Ken Grohe's avatarPerson

Ken Grohe

PresidentLeverageGTM, Inc.

San Francisco, CA

Skills

Business Strategy
Business Management
Go to Marketing Strategy

About

Ken Grohe has enjoyed being a business entrepreneur for over 35 years. Grohe's experience includes a 25-year career at EMC, as VP & GM of the flash, software, and partner business units. He was with Barracuda Networks as SVP & GM, CRO of Virident and its acquirer, Western Digital, and President of SignNow. Additionally, he was the CRO of Samsung's Stellus and President, CRO at AI leader WekaIO, CRO/SVP of Taos/subsequent Partner, Platform and Security Engineering at IBM, and fractional CMO of SPHERE. An International Bestselling Author, and Rockland, Mass Hall Of Fame inductee ('22), Grohe has served as a board advisor/investor to several technology companies, including: Zoom, SecurityScorecard, Evisort/WorkDay, Boston Red Sox, SantaCruz Warriors, Multiple Sclerosis Society, Pasatiempo, SalesCommunity, Boston College, Stanford GSB, Breezeway, CoPilot, Cohesity, ServIQ/ServiceExpress, Taos, Mettalic.io/Commvault, Cytactic, SPHERE, www.SantaCruzWhatever.com, & www.LeverageGTM.com

Published content

Software Supply Chain Security: Preventing Downstream Compromise

expert panel

Software supply chain security is often treated as a gatekeeping problem: Keep malicious code from entering the environment. But modern applications are built from dense webs of open-source and third-party dependencies, and a single compromised package can surface across numerous applications and systems downstream, far beyond the first project that installs it.Recent attacks have shown how quickly that risk can multiply. In September 2025, the self-replicating Shai-Hulud worm infiltrated the npm ecosystem through compromised maintainer accounts, spreading automatically across the registry by hijacking developer credentials. By the time it was contained, the worm had compromised more than 500 packages, prompting GitHub to remove them from the registry to stop further propagation.For security leaders, the challenge isn’t only determining whether a package is safe at the point of entry—it’s understanding how far a compromise could travel once that software is already embedded across an organization. Supply chain risk is compounded when organizations lack visibility into how the technology they rely on is developed, integrated and deployed.Members of the Senior Executive Cybersecurity Think Tank bring deep expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and modern security architecture. Here, three of them examine how leaders should assess the downstream risk posed by poisoned software dependencies and what meaningful prevention and containment look like when a single compromised component has the potential to affect many systems.

From Siloed Alerts to Unified Action: Moving Beyond Detection-Centric Cybersecurity

expert panel

An attacker who gains access through a stolen credential may quickly move across devices, cloud resources and network systems in search of valuable data or greater control. Each step can generate clues, but when those signals land in separate tools and queues, security teams may struggle to recognize the full attack before the damage spreads.This challenge is becoming harder to tackle as traditional boundaries between users, devices, applications and infrastructure continue to dissolve. NIST’s zero-trust guidance reflects that shift, moving security away from static, network-based perimeters and toward continuous decisions based on users, assets and resources. This same erosion of boundaries is what makes it harder to catch attackers who don’t need to break anything to move around. CISA’s guidance on identifying and mitigating “living off the land” techniques warns that attackers can abuse legitimate, trusted tools and processes to blend in with normal system activity, making isolated alerts harder to interpret without broader context.Yet many organizations still measure security effectiveness largely by how well they detect suspicious activity. Detection remains essential, but alerts alone don’t determine which risks matter most, coordinate action across environments, or help the business continue operating when defenses fail. That requires an approach that connects visibility with timely decisions, enforceable controls and plans for maintaining and restoring critical operations.Moving beyond a detection-centric model means reconsidering how security data, decisions and defenses work together across the enterprise. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and cybersecurity leadership—explain what a more unified, real-time approach to visibility, control and resilience should look like.

Company details

LeverageGTM, Inc.

Company bio

Leverage the transformative power of generative AI alongside our proven growth strategy to propel your business forward. With our Silicon Valley expertise, we’ll guide you in harnessing the latest AI technologies, identifying essential resources, and forging strategic connections. This integrated approach will accelerate your momentum and enhance your company’s value as you expand into new markets.

Industry

Management Consulting

Area of focus

Business Development
Brand Marketing
Cyber Security

Company size

11 - 50