experience within corporate finance, operations, information security and field audits. She has worked in many...

Milinda Rambel Stone

Milinda Rambel Stone

CISM, CISA, MS, MBA — Certified ISO 27001 and ISO 42001 Lead Auditor

Principal Consultant

View Profile →

Milinda Rambel Stone is an executive security leader with proven experience building and leading security programs and teams, with more than 20 years in technol...

Patrick F. Sullivan, PhD — In Memoriam
In Memoriam

Patrick F. Sullivan, PhD

Principal Consultant

View Profile →

We honor and remember our dear colleague, Dr. Patrick Sullivan, whose passing on February 12, 2025, was sudden and heartbreaking. For over two decades, Patrick was more than an expert in information security and privacy — he was a mentor, a collaborator, and a friend.

Dallas Bishoff — Profile Coming Soon

Dallas Bishoff

Consultant

Profile Coming Soon
Amanda King — Profile Coming Soon

Amanda King

Consultant

Profile Coming Soon

Work With Our Experts

Let's discuss how our team can support your compliance, privacy, and risk management objectives.