22+
Years operational experience
C-Suite
Executive & board credibility
EU-based
NIS2, CRA, GDPR, DORA expertise
01
Ongoing Retainer
Fractional CISO / vCISO
Embedded executive security leadership for organisations that need board-credible, operationally grounded security oversight without a full-time hire. Engagement structured at 1–3 days per week, with defined deliverables and a 90-day initial programme review.
What You Get
  • Security programme design and ownership — strategy, roadmap, budget justification
  • Board and audit committee reporting — risk posture, KPIs, regulatory exposure
  • Team mentoring and security culture development
  • Vendor and MSSP oversight and accountability
  • Incident response authority and escalation path
02
Fixed Scope
Security Architecture Review
Structured assessment of cloud, application, and infrastructure security posture. Delivered as a prioritised risk register with a phased remediation roadmap. Benchmarked against ISO 27001, NIS2, or SOC2 depending on regulatory context.
What You Get
  • Cloud security posture assessment (AWS, GCP, Azure) — IAM, network, data controls
  • Product security posture assessment — design principles, vulnerability exposure, ownership gaps
  • Access control and privileged access review
  • Logging, monitoring, and detection coverage map
  • Prioritised risk register with effort/impact scoring
03
Board Level
Board & Audit Committee Advisory
Translating technical risk into board-digestible reporting. Designed for CFOs, audit chairs, and NEDs who need security accountability without relying on the CISO to self-report. Also covers pre-IPO and M&A security due diligence support.
What You Get
  • Cyber risk quantification framework — financial exposure, not traffic light dashboards
  • Board reporting template with evidence-based KPIs
  • NIS2, CRA, and GDPR board accountability briefing
  • Independent security programme assessment for audit purposes
  • M&A security due diligence — target assessment and risk quantification
04
Programme Build
Product Security Programme
Strategic design and ownership of security integration across the software delivery lifecycle. For engineering organisations where security accountability and development velocity must coexist. Delivered as a programme with defined ownership, measurable security gates, and full team capability transfer — not a one-time audit.
What You Get
  • Product security programme design — ownership model, maturity roadmap, KPIs
  • Security gate strategy across the full delivery lifecycle
  • Engineering team enablement and security culture development
  • Risk-based vulnerability prioritisation framework
  • Measurable outcomes: coverage, mean time to remediate, gate pass rate
05
Programme Design
Incident Response & Readiness
Design and testing of incident response programmes against realistic threat scenarios. Leaves the organisation with a durable, exercised capability — not a document that sits in a SharePoint folder.
What You Get
  • Incident response programme design — roles, escalation, communication, recovery
  • Scenario-specific playbooks (ransomware, data breach, supply chain, insider)
  • Tabletop exercise facilitation with findings report
  • MSSP integration review and alert triage workflow design
  • Benchmarked against NIST CSF and ENISA guidelines
06
Specialist
Vendor & Outsourcing Security Governance
Security governance frameworks for organisations with significant third-party delivery. Specialist experience in regulated outsourcing environments with FDA, GMP, and EU data protection exposure. Built for organisations where the vendor IS the risk.
What You Get
  • Vendor risk assessment methodology and tiering framework
  • Contractual security requirements library (SLAs, audit rights, breach notification)
  • Ongoing vendor security monitoring programme
  • FDA/GMP compliance mapping for outsourced software development
  • Third-party access control and privileged account governance

How I Work

Every engagement starts with a direct scoping conversation — no questionnaires, no sales process. I need to understand your actual risk exposure, your team's current maturity, and your board's appetite before committing to a scope.

Deliverables are always written, measurable, and evidence-based. I do not produce strategy documents that require another consultant to implement. The outputs are operational.

01
Scoping Call
30–45 minute conversation to assess fit, current state, and define what success looks like. No commitment required.
02
Proposal & Scope Definition
Written proposal with clear deliverables, timeline, and success criteria. Fixed-scope or retainer depending on engagement type.
03
Engagement Delivery
Embedded or advisory depending on scope. Weekly written status updates. All findings documented with evidence.
04
Handover & Continuity
Full documentation package. Internal team capability transfer. Optional retainer for ongoing oversight or follow-on work.

Ready to discuss an engagement?

Engagements are evaluated on strategic fit. If the problem is real and the organisation is ready to act on findings, let's talk.

Start a Conversation →