One leader below has worked at the same insurer since 1990, when she joined as a software developer. Another ran a Citrix farm and Symantec upgrades at APC before he ever touched a security program. Rhode Island is the smallest state in the country, and its cybersecurity bench is built around a handful of large employers within a short drive of each other: a health insurer, a commercial property insurer, a toy company, an auto and home insurer, and two health systems. The six leaders below defend them.
Frederick Webster – CISO, Blue Cross & Blue Shield of Rhode Island
Frederick Webster started his career managing data centers at APC, running a Citrix farm of more than 30 servers and handling antivirus and systems management deployments across North America. He moved through systems administration at Johnson & Wales University and project management at Dell before joining CVS Health in 2012, where he coordinated the company’s vulnerability management programs and later led IT security operations for a team of 32 across vulnerability management, logging and analytics, the cyber intelligence center, and a 24/7 SOC. At NTT he managed a global organization of more than 40 security engineers and analysts, transitioning the company’s SOC from 12×5 to 24×7 coverage and helping build out a delivery office in Bangalore. Webster joined Blue Cross & Blue Shield of Rhode Island in 2020 as Director of Information Assurance, became Information Security Officer in 2022, and has served as CISO since January 2025. He sits on the Rhode Island Department of Health’s All Payer Claims Database Data Release Review Board and its Data Security Subcommittee, and he holds CISM and PMP certifications alongside an MBA.
Annette MacLeod – VP & CISO, FM Global
Annette MacLeod has worked at FM Global for nearly 36 years. She joined in 1990 and spent 27 years in software development leadership, running application development, information security, data management, and data warehousing teams at various points. She moved into a VP role heading technology enablement in 2017, then became Vice President and Head of Information Security and Risk Management in February 2021. FM Global is a commercial property insurer headquartered in Johnston, and MacLeod now leads its cyber defenses and risk management program. Before FM Global, she spent eight years at Data General Corporation as an information services manager. She holds an MBA from Babson’s F.W. Olin Graduate School of Business and a computer science degree from Boston College.
Yuriy Litvak – Director of Cybersecurity Operations, Hasbro
Yuriy Litvak spent six years at Gillette as a LAN analyst and lead system administrator before moving into infrastructure architecture at IHCIS and then Ingenix, where he designed hosted solutions serving more than 100 clients. He spent nearly three years as Principal Systems Architect at Massachusetts Eye and Ear Infirmary, building the hospital’s virtualization infrastructure and working with auditors on HIPAA compliance. At CyberArk he ran IT infrastructure and operations for the Americas across more than seven years, taking DMZ uptime from 80% to 99% and implementing network access control and internal segmentation. After a stint leading IT and operational technology at a Procter & Gamble site, Litvak became Director of Information Security at Avid in 2022. He joined Hasbro in January 2025 as Director of Cybersecurity Operations, working from Rhode Island.
Steve Torino – CISO, Synergent
Steve Torino came to security leadership from the vendor side. He spent nearly four years in sales operations and sales engineering at Altius Systems, then a year and a half as lead sales engineer at CI Security, before joining CyberSaint in 2020 as a principal solutions architect. He rose to Vice President of Solutions Architecture there, chaired the company’s InfoSec committee for more than four years, and served six months as its CISO. Torino then spent nine months at Geels Norton directing the firm’s vCISO and GRC-as-a-Service practice, which covers SOC 2 and ISO 27001 advisory work for cloud technology companies. He became Chief Information Security Officer of Synergent in April 2025, working remotely from Providence for the credit union technology provider.
Michael Mason – Manager, Enterprise Cybersecurity, Amica Insurance
Michael Mason spent more than 18 years at CSC, first supervising a server group of up to 24 Unix administrators and then working 12 years as a senior network security engineer, designing and maintaining a large customer network with high security requirements. His technical range there covered Cisco and Juniper hardware, Fortinet and Palo Alto firewalls, Websense proxies, IBM intrusion prevention appliances, and QRadar SIEM. Mason joined Amica Insurance in Lincoln in 2018 as lead network security specialist and became Manager of Enterprise Cybersecurity in June 2019. He holds a CISSP.
Jason Morais – Director of IT Security & ISO, Sturdy Health
Jason Morais led an enterprise ransomware recovery affecting more than 3,000 endpoints and servers, restoring mission-critical systems within 96 hours while keeping patient care running. That came during nearly seven years as Director of Information Security and Technology at Care New England, where he also built a cybersecurity governance framework aligned to HIPAA and NIST CSF, managed a $20 million annual budget, and briefed the board quarterly. He had joined the health system in 2006 as a Unix administrator, spent nearly eight years as a disaster recovery specialist, and became Director of Information Security in 2016, standing up a 24/7 security operations center and revamping the vulnerability management program. Morais moved to Sturdy Health in November 2025 as Director of IT Security and Information Security Officer. He holds CISSP and CISM certifications and has more than 25 years in the industry.
Small State, Large Institutions
Rhode Island’s size works in its favor here. MacLeod has spent 36 years at FM Global, Morais nearly 20 at Care New England before moving one town over to Sturdy Health, and Mason eight years at Amica after a long run at CSC. Webster built his security career at CVS in Woonsocket before taking the top job at the state’s largest health insurer. Litvak and Torino came in from the Boston corridor, one from a product company and one from the vendor and advisory side. The institutions these leaders protect employ a meaningful share of the state, and most of them sit within half an hour of each other, which tends to mean the people defending them are working the same problems in the same weather.
Discover more CISOs securing their organizations:
- Built to Last: Winnipeg’s Cybersecurity Leaders to Watch
- Half a Million Neighbours: Wellington’s Cybersecurity Leaders to Watch
- At the Edge of the Map: Auckland’s Cybersecurity Leaders to Watch
- The Yarra’s Quiet Defenders: Melbourne’s Cybersecurity Leaders to Watch
- The River City’s Watchtowers: Brisbane’s Cybersecurity Leaders to Watch
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

