
Gracia Herts
After almost twenty years as an IT and Operational Auditor across leading financial institutions and government organizations, I have built a career at the intersection of IT, risk, and security. Along the way, I made a shift into Non-Financial Information Risk Management, taking on roles at ING and De Nederlandsche Bank. Today, I work as a Security Risk Manager within KPN’s CISO Office. This journey has given me a broad and practical expertise in IT Security Risk Management, and I see raising risk awareness across the organization as one of the most valuable contributions I can make.
The pace of change in IT, Risk, and (Cyber)Security never slows down, and I make it a priority to keep learning, committing to at least one training every year to stay ahead of new developments.
Since 2024, I’ve also been an active volunteer, helping organize ISACA’s annual Risk Event — a role that lets me give back to the professional community I’m proud to be part of.