Kevin Cheeley’s career began with a responsibility he still recognizes in his work today: understanding threats and protecting what matters. Over 30 years, that responsibility has taken him from a Military Police gate to executive protection, critical infrastructure, and now the leadership of CoreX’s IRM practice.
“It has been a long (but exciting journey. I started 30 years ago protecting people and facilities from external threats as a Military Police Gate Guard. Then I progressed to protecting Critical Assets (Executives) from internal and external worldwide threats as a Protective Security Agent. I progressed further protecting Critical Infrastructure from physical and cyber threats. Now I find myself leading a team that is focused on all of the above and at the forefront of helping clients achieve autonomous security and risk.”
Across that journey, Cheeley has come to see alignment, not another policy, as the starting point for effective governance.
“I learned early that most significant business problems are not caused by a lack of policies. They're caused by a lack of alignment. When leadership, operations, security, and technology teams make decisions independently, organizations create blind spots. The stakeholders that should be in the room, are often not even aware the room exists. That realization shaped my belief that governance should enable better decisions, not simply enforce rules.”
That belief informs the way he talks about integrated risk management. Cheeley does not define IRM by a deployment or a compliance checklist, but rather by whether people across the business can use risk information to make decisions together.
“The biggest misconception is that IRM is a technology project or a compliance exercise. In reality, IRM is a business decision-making capability. A mature IRM program is one where risk, compliance, security, IT, and business leaders are operating from the same data, the same control framework, and a shared understanding of business impact. The organization is not just documenting risk, it is making better decisions because of it.”
For Cheeley, bringing those groups together means making governance part of the work itself. It also means identifying the people who own the IT items and business entities involved. Without them, a risk team cannot remove the divisions between departments on its own.
“Many organizations treat governance as a checkpoint instead of embedding it into the workflow. When governance lives outside the business process, it creates friction. When governance is integrated into how work is done, it accelerates decisions because people have the information and controls they need without slowing execution. This is usually confounded by lack of business mapping to Entities (both core and Configuration Items). The goal should be governed speed, not governance versus speed.”
That is the kind of connected program Cheeley wants to help customers build at CoreX. He sees an opportunity to draw on both ServiceNow expertise and risk and compliance experience while helping customers establish operating models that last beyond a technology deployment.
“What excites me most is the opportunity to help organizations move beyond fragmented governance and compliance programs and build truly connected risk programs. CoreX has a unique combination of deep ServiceNow expertise and real-world risk and compliance experience. Our focus is not just deploying technology, but helping customers create sustainable operating models that connect governance, risk, compliance, security, and business outcomes.”
The questions customers ask are changing, too. Cheeley says executive teams increasingly want to understand operational resilience, cyber risk, third-party risk, and AI-related risks in business terms, not only whether an audit requirement has been met.
“Ten years ago, GRC discussions were often compliance-driven, or specific to one external Audit. Today, executive teams increasingly want to understand operational resilience, cyber risk, third-party risk, and AI-related risks in business terms. They want faster visibility, measurable outcomes, and evidence that risk investments are reducing business exposure. The focus is shifting from 'Are we compliant?' to 'Are we resilient?'”
Cheeley sees ServiceNow IRM’s value in its ability to connect risk work with the operational information and workflows that can help answer those questions. The measures he wants to see follow the same logic: not simply how much activity a team records, but what changes as a result.
“The biggest differentiator is connectivity. Traditional GRC solutions often become systems of record. ServiceNow becomes a system of action. It connects risk, controls, compliance activities, IT operations, security operations, asset data, and workflows in a single platform. IRM is a 'consumer' of CMDB and core data (departments, locations, etc) and when healthy places the onus on the actual owners.”
“I am more interested in metrics that demonstrate outcomes, such as remediation effectiveness, control performance, reduction in business exposure, or time required to identify and respond to emerging risks.”
Looking ahead, Cheeley calls for common control frameworks, automation and continuous monitoring, and governance for emerging technologies, especially AI. He also expects the people leading IRM programs to spend more time helping others understand and act on information.
“Future IRM leaders will need to understand AI governance, data management, operational resilience, and executive communication. They will spend less time collecting information and more time interpreting it, validating automated outputs, and helping leadership make informed decisions.”
Outside CoreX, Cheeley makes time for family, friends, technology, and learning. He also continues to serve as a Command Sergeant Major in the U.S. Army Reserve. In describing that service, he returns to the work that has run through his career, and to the practical question at the heart of his approach to IRM: what helps people recognize a risk and respond to it?
“I am a Military Police Senior Leader who (although with slightly different flavor) identifies threats, assesses risk, implements controls, monitors effectiveness, and ensures mission success.”