About Melissa Thornton

Founder and Fractional CISO, Cybersecurity Advisory Group

Melissa Thornton, founder and fractional CISO of Cybersecurity Advisory Group, White Plains, New York

Fractional CISO · White Plains, New York

Before I was a CISO, I was a CEO.

Certifications

CISSP · C|CISO

Education

BBA, Pace University · Tuck WBENC Executive Program, Dartmouth

Affiliations

HSCC Cybersecurity Working Group · CISO Society · AI Security Council · Westchester County Business Council

Recognition

Inc. 500, 2012 · 40 Under 40, Westchester County Business Council, 2009

Where I started

I earned my BBA from Pace University in 2000 with a concentration in Management Information Systems, and in 2012 I completed the Tuck WBENC Executive Program at Dartmouth's Tuck School of Business.

A decade in the CEO's chair

In 2008 I stepped into our family business, LSW Chauffeured Transportation, as Chief Operating Officer, and led it as Chief Executive Officer from 2010 to 2019. Over that decade we grew revenue from $2.5 million to more than $5 million by modernizing operations, rebranding, and — well before it was fashionable — treating technology and security as genuine business differentiators rather than line items to be minimized. LSW was named to the Inc. 500 list of America's fastest-growing private companies in 2012, and in 2009 I received a 40 Under 40 award from the Westchester County Business Council. Those recognitions belonged to a team; I was fortunate enough to lead it. I sold the business in 2019.

The sale gave me the opportunity to return to the work I love most. I spent several years as a Director of IT and Security in corporate America before committing fully, in 2022, to cybersecurity.

Credentials, and what comes after

That year I earned the Certified Chief Information Security Officer (C|CISO) credential from EC-Council — a certification centered not on tools but on executive leadership: governance, risk, audit, strategy, and the financial discipline required to run security as a business function. I then sat for and passed the CISSP, widely regarded as the most rigorous and respected certification in the field, requiring both broad command of the security domains and years of verified, hands-on practice. I am proud of both, and mindful that a credential only opens a door. The work is what happens after.

I went on to serve as a virtual CISO and as Senior Director of Information Security for a healthcare startup for two years — an experience that clarified where I could be most useful.

Cybersecurity Advisory Group

In 2026 I founded Cybersecurity Advisory Group, a risk management and cybersecurity advisory firm built deliberately for the underserved small and mid-size market. I work predominantly, though not exclusively, in healthcare as a fractional CISO.

The premise is straightforward. You don't need a full-time CISO. But you do need someone who thinks like one. Healthcare organizations under 500 employees are the fastest-growing target for ransomware, HIPAA enforcement, and data breaches — yet a full-time CISO costs $200,000 or more per year, which most small and mid-size practices simply don't have in the budget.

Most security consultants think in terms of frameworks, audits, and controls. Having sat in the CEO's chair and signed the payroll myself, I think in terms of risk, revenue, and reality. My goal is to build practical security programs that scale with an organization's mission rather than impede it, and to translate risk into language boards, leadership teams, and auditors can all act on.

Where I serve

I am a proud member of the CISO Society, a community of security executives who convene to exchange field experience and sharpen one another's practice, and of the AI Security Council, an invitation-only coalition of CISOs, CTOs, researchers, and practitioners working to anticipate adversarial AI and publish usable frameworks for deploying, auditing, and containing it. In August of 2026 I was invited to join the Health Sector Coordinating Council's Cybersecurity Working Group, which develops best practices for the health sector under a mission it calls, rightly, Patient Safety. I serve on its Public Policy and Post-Quantum Computing task groups.

White Plains, New York

I was born and raised in White Plains, New York, and I still call it home — where I live today with my beautiful son and our delightfully crazy chocolate Labrador Retriever, appropriately named Thor.

Thank you for visiting Cybersecurity Advisory Group. If you are building something worth protecting, I would welcome the opportunity to advise you on cybersecurity risk the way I have come to understand it — through the lens of a CEO turned CISO — with guidance that is practical, proportionate, and aligned to how small and mid-size organizations actually grow and scale.

Let's talk

If you are building something worth protecting, book a free 30-minute security clarity session. No pitch, no obligation — just a straight read on where you stand.

Book a 30-minute call