ERIC M. FAIR CISA, CDPSE, CBCLA

Eric is a Shareholder in the Risk Advisory Services practice at Schneider Downs. He joined Schneider Downs in 2011 and has more than 10 years of experience providing IT internal audit and risk advisory co-sourcing and outsourcing consulting services across various industries, including more than five years of experience leading, managing and mentoring a team of IT audit, security and risk professionals to successfully serve our clients. Eric is responsible for leading the engagement team to coordinate, conduct and review engagement deliverables, as well as ensuring effective communications to provide continued value to clients.

Eric brings significant experience in guiding clients and internal teams through efficient and successful IT audit projects, SOC 1 examinations, SOC 2 examinations, SOC 2 + examinations, as well as business continuity, business impact analysis, disaster recovery, crisis management and emergency preparedness, SOX, network security and cybersecurity frameworks (NIST 800-53 and 800-171), data privacy (GDPR, CCPA), IT general controls, risk assessments, FISMA, PCI-DSS, and vendor risk management.

Eric is one of only 83 active Certified Business Continuity Lead Auditors (CBCLA) globally, as recognized by DRI International. This designation encompasses the ability to audit, consult and assess business impact and continuity, disaster recovery, emergency preparedness, crisis response and overall organizational resiliency.

Prior to joining Schneider Downs, Eric served in system and network administrator roles, over a span of seven years, supporting, managing and leading IT initiatives to develop and support ongoing Casino operations.

Education

M.S.—Internet Information Systems, Robert Morris University
M.S.—Accounting, Liberty University
B.S.—Information Systems Management, Robert Morris University

Professional and Community Involvement

Board Member—Robert Morris University Accounting Advisory Board
Co-Chair—IAPP KnowledgeNet Pittsburgh Chapter (2021-2023)
Director of Career & Educational Outreach—ISACA Pittsburgh Chapter (2017-2020)
Member—The Institute of Internal Auditors (IIA) Pittsburgh Chapter
Member— DRI International, Inc.
Member—FAIR Institute and local Pittsburgh Chapter
Member—Three Rivers Contingency Planning Association (TRCPA)
Member—InfraGard Pittsburgh Chapter

SHARE

Do you have a hobby/personal passion?   
My family

What was the best advice you’ve ever received?   
Never stop learning

What was your childhood dream?  
To be like Mike (Michael Jordan, that is)

If you could go back in time, what advice would you give your college self? 
Foster new relationships and continuously build upon existing relationships

People would be surprised to know that I…  
Met “Dickie V” (Dick Vitale for those non- college basketball fans)

What is the best or most interesting thing about your career?    
I pivoted in my career after 7 years in the Casino industry as an IT Administrator

Do you have a “motto”? (spoken or unspoken)  
Get comfortable with the uncomfortable

When you have an hour of free time, what do you like to do?    
Unwind with a cigar, a book, music, or Netflix

Do you have advice for young professionals?  
Continuously challenge yourself and those around you

Our Thoughts On

FEATURED

Big Problem: Cybersecurity Defenses Compromised By Employees’ Passwords


Big Thinking: Significant Updates To The Cybersecurity Environment.

Shareholder ERIC WRIGHT has been involved with Information Technology with Schneider Downs since 1983 and oversees the firm’s thriving Technology Consulting and IT Audit & Compliance practices. Through this role, Eric brings extensive experience in assessing IT infrastructure and identifying cybersecurity risk and exposure.
One of our clients felt fairly good about their existing cybersecurity defenses. But they were still afraid of the unknown and newer cyber attack techniques. Through our regular audit procedures, we inquired about their current cyber controls and their confidence in withstanding an attack. We then performed a network penetration test which simulates an external adversary hacking their network. This procedure identified the client's unknown weaknesses in their defenses through a live test. “Within 48 hours, we were able to guess the passwords of close to 10% of their employees, effectively giving us VPN access to their corporate network and certain employee utilities, like email.” Eric said. "We also found that their corporate intranet site was visible over the internet and susceptible to login via the bad passwords. After identifying these issues, we worked with the client to make significant changes to their environment to make it harder for an attacker to break in." Schneider Downs provides Big Thinking and Personal Focus in delivering a variety of services for large and small businesses, both publicly and privately held, as well as nonprofit organizations, government entities and more. Through our commitment to thought leadership and knowledge management, we deliver the solutions our clients need with a personal commitment to service.

Have a question? Ask us!

We’d love to hear from you. Drop us a note, and we’ll respond to you as quickly as possible.

Breached?

Every moment counts. For urgent requests, contact the Schneider Downs digital forensics and incident response team at 1-800-993-8937. For all other requests, please complete the form below.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.