Hector Herrera
Judgment to connect risk, technology, and decisions.
I’m Hector Herrera. I work at the intersection of cybersecurity, cyber risk and resilience, technology strategy, and applied AI for cybersecurity. I focus on turning technical complexity into clear decisions, sustainable capabilities, and outcomes that work in practice.

Background
Areas of work
Where I focus
I don’t start with tools. I start with context, the decisions that matter, and the real ability to execute.
Risk and resilience
Understanding exposure, separating signal from noise, and prioritizing decisions that strengthen an organization’s ability to anticipate, respond, and recover.
Technology strategy
Connecting architecture, capabilities, investment, and operations so technology serves real business needs and remains sustainable over time.
Applied AI for cybersecurity
Exploring concrete uses of AI to interpret information, enrich analysis, support decisions, and improve security workflows without treating AI as an end in itself.
Working principle
How I approach the work
Technology creates value when it improves the quality of a decision, strengthens a capability, or simplifies execution that was previously fragile or unclear.
That is why I prefer approaches that are sober, verifiable, and executable: understand the context, prioritize what matters, design around real constraints, and learn from implementation.
Work evidence
Work and explorations
Projects where I document how I connect strategy, technology, and execution, clearly distinguishing professional work from experimentation.
AI integrated with cybersecurity software
Exploration and structuring of use cases where AI connects with security tools to create practical value.
Explore project →Designing an email protection capability against phishing, fraud, and critical-process compromise
Structuring an email protection capability focused on detecting phishing, fraud, impersonation, and other interactions capable of compromising critical business processes.
Explore project →Ideas
Recent ideas
Ideas and lessons on cybersecurity decisions, resilience, technology strategy, and applied AI for cybersecurity.
More security tools do not mean more security capability
Technology can enable a capability, but the capability exists only when people, processes, decisions, controls, and evidence work together.
Read idea →A technically correct architecture can be a bad business decision
Architecture quality depends on more than technology: operability, cost, skills, dependency, recovery, governance, and the real ability to sustain it also matter.
Read idea →Professional conversations
Is there a complex decision on the table?
I’m interested in conversations where cybersecurity, risk, technology, and applied AI for cybersecurity need to become concrete decisions and actions.
Start a conversation