Author Bio

Jason Pufhal

Jason Pufahl

Chief Revenue Officer & Partner

Jason Pufahl runs revenue at Vancord, which is a slightly unusual job for someone who spent the last 20 years in information security. He's also a partner and sits on the Board of Directors, so the growth of the company isn't an abstract goal for him. It's personal.

The path here wasn't accidental. Jason ran security at the University of Connecticut as their CISO, then joined Vancord to lead the security practice and help shape it into a full MSSP. Now he runs the revenue side, which sounds like a pivot until you talk to him for ten minutes. His view: selling security isn't really about selling. It's about understanding what an organization is actually exposed to, telling them the truth about it, and being honest about what it takes to fix. The companies that figure that out tend to grow. The ones that don't, don't.

He works with clients on the messy stuff: CMMC, NIST 800-171, HIPAA, FERPA, CJIS. The compliance frameworks that sound dry until you're three weeks from an audit. He holds a CISM and a Master's in Educational Technology from UConn.

You can hear him every week on CyberSound, Vancord's podcast, where he and the team talk about what's actually happening in cybersecurity without the vendor spin. He also speaks at industry events, usually about leadership, compliance, or what it really takes to defend a mid-sized organization in 2026.

When he's not working, he's mountain biking, running, skiing, or playing guitar. Probably not all on the same day.

geopolitical cyber threats what businesses need to know

Geopolitical Cyber Threats: What Businesses Need to Know

Read More
why many cyber attacks go undetected for days

Why Many Cyber Attacks Go Undetected for Days

Read More
how to build a security program without a full time ciso

How to Build a Security Program Without a Full-Time CISO

Read More
fractional ciso vs virtual information security office whats the difference featured img

Fractional CISO vs Virtual Information Security Office: What’s the Difference?

Read More
fully managed vs co managed it choosing the right security first model

Fully Managed vs Co-Managed IT: Choosing the Right Security-First Model

Read More
why manufacturing companies are prime ransomware targets featured img

Why Manufacturing Companies Are Prime Ransomware Targets

Read More
cybersecurity challenges schools face during the school year

Cybersecurity Challenges Schools Face During the School Year

Read More
ai in the classroom adoption and student innovation in public schools social

AI in the Classroom – Adoption and Student Innovation in Public Schools

Read More
how fast should incident response be during a cyber attack

How Fast Should Incident Response Be During a Cyber Attack?

Read More
conduent cybersecurity breach lessons for dod manufacturing supply chains and how to prevent the next one featured img

Conduent Cybersecurity Breach: Lessons for DoD Manufacturing Supply Chains – And How to Prevent the Next One

Read More
pen testing demystified how penetration testing reveals real attack paths social

Pen Testing Demystified: How Penetration Testing Reveals Real Attack Paths

Read More
cybersound ep142 cybersecurity predictions reality check

Cybersecurity Predictions: A Reality Check & 2026 Risks Part 2

Read More