About JBW Group
About Our Compliance & Privacy Advisory Team
We put trusted relationships and quality of work at the heart of all we do.
Who We Are
Compliance Advisory Built for Growing Companies
JBW Group International is a strategic compliance and risk advisory firm serving growing companies navigating increasing regulatory, customer, and AI-driven compliance demands. We specialize in fractional compliance leadership, virtual Chief Privacy Officer services, and ISO 27001 certification support for mid-size organizations.
We work with organizations in the 50–200 employee range — companies large enough to face meaningful compliance exposure from enterprise customers, regulators, and vendor partnerships, but not yet at the scale where a full internal compliance function is practical or necessary.
Our team brings senior-level experience across ISO certification, privacy regulation, vendor risk management, AI governance, and regulatory frameworks including NIST, SOC 2, GDPR, and HIPAA.
Our Approach
Practical Execution Over Theoretical Frameworks
We believe compliance should be an enabler of growth, not an obstacle. Every engagement is scoped to the organization's actual needs, regulatory landscape, and growth trajectory — not a pre-packaged template.
Our Principles
- Augment, never replace — we strengthen your existing leadership capacity.
- Structured, not bureaucratic — clear processes without unnecessary overhead.
- Independent judgment — objective guidance without conflicts of interest.
- Long-term orientation — relationships built on sustained value, not one-time projects.
Our Team
Experts in Standards-Based
Information Security
All consultants are highly experienced, recognized by the industry, and known for plain-dealing and attention to detail. Click any profile to learn more.
Brock Griffin
CDPSE, CISSP, CISA
CEO and Owner
Brock Griffin is an innovative, forward-thinking leader with over 20 years of technical engineering, IT architecture, cybersecurity operations and leadership ex...
John B. Weaver
CISSP, CISA, CISM, CPP, CSA — Certified STAR Lead Auditor
Principal Consultant
John is an IRCA-certified ISO 27001 Information Security Auditor and British Standards Institute-qualified in Implementation with more than thirty years' experi...
Cynthia Kriha
MIM
Chief Operating Officer and ISO Program Manager
Cynthia Kriha has a diverse career in technology leadership focusing on operational excellence, information security, business systems efficiency and continuous...
Robert A. Aanerud
Accredited Certifying Body Lead Auditor
Principal Cybersecurity and Privacy Consultant
For over two decades, Robert has been a critical part of the JBW Group family and instrumental in the founding of the company and its success over the years. Ro...
George Bakalov
CvCISO, CC
Senior Consultant
George Bakalov is uniquely adept at aligning security initiatives with organizational goals stemming from his many years of working with distributed, cross-func...
Kathy Braun
MBA, CCE
Principal Consultant, Cybersecurity and Risk Management
Kathy Braun is an experienced cyber risk management consultant, computer forensic investigator, and incident response senior advisor with more than twenty-five ...
Mark Eckel
CBCLA, CBCP, ISP, PMP, MBA, MAOM
Principal Consultant
Mark Eckel's business continuity and disaster recovery planning expertise was forged in the aftermath of the 9/11 attacks. For more than 25 years, Mark has appl...
Ainsley A. McKay
MAT, Certified ISO 27001 Lead Auditor
Principal Consultant and Knowledge Management Specialist
Ainsley A. McKay is an ISO 27001 lead auditor and knowledge and document management expert with significant experience in the design, delivery, implementation, ...
Keith Parkman
CISA, CDPSE, MBA — Certified ISO 9001/27001/42001 Lead Auditor
Principal Consultant
Keith Parkman is an IT professional, information security leader and trainer with proven experience implementing and auditing management systems. He has more th...
Chelsey Pozarnsky
CIA, Certified ISO 27001 Lead Auditor
Senior Consultant
Chelsey Pozarnsky has extensive internal auditing experience within corporate finance, operations, information security and field audits. She has worked in many...
Milinda Rambel Stone
CISM, CISA, MS, MBA — Certified ISO 27001 and ISO 42001 Lead Auditor
Principal Consultant
Milinda Rambel Stone is an executive security leader with proven experience building and leading security programs and teams, with more than 20 years in technol...
Patrick F. Sullivan, PhD
Principal Consultant
We honor and remember our dear colleague, Dr. Patrick Sullivan, whose passing on February 12, 2025, was sudden and heartbreaking. For over two decades, Patrick was more than an expert in information security and privacy — he was a mentor, a collaborator, and a friend.
Dallas Bishoff
Consultant
Profile Coming SoonAmanda King
Consultant
Profile Coming Soon