About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Khalid serves CIOs, leading the team responsible for delivering research and advisory services to IT leaders. He provides strategic guidance and advice to clients in the areas of organization design; governance, risk, and compliance (GRC); and emerging technologies. His research focuses on helping clients mature from an IT-centric role in their organizations to a business-embedded one. Khalid has extensive experience working with the government, healthcare, and financial services sectors.
Khalid has been widely quoted in the press, including such media outlets as MSNBC, The Boston Globe, CIO Magazine, and The Wall Street Journal. Khalid is a frequent keynote speaker at national and international conferences.
Before joining Forrester, Khalid worked for a global insurance company where he provided leadership and direction for the information security program. Prior to this, he worked as a consultant and program manager at a telco, helping clients with IT strategy and architecture.
Khalid holds master's degree in networks and telecommunications management from the University of Pennsylvania and a bachelor's degree in business and economics from the University of Texas at Austin.
Assessment Framework: The S&R Practice Playbook
This report outlines the assessment framework associated with Forrester's solution for security and risk (S&R) executives. The report is designed to help CISOs as they continue working their way...

Firms Must Improve The Maturity Of Their Services To Remain Relevant
While it hasn't always been seen in the past as the earliest adopter of information security technologies or the largest market for information security services, the US federal government is...
The cyberinsurance market has existed for longer than most would guess. In fact, insurance companies wrote the first cyberinsurance policies more than a decade ago. Since cyberinsurance first emerged...
Governance, Maturity, And Analytics Are The Major Themes For 2011
Every winter Forrester outlines 12 important recommendations for your security strategy for the coming year. We base these recommendations on hundreds of client inquiries, numerous consulting...
As information security matures into a formal discipline, it needs formal governance mechanisms. Over the past 12 months, Forrester has seen increased interest and activity in establishing security...
Understand The New Threat Paradigm To Make Your Responses More Effective
The information security threat landscape is changing rapidly, and many security organizations are struggling to keep up with the changing nature, complexity, and scale of attacks. Not only is it...
In Forrester's 78-criteria evaluation of managed security services providers (MSSP), we found that IBM and SecureWorks led the pack because of flexibility, competency, and breadth of coverage. While...
Deloitte Leads The Pack, With PricewaterhouseCoopers, Ernst & Young, And Accenture Close Behind
In Forrester's 75-criteria evaluation of information security and risk consulting service providers, we found that Deloitte led the pack because of its maniacal customer focus and deep technical...
The Forrester Information Security Maturity Model is a framework that consists of four main security domains (oversight, technology, process, and people) with 25 functions and 123 low-level...

Only a few years ago, the vast majority of chief information security officers (CISOs) reported to the CIO. Their task was to run and manage the technical and operational security infrastructure....
Look Beyond Cost Savings And 24x7 Support To Select An MSSP
The managed security services market is growing at a healthy clip due to a confluence of several factors, most notably staffing and skill pressures, an ever-evolving threat landscape, and an...

The scope of IT security continues to expand, and with it the visibility of the security organization is rising. Most security organizations now regularly engage with executives and business...
As we enter 2010 and look ahead, the challenges we face are very familiar. The technology has been changing as usual, the business has been demanding more and more from security professionals as...
Intel, a large global technology provider, has more than 86,000 employees worldwide. It's only natural that, working for a technology provider, Intel's employees are generally ahead of the curve in...
Many chief information security officers (CISOs) are forced to respond to security breaches with little knowledge or planning. Not only is it important to have the tools for responding to security...
With increasing workforce mobility and the extension of the business supply chain globally, organizations are struggling to keep up with increasing corporate and regulatory compliance requirements....
Applying Five Cardinal Rules Of Information Security To Healthcare Companies
The US Congress enacted the Health Insurance Portability and Accountability Act (HIPAA) in 1996. The security and privacy rules took effect in 2003, but none of this really improved the overall state...
Many CISOs struggle to articulate the value of their security programs and justify the security budget to business and executive management. This problem was acutely evident in the current economic...
John Petrie at Harland Clarke was lucky to report directly to executive management, and he reported on a routine basis to the executive management team on information security issues. This gave him a...
Jim Routh at DTCC took a unique approach in developing his security metrics program. He identified all of the processes that the security team was responsible for and then defined a process owner for...
Includes a real world example of a security metrics dashboard courtesy of Eastman Kodak Company.
Eastman Kodak's matrixed organizational structure enables its business units to act quickly in response to changing business conditions, but it also creates a decentralized security function....
Deloitte And PricewaterhouseCoopers Lead, With Accenture Close Behind
In Forrester's 72-criteria evaluation of information security and IT risk consulting service providers, we found that Deloitte and PricewaterhouseCoopers (PwC) lead the pack because of their superior...
Security professionals have been complaining for years about their inability to influence the organization and that information security is a thankless job. Recent conversations with CISOs and data...
Many security predictions paint a doomsday scenario where a crippling cyberattack will leave us all reeling from its effects or Supervisory Control and Data Acquisition (SCADA) systems...