Thinkers360
Interested in getting your own thought leader profile? Get Started Today.

Richard Tello

Principal & Lead Consultant. at ComplyZoom

Jacksonville FL, United States

Richard Tello is Principal and Lead Consultant of ComplyZoom, a specialist IT GRC advisory firm serving aerospace, space, Defense Industrial Base, and federal suppliers, DoD contractors, and subcontractors. His work focuses on a single leadership question: can the organization prove readiness on demand?

Rich advises on CMMC Level 2, NIST SP 800-171, and DFARS 252.204-7012 / 252.204-7021 readiness, with emphasis on making evidence provable and leadership representations supportable before SPRS submission, Level 2 self-assessment, C3PAO Level 2 certification assessment, prime review, or Affirming Official action under 32 CFR 170.22.

His signature 10-minute test (pick one control, ask the accountable owner to prove it, and watch the pause) is the entry point for his thinking on why CMMC programs often fail at the evidence layer rather than the control layer. That thinking is codified in two proprietary frameworks: the Proof Equation™, WHO + WHERE + WHAT + HOW = PROOF, and the Scope-to-Evidence Readiness Model™: Scope, Map, Close, Evidence, Affirm. Together, they turn readiness from a periodic scramble into an operating discipline: Readiness: Provable on Demand™.

Rich writes and speaks on evidence-based CMMC readiness, objective-level assessment, 32 CFR 170.24 evidence requirements, executive accountability under the Affirming Official requirement, AI governance where AI tools touch CUI, and the convergence of CMMC with EASA Part-IS for aerospace suppliers operating across defense, aviation, safety, quality, and regulated information-security obligations. His published themes include CUI governance, SPRS score defensibility, NIST SP 800-171A evidence traceability, supplier and cloud dependencies, AI risk in defense environments, and the operational gap between implemented controls and evidence that holds under examination.

Rich brings 15+ years of information security and compliance leadership, holds the CISM certification, and is a CMMC Registered Practitioner. He founded ComplyZoom in 2018, advising defense suppliers on DFARS 252.204-7012 and NIST SP 800-171 implementation before CMMC existed. ComplyZoom is advisory and readiness-focused: not a C3PAO, assessor, or certification body. Based in Jacksonville, Florida, serving clients nationwide.

His view in one sentence: readiness is not what you implemented; it is what you can prove in 10 mins or less, in final form, on demand.

Available for briefings, webinars, podcasts, panels, executive education, and expert commentary on CMMC readiness, CUI evidence discipline, AI governance, and aerospace compliance convergence.

Available For: Advising, Authoring, Consulting, Speaking
Travels From: Jacksonville, FL
Speaking Topics: 1. The 10-Minute Test: Why CMMC Evidence Fails Before Controls Do One control, one accountable owner, ten minutes, and the pause that predicts assessm

Richard Tello Points
Academic 0
Author 3
Influencer 80
Speaker 0
Entrepreneur 0
Total 83

Points based upon Thinkers360 patent-pending algorithm.

Thought Leader Profile

Portfolio Mix

Company Information

Company Type: Service Provider
Business Unit: Advisory
Theatre: North America
Minimum Project Size: $10,000+
Average Hourly Rate: $300+
Number of Employees: 1-10
Company Founded Date: 2018
Media Experience: Richard Tello began presenting on CMMC and defense
Last Media Interview: 11/19/2020

Areas of Expertise

AI Governance
Cybersecurity 30.07
GovTech
GRC
National Security
Privacy
Risk Management 30.10
Supply Chain

Industry Experience

Aerospace & Defense
Federal & Public Sector
High Tech & Electronics
Manufacturing

Publications & Experience

3 Article/Blogs
4 Types of Agencies You’ll Find When Looking for a Compliance Partner
ComplyZoom
May 26, 2020
The 4 Types of Agencies You’ll Find When Looking for a Compliance Partner

A colossal cybersecurity budget does not guarantee compliance - and it certainly doesn’t guarantee protection. All too often, small businesses partner with a turnkey provider in the name of convenience, only to be left out in the cold during a breach.

So, what separates the good from the bad? What should you look for (and avoid) when searching for a compliance solutions expert? HIPAAEx is here to break it down for yo

See publication

Tags: Cybersecurity, Risk Management, Business Continuity

The Cybersecurity Pitfalls of AI
ComplyZoom
November 09, 2018
The Risk of Breach Skyrockets as Machine Learning Gains Popularity

Automation makes lives easier. AI can drive cars, fly planes, filter spam emails, play chess and even sort cucumbers. However, with the convenience comes great risk. As fewer human eyes remain on the data, it can fall prey to both external and internal threats. We’re here to help you recognize the cybersecurity risks involved with AI, but also how you can further protect yourself while enjoying the fruits of machine learning mechanisms.

See publication

Tags: AI, Cybersecurity, Risk Management

HIPAAEx | Expert HIPAA Compliance & Advisory Services
HIPAAEx
August 09, 2018
Combining Compliance Best Practices With Proactive Protective Measures to Ensure True Cyber-Resiliency

In an era of increased cybersecurity hacks, it’s not enough to simply be compliant with existing regulations. Rather, an organization must cover itself from all angles to become “cyber-resilient.” That’s why HIPAAEx is here – to protect you against both the rise in HIPAA audit penalties and aggressive, ever-evolving cyber-based threats.

See publication

Tags: Business Strategy, Cybersecurity, Risk Management

Blog

Opportunities

1 IT Advisory
CMMC Level 2 Readiness Review: Evidence, Scope, and SPRS Validation for Defense Subcontractors & Suppliers

Location: Jacksonville, Florida, US (Remote n    Fees: Fixed fee, quoted after a complimen

Service Type: Service Offered

Before your organization submits an SPRS score, signs an affirmation, or schedules a C3PAO Level 2 certification assessment, the leadership question is simple: can you prove readiness on demand?

This fixed-scope CMMC readiness review, delivered by a CMMC Registered Practitioner with 15+ years in information security and compliance, gives aerospace, space, Defense Industrial Base (DIB), and federal Subcontractors and suppliers a clear, defensible picture of where they stand. The review covers CUI and FCI scoping and asset categorization, SSP and POA&M review, SPRS score validation under the CMMC Scoring Methodology (32 CFR 170.24), and evidence traceability spot-checks against NIST SP 800-171A assessment objectives, using the same Examine, Interview, and Test discipline an assessor will apply.

Deliverables include a findings summary for leadership, an evidence-gap map with named-owner accountability, and a prioritized path to close. Principal-led end to end: the practitioner you engage is the practitioner who delivers.

ComplyZoom is advisory and readiness-focused: not a C3PAO, assessor, or certification body. Remote nationwide; on-site available across Northeast Florida, Southeast Georgia, and the South Carolina Lowcountry.

Respond to this opportunity

Events

Contact Richard Tello

Book Richard Tello for Speaking

Book a Video Meeting

Media Kit

Share Profile

Contact Info

  Profile

Richard Tello


Latest Opportunities

Search
How do I climb the Thinkers360 thought leadership leaderboards?
What enterprise services are offered by Thinkers360?
How can I run a B2B Influencer Marketing campaign on Thinkers360?