Arif Hameed is a two-time CISO, having served at C&R Software and Munich Re, with previous cyber roles at Equifax, RBC, and TD. He holds CISSP, CISA, and CRISC certifications and a Canadian Federal Secret clearance. An active ISACA and Cloud Security Alliance volunteer, he is a recognized speaker at industry events including RSA Conference, InfoSec World, and SecureWorld, where he shares practical insights on cybersecurity leadership, strategy, and risk management.
When C&R Software completed its divestiture, we inherited an urgent compliance challenge: our prior certifications and attestations were no longer in force, leaving us outside our contractual obligations to customers. Operating in a new cloud environment with no inherited compliance posture, we had to achieve ISO 27001, SOC 2, and PCI DSS certifications rapidly — not as a roadmap item, but as a business imperative. We built controls, evidence, and audit-ready processes concurrently across all three frameworks and passed every audit. We navigated customer security assessments from regulated clients, restoring confidence that their data remained protected in our SaaS environment.








