New code of practice sets expectations for senior leaders and board members on cyber risk oversight, including annual cyber risk reviews, CISO reporting lines and incident escalation procedures.
Security architect, OT/ICS specialist, and hands-on security consultant. 25+ years of contract delivery across financial services, defence, critical national infrastructure, and regulated industries. Big 4 consulting lineage. Academic at UCL, Imperials, and Schiphol University. Contract-only engagements — architecture through implementation, governance through technical delivery.
Six contract engagement types — from fractional CISO to hands-on security architecture and programme delivery. Available for contract and consulting engagements only.
Fractional CISO engagement — hands-on security leadership on a contract basis. Risk ownership, board reporting, and programme execution without a permanent commitment.
Critical leadership continuity for M&A integration, post-incident recovery, regulatory remediation, and executive succession. Operational from Day 1.
End-to-end security transformation: hands-on architecture, technology platform modernisation, and capability delivery across complex, multi-entity organisations.
Zero-trust architecture, cloud security design, identity governance, and security-by-design embedding across engineering and product organisations.
GRC programme design, board-level risk reporting, and enterprise risk management frameworks aligned to ISO 31000, NIST CSF 2.0, and sector-specific regulatory requirements.
Hands-on regulatory compliance consulting. FCA/PRA operational resilience, DORA, NIS2, EU AI Act, and GDPR/UK GDPR across multi-jurisdictional enterprises.
Security leadership across every major regulated sector — with the regulatory and framework fluency each environment demands.
| Sector |
|---|
| Financial Services & Banking |
| Aerospace, Defence & Space |
| Critical National Infrastructure |
| Healthcare & Life Sciences |
| Energy & Utilities |
| Transport & Aviation |
| Law Enforcement & Government |
| Insurance & Capital Markets |
A career built across the most demanding environments in information security — consultancy, academia, government, and international standards.
Global advisory practice — enterprise security strategy and GRC for FTSE 100 and Fortune 500 clients
Academic appointments across University College London, Imperial College London, and Amsterdam Airport Schiphol
Oral and written testimony on the UK Cyber Security and Resilience Bill — advising national legislative cyber policy
Vice Chair, Singapore — national-government-level resilience leadership
Appointed participation in international standards development for information security management
Active engagement with the national police-led cyber resilience initiative
Editorial bylines and expert commentary in the publications that shape the profession.
“Cybersecurity is a team sport — no single vendor, framework, or practitioner secures an organisation alone. The executive’s role is to build the team, set the doctrine, and keep the board informed.”
Practitioner and architect-level command of the frameworks that govern regulated enterprise security.
Contract-only engagements. Whether you need a security architect, fractional CISO, or hands-on programme lead — architecture through delivery, governance through technical execution. The engagement starts with a conversation.
Live Standards & Regulatory Horizon
Curated each day from authoritative sources (ISO, NIST, ENISA, ESAs, ICO, NCSC). The signal pool refreshes nightly; the daily slate is selected deterministically so two readers on the same date see the same brief.
New code of practice sets expectations for senior leaders and board members on cyber risk oversight, including annual cyber risk reviews, CISO reporting lines and incident escalation procedures.
New EDPB guidelines on legitimate interests clarify the three-step test: purpose, necessity and balancing. Advertising profiling and HR monitoring face heightened scrutiny under the revised framework.
GDPR enforcement reached €4.5bn cumulative by early 2026, with Meta, LinkedIn and health-sector organisations facing the largest fines. Cross-border enforcement coordination between DPAs is accelerating.
50% of UK businesses reported a cyber breach or attack in 2025. Phishing remains the most common attack vector. Only 31% of businesses have a formal incident response plan.
ICO guidance clarifies that Article 30 RoPA must be kept current and accurately reflect processing activities. Failure to maintain RoPA is increasingly cited in enforcement notices.
ISO 27701 extends ISO 27001 and 27002 for privacy information management. Organisations with ISO 27001 certification can pursue 27701 as an integrated PIMS extension to evidence GDPR compliance.
Signal pool refreshed by kie_master_daily.py Phase 26. Methodology: curated synthesis from ISO / NIST / ENISA / ESAs / ICO / NCSC primary sources.
Live Standards & Regulatory Horizon
Curated each day from authoritative sources (ISO, NIST, ENISA, ESAs, ICO, NCSC). The signal pool refreshes nightly; the daily slate is selected deterministically so two readers on the same date see the same brief.
New code of practice sets expectations for senior leaders and board members on cyber risk oversight, including annual cyber risk reviews, CISO reporting lines and incident escalation procedures.
New EDPB guidelines on legitimate interests clarify the three-step test: purpose, necessity and balancing. Advertising profiling and HR monitoring face heightened scrutiny under the revised framework.
GDPR enforcement reached €4.5bn cumulative by early 2026, with Meta, LinkedIn and health-sector organisations facing the largest fines. Cross-border enforcement coordination between DPAs is accelerating.
50% of UK businesses reported a cyber breach or attack in 2025. Phishing remains the most common attack vector. Only 31% of businesses have a formal incident response plan.
ICO guidance clarifies that Article 30 RoPA must be kept current and accurately reflect processing activities. Failure to maintain RoPA is increasingly cited in enforcement notices.
ISO 27701 extends ISO 27001 and 27002 for privacy information management. Organisations with ISO 27001 certification can pursue 27701 as an integrated PIMS extension to evidence GDPR compliance.
Signal pool refreshed by kie_master_daily.py Phase 26. Methodology: curated synthesis from ISO / NIST / ENISA / ESAs / ICO / NCSC primary sources.