Chris Mark — studio portrait

About

Chris Mark, MBA

Enterprise Security & Risk Strategist | Published Author | International Consultant

For more than 30 years, Chris Mark has worked at the intersection of the physical and the digital — securing payment systems and enterprise networks, running intelligence operations in active maritime threat environments, and commanding reconnaissance and sniper teams in combat. That breadth is unusual. Most security professionals specialize in one domain; Chris has operated credibly across physical, maritime, operational, and cyber security, and he brings the same analytical rigor to a Fortune 100 boardroom that he once brought to the field.

His career is defined by a rare combination of roles: combat-tested operator, founder and chief executive, inventor, and published thought leader. He is the former founder and CEO of two security companies, and he has worked directly for both MasterCard and Visa on their information-security programs. At MasterCard, he authored the internal whitepaper "Impracticable Data," which originated the conceptual framework for Point-to-Point Encryption (P2PE) — a foundational technology now standard across global payments — and he served as the company's representative to the PCI Security Standards Council. He is a named inventor on one of the payment industry's earliest tokenization patents, co-authored the CISP (2001) and the PCI DSS (2005), and was the world's first global PCI DSS QSA trainer. Across his payments career he personally trained more than 8,000 attendees for Visa and over 1,500 Qualified Security Assessors worldwide, and he later led AT&T's national PCI practice, managing payment security, fraud prevention, and identity services for the company's largest accounts.

Before his work in cybersecurity and payments, Chris served as both an enlisted US Marine and a US Navy officer. He is a qualified Marine Infantryman (0311), Scout/Sniper (8541), and Reconnaissance Marine (8654), and a former Reconnaissance Instructor. A combat veteran of Operation Continue Hope in Somalia, he is a graduate of more than a dozen specialized military schools, including Basic Infantryman, Scout/Sniper, Urban Sniper, Basic Reconnaissance, Urban Surveillance and Reconnaissance, Airborne, Pathfinder, Navy Scuba, HRST Master, and Security Forces. That operational background still shapes how he thinks about modern security — as a discipline grounded in adversary behavior, not just technology.

Chris holds the CISSP, CIPP, and CPISM/A certifications, is a Visa Accredited EMV Consultant, and maintains numerous additional technical credentials. He earned an MBA from the University of Maryland and a BA in Political Science (Magna Cum Laude, Distinguished Military Graduate) from Auburn University, and is currently pursuing a DSc (Doctor of Science) in Cybersecurity.

A prolific writer, Chris is the author of ten books and more than 20 articles on risk, risk management, and information security. His work spans cybersecurity theory and practice, China's unrestricted warfare doctrine, the limitations of artificial intelligence, predator behavior and personal safety, and applied Bayesian reasoning — including titles such as The Science of Security: Scientia Securitatis, The War God's Face Has Become Indistinct, The Predator's Playbook, Bayes for Beginners!, Confident, Precise, and Wrong, and Defining Security. Much of his writing develops original frameworks that bridge operational experience with quantitative rigor. His articles have appeared in the National Review, SC Magazine, The Counter Terrorist, Penetration Tester, Secure Payments, the Huffington Post, and others, and he is a frequent keynote speaker, having presented at more than 30 conferences. He has been interviewed on CNN, Fox News, NPR, NewsMax, and Blaze.

In 2016, Chris co-founded the Recon & Sniper Foundation, which supports the reconnaissance and sniper community. He lives in the Houston area with his Belgian Malinois, Freya.

30+

Years in Security

10

Books Published

10,000+

Professionals Trained

8,000+

Attendees Trained (Visa)

Original Frameworks

Concepts & Models

I build frameworks from operational experience. These models are used in enterprise security programs, academic research, and advisory work.

Mark Heptad

Seven-element security architecture model

IMCM

Integrated Maritime Compliance Model

Proximate Reality

Threat perception and decision-making framework

Compellence-Deterrence Framework

Active vs. passive security posture theory