About Maya Sutherland
Maya Sutherland is 39 and the compliance and risk manager at a 700-person mid-market insurance company in Hartford that has spent three years pivoting toward digital financial products. She owns the security-audit readiness program, the health-data obligations attached to a wellness product line, and third-party vendor risk; she supports the financial-controls program with finance and keeps the risk register current. She has no direct reports and owns work product across the company anyway, reporting to the chief risk officer with dotted lines to the security chief and the general counsel. Fourteen years in the field, five in this seat, and a start in Big Four audit. Her week is defined by three pressures: auditors arriving in five weeks, eight new vendor assessments on a queue already past sixty, and an engineering leader who does not yet accept that a new feature needs a privacy review before it ships.
She optimises for documented evidence over verbal assurance and for calibrated risk rather than zero risk, and she is explicit that she is not a no-machine. She is composed, listens more than she talks, and delivers a refusal with a written rationale rather than a tone. Her email is formal and cites the specific control or regulation at issue, and she writes nothing casual that might one day be discoverable. Her vocabulary is the discipline’s: control evidence, control owner, audit finding, risk register, third-party risk, data residency, right-to-audit clause, subprocessor. She will not schedule an introductory call before receiving four things — a current security audit report, a data-processing agreement template, two references at regulated companies of similar size, and data residency commitments.
She is a strong subject at consideration, decision and renewal for governance and risk platforms, vendor risk management, privacy management, audit automation and any software touching regulated data. She is the library’s gatekeeper voice, right for testing security positioning, contract-paper narratives and regulated-industry references. She dislikes per-control or per-evidence pricing that scales with exactly the thing a program is supposed to grow. She separates marketing-grade promises from product-grade limitations unusually well, because her own evidence lives across fourteen systems and nine owners and she knows what collection costs. She is less informative on developer tooling and consumer marketing.
Her media is professional and text-heavy, with a mid-range profile everywhere else — she is reachable, but only through channels that carry documents. Search, LinkedIn and email score high. She reads a professional-association newsletter, a compliance weekly, a privacy daily digest and, critically, the content marketing published by the automation vendors she already uses. The sources she actually trusts are her professional-association peer network, a privacy practitioner community, her chief risk officer and two former colleagues in equivalent seats. Podcasts run to true crime as much as to the profession. Facebook, Instagram, YouTube, Reddit, X, podcasts, connected television, direct mail and print sit in the middle; Threads, TikTok, out-of-home and text messages are low. Cold sales mail arrives daily and gets a document request rather than a meeting.