AT A GLANCE
Tiernan leverages more than 20 years of experience in the financial services and consultancy sectors, with focus on domestic and international dimensions of cybersecurity, regulations, threat intelligence, strategy, risk and governance. He has played a pivotal role in developing industry intelligence-sharing initiatives and frameworks.
At Kroll, Tiernan works with clients to implement and strategically enhance their cybersecurity programs via a business-aligned and risk-based approach, ensuring effective risk mitigation and regulatory compliance.
Prior to joining Kroll, Tiernan served as EMEA Legal Entities Lead for Cyber and Technology Controls at JP Morgan. Prior to this, he was Global Head of Technology and Security Operations at MUFG Investor Services, responsible for the first line of defence security and IT services. Tiernan has also worked in a strategic cybersecurity consultancy role for EY, as well as in various technical roles spanning network engineering, vulnerability management and cyber threat intelligence at Morgan Stanley.
Tiernan holds a Bachelor of Science in network management and design from Robert Gordon University. He also holds several certifications in information security, including Certified Information Systems Security Professional (CISSP).
Kroll's 2025 Financial Crime Report
From pivotal elections to advances in AI to heightened geopolitical tensions, the events of the past year have only amplified the challenges of fighting financial crime. Based on data from over 600 executives across the globe, our report provides insight to help leaders prepare for what’s next.

Stay Ahead With Kroll
Cyber and Data Resilience
Kroll merges elite security and data risk expertise with frontline intelligence from thousands of incident response, regulatory compliance, financial crime and due diligence engagements to make our clients more cyber resilient.
Cyber Risk Retainer
Kroll delivers more than a typical incident response retainer—secure a true cyber risk retainer with elite digital forensics and incident response capabilities and maximum flexibility for proactive and notification services.
Cybersecurity Due Diligence Services
Evaluate the cybersecurity risks associated with business transactions.