About Forrester
Forrester Research, Inc. is an independent research company that provides pragmatic and forward-thinking advice to global leaders in business and technology.

Andy is a member of Forrester's Business Technology Futures team, which serves CIOs and their business partners by predicting the long-term business impact of information technology. His research focus is on smart computing and analytics and tech-driven business transformation, analyzing the shifting economics of the industry, including spending, budgeting, and the influence of macroeconomic trends.
He also researches the growing customization of IT systems for industry-specific applications, especially in the utilities, energy, and professional services sectors. He is also a thought leader in the sourcing and procurement technology markets.
Andy has extensive experience in the technology market and in strategic planning, both as an analyst and a practitioner in the business world. He came to Forrester through its acquisition of Giga Information Group in 2003, where he had worked as a vice president and research leader since 1998. Prior to joining Giga, Andy held a variety of vice president positions at American Express in the chairman's office, technologies, strategic planning, and re-engineering. Before joining American Express, Andy worked as an economist, writer, and editor for various organizations, including Shearson Lehman Brothers; the US House of Representatives' Committee on Banking, Finance, and Urban Affairs; and the Council on Wage and Price Stability in the Executive Office of the President.
Andy has been a regular participant in Forrester's IT Forum conferences, delivering keynote addresses in 2006 and 2007 with colleagues on the future of software. He has also been a recurring presenter at Conference Board conferences on eProcurement and eSourcing. He has been quoted in leading business and technology publications, including BusinessWeek, The Economist, The New York Times, and The Wall Street Journal.
Andy earned a B.A. in philosophy from Haverford College and a Ph.D. in history from Johns Hopkins University.
An Empowered Report: Getting Past Cloud Security Fear Mongering
At Forrester's Security Forum 2010 in Boston, Eran Feigenbaum, director of security, Google Apps; and Archie Reed, chief technologist for cloud security at HP, joined me on stage for a keynote panel...
As a consequence of increasing global commerce, security and risk (S&R) professionals face the complexity of navigating data privacy regulations from around the world. Forrester clients frequently...

Enterprise Benchmark Considerations For Budgets, Challenges, And Planning
Today's organizations face aggressive cost-cutting and efficiency pressures that drive businesses to consider cloud sourcing solutions. While the many properties of cloud services, such as...
By 2012, OAuth Will Be The Incumbent Cloud API Security Solution
Enterprises face a tension between the cloud-friendly software environment promoted by the Web, with its easy-to-use REST interface style and proliferation of lightweight services, and the security...
This month I published a new report on information security metrics, best practices as well as a maturity model to measure your maturity in the reporting process. This report outlines the...
The cyberinsurance market has existed for longer than most would guess. In fact, insurance companies wrote the first cyberinsurance policies more than a decade ago. Since cyberinsurance first emerged...
Have you ever been in a vendor meeting and heard the vendor extol the greatness of their threat intelligence? You may have even seen a slide that looks similar to this: The vendor probably...
Essential Functionality For The Zero Trust Model Of Information Security
In today's threat environment, the network perimeter has disappeared. Insiders are as insidious a threat as outsiders. In the past, the "trust but verify" model did not facilitate insight into...
"My master made me this collar. He is a good and smart master and he made me this collar so that I may speak. Squirrel!" In the Pixar film Up, squirrels frequently distract Dug the talking...
We have several questions: 1) How do companies manage employee Internet access? 2) How do they authenticate employees? 3) How do they block access to unwanted applications? 4) How can we block...
Be Ready To Comply With Dynamic Regulatory Changes
Understanding the laws and regulations that govern data privacy across your organization is critical for any company, but it can be challenging. As a result, too many security and risk (S&R)...
Among risk professionals who have successfully navigated their organization through a crisis, almost all will say that they had grossly underestimated the difficulty of communicating effectively...
Back in July, I wrote about a new RESTful API that cloud providers and provisioning vendors are working on for doing identity provisioning and synching: Simple Cloud Identity Management, or SCIM...
Forrester Research And ARMA International Records Management Online Survey, Q3 2010
Successful records management helps your organization comply with regulatory requirements, ease eDiscovery burdens, and meet information governance objectives. In pursuit of these goals, nearly...
Endpoint Security Suites Take Center Stage In The Enterprise
In Forrester's 50 criteria evaluation of endpoint security vendors, we identified nine top providers in the category — F-Secure, IBM, Kaspersky, LANDesk, Lumension, McAfee, Sophos, Symantec,...

To effectively deal with the broad and complex requirements of Payment Card Industry (PCI) data security, you need to break the elements apart to provide enhanced clarity. We've designed the PCI...
Policy And Procedures: The S&R Practice Playbook
Over recent years, the information security industry has matured nicely; experts and associations have documented many best practice models, and their adoption has been widespread. It's disconcerting...
You are now no doubt aware that Boston-based security firm Bit9 suffered an alarming compromise, which resulted in attackers gaining access to code-signing certificates that were then used to sign...
The rapid adoption of mobile devices and cloud services together with a multitude of new partnerships and customer-facing applications has extended the identity boundary of today’s enterprise....
As information security matures into a formal discipline, it needs formal governance mechanisms. Over the past 12 months, Forrester has seen increased interest and activity in establishing security...
Strategic Plan: The Governance, Risk, And Compliance Playbook
Governance, risk management, and compliance (GRC) are far too often positions of emergency response. What's worse, as you constantly rush to respond to new mandates, enforce policies, or pull...
