Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

Jump to content

Draft:Blake Curtis

From Wikipedia, the free encyclopedia
  • Comment: Promotional resume or CV, not a bibliography of a living person, and shows strong signs of having been compiled using a large language model. Needs to be completely rewritten by a human being. Paul W (talk) 17:46, 23 September 2026 (UTC)


Blake Curtis is a cybersecurity and audit leader, research scientist, and published author associated with security assurance, information security governance, IT audit, risk management, and auditor competency. His public work brings these areas together around a recurring question. How should organizations determine whether a person can perform a security or audit task, rather than rely on job tenure, a credential list, or completed paperwork alone? In 2023, Cyber Security Hub included Curtis in a feature on cybersecurity leaders and described his work in security assurance at Amazon, together with earlier positions at Vanderbilt University, Cigna, and Deloitte.[1]

Curtis’s doctoral work examines the relationship between IT auditor competency, audit quality, and data breaches. Computer security scholar Bill Buchanan discussed the study’s question, sample, and reported findings in 2023.[2] The research, his professional writing, and later interviews connect capability to the work people actually perform, the evidence they can interpret, and the decisions they can defend.

Education and research

[edit]

Curtis completed the doctoral dissertation “Creating the Next Generation Cybersecurity Auditor: Examining the Relationship Between IT Auditors’ Competency, Audit Quality, and Data Breaches” in 2022. The ProQuest record identifies the work by publication number 2680312317. Buchanan’s reference identifies Capitol Technology University.[3][2]

ISACA’s Industry Spotlight adds personal context to the academic record. The interview describes a nontraditional educational path, including growing up in a small town, completing a master’s degree in 10 weeks, and producing a 600-page dissertation. These details help explain why Curtis’s work returns repeatedly to deliberate study, professional development, and demonstrable capability.[4] The dissertation is a quantitative study of IT auditors and subject matter experts. Its professional question is direct. Audit quality depends on the knowledge, technical judgment, and task-level capability available when an auditor must evaluate evidence and controls.[2]

Career

[edit]

In a 2020 ISACA Journal author biography, Curtis was identified as an information security and compliance adviser for Cigna’s Global Security Assurance Team. The same profile described a foundation in engineering, networking, virtualization, IT service management, cybersecurity, and risk management. In that conversation, he connected governance frameworks and controls to the daily technical work of security and audit professionals.[5] In 2022, an ISACA podcast described him as a global business risk and security engineer for Deloitte Global while completing doctoral research in cybersecurity and risk management.[6] Cyber Security Hub described Curtis as a senior technical program manager in security assurance at Amazon and identified prior work at Vanderbilt University, Cigna, and Deloitte.[1] The SFIA specialist profile also describes a progression from systems engineering to governance, risk, architecture, assurance, and AI-related work. Curtis’s public professional profile identifies Capital One as his current organization.[7][8]

Publications

[edit]

Books and manuals

[edit]

Curtis is credited as an author of the CISM Review Manual, 17th edition, published by ISACA. The manual is an examination preparation and reference resource for information security management.[9] The SFIA profile also identifies three longer-form book projects that extend the same professional interests. “Cybersecurity & AI Auditing” addresses evidence-centered audit work in AI, cloud, and automated environments. “The Truth Trap” focuses on research credibility and evidence evaluation. “Self-Governance” addresses attention and decision-making under pressure.[7]

Articles and professional publications

[edit]

ISACA Journal published “Are Organizations Actually Performing Risk-Based Audits?” under Curtis’s byline on 5 August 2020. The article contrasts compliance-based and risk-based audit approaches, including the use of risk appetite and risk tolerance in audit planning. It argues that auditors should connect strategic, operational, and technical conditions and should assess evidence in the context of the organization’s risk expectations.[10] Security Magazine published “Technical Competency Gaps in 151,000 IT Auditors in the Audit Industry” under Curtis’s byline on 1 November 2022. The article addresses the technical skills used in IT audit work. Together, the two articles show Curtis’s interest in both the design of a risk-based audit and the capability of the people performing it.[11]

Academic work

[edit]

The doctoral dissertation is Curtis’s principal identified academic work. The study gives a research foundation to a broader professional argument. Years in a role may provide experience, yet task relevance, technical feedback, and observed performance are needed to assess whether that experience developed the capability a particular audit requires.[7] Buchanan’s discussion describes it as a quantitative study of IT auditors and subject matter experts.[3][2]

Public commentary and appearances

[edit]

ISACA published the 2022 podcast “From the Board Level to the Code Level,” featuring Curtis. The episode describes his approach to moving between governance frameworks, management decisions, and technical controls. It also introduces his distinction between years of experience and years of exposure.[6]

ISACA published a 2022 Industry Spotlight interview with Curtis on professional development, doctoral research, and IT audit workforce questions. The conversation makes the biography more human by connecting his career development with education, deliberate learning, and the need to give emerging professionals practical routes into the field.[12]

AI Cyber Magazine included a quotation attributed to Curtis in its “What Actually Governs Shadow AI?” expert panel. His contribution frames AI governance as a working practice that gives everyday users an approved route while sending higher-risk uses through additional review.[13]

Lumivero published “Streamlining the Dissertation Writing Process” in 2023. The case study discusses Curtis’s use of Citavi in organizing sources and developing the dissertation. It documents the research workflow behind the doctoral project, including literature organization and citation management.[14]

Security Confidential listed Curtis as a guest on “Are We Measuring Cyber Talent Wrong?”. The episode title reflects the same capability question that appears in his research, writing, and public teaching.[15]

Professional approach

[edit]

Across this work, Curtis’s professional approach has three connected features. He translates technical controls into decisions that leaders and audit teams can understand. He asks for evidence of actual capability rather than treating credentials or tenure as a complete answer. He uses writing, research, and teaching to make those questions accessible to practitioners who need to act on them.[6][10][7]

References

[edit]
  1. 1 2 "The Top 25 Leaders in Cyber Security 2024". Cyber Security Hub. 19 October 2023.
  2. 1 2 3 4 Buchanan, Bill (10 April 2023). "Assessing Skill Levels of IT Auditors". Medium.
  3. 1 2 "Creating the Next Generation Cybersecurity Auditor: Examining the Relationship Between IT Auditors' Competency, Audit Quality, and Data Breaches". ProQuest.
  4. "Industry Spotlight with Dr. Blake Curtis, Part II". ISACA.
  5. "Are Organizations Actually Performing Risk-Based Audits?". ISACA Journal. ISACA. 5 August 2020. author biography.
  6. 1 2 3 "From the Board Level to the Code Level". ISACA. 6 January 2022.
  7. 1 2 3 4 "Dr Blake Curtis". SFIA Foundation.
  8. "Dr. Blake Curtis, Sc.D". LinkedIn.
  9. CISM Review Manual (17th ed.). ISACA. p. v. ISBN 9798892270748.
  10. 1 2 "Are Organizations Actually Performing Risk-Based Audits?". ISACA Journal. ISACA. 5 August 2020.
  11. "Technical Competency Gaps in 151,000 IT Auditors in the Audit Industry". Security Magazine. 1 November 2022.
  12. "Industry Spotlight with Dr. Blake Curtis, Part II". ISACA.
  13. "What Actually Governs Shadow AI?". AI Cyber Magazine.
  14. "Streamlining the Dissertation Writing Process". Lumivero. 11 April 2023.
  15. "Security Confidential S20 E02, Dr. Blake Curtis". Dark Rhiino Security.