Independent cyber governance advisor to boards and senior leaders.
I support boards and senior leaders who need clear, defensible decisions on cyber risk, and the evidence to back them up.
Background
I provide CISO-level cybersecurity advisory and fractional leadership for boards and senior executives who need experienced security leadership at the right level without a permanent appointment. I hold an LL.M. in Information Technology Law and have authored two compliance frameworks covering NIS2 and the CRA Self-Assessment Tool, bringing regulatory depth that goes beyond traditional cybersecurity practice.
I support organisations in making defensible decisions on cyber risk, governance, regulatory readiness, cloud assurance and security investment. I combine practical cybersecurity experience with legal, regulatory and business understanding, helping organisations move from fragmented security activity to clear ownership, prioritised action and audit-ready evidence.
Frameworks
NIS2 Diagnostic Framework
Establishing scope, readiness, and programme direction in five days
Moves from NIS2 uncertainty to a confident programme decision, with outputs that feed directly into mobilisation.
NIS2 Programme Framework
How to run a NIS2 programme that delivers sustained compliance.
Provides a working structure for every phase, from mobilisation, through board oversight, to sustained compliance.
Briefings
Board Assurance over CRA Reporting Readiness
From 11 September 2026, Article 14 of the Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities and severe incidents affecting product security. Boards need assurance that management can meet these obligations, fifteen months before the CRA's main requirements apply in December 2027.
The Cyber Security and Resilience Bill Puts UK Boards on Notice
The Cyber Security and Resilience Bill is the UK's answer to many of the same cyber resilience problems addressed by the EU's NIS2 Directive, which does not apply in the UK after Brexit. It updates the Network and Information Systems Regulations 2018 and is moving through its final stages in Parliament. It brings managed service providers, data centres and large electricity load controllers into UK cyber regulation for the first time, with penalties reaching 4% of worldwide turnover for the most serious breaches.
Governing the NIS2 Gaps That Remain at Programme Close
A NIS2 programme may reach its planned end date with some findings still open. Supplier negotiations can take longer than expected, technical remediation may depend on wider investment, and new gaps can emerge while delivery is under way. Extending the programme until every issue disappears may be impractical because the obligations, systems and risk environment continue to change.
A NIS2 Programme Should Leave an Operating Model Behind
When a NIS2 programme closes, the steering committee stands down and the programme team disperses. The regulatory obligations continue: controls require ongoing verification and evidence, risk assessments require refreshing, the incident notification capability requires testing, and the management body needs reporting to exercise oversight. Each of these needs to be designed, owned and handed over before the programme closes.
Governing a Compliance Platform
Compliance platforms like Drata centralise the control framework, evidence and ownership structure that an auditor interrogates. Their value depends entirely on whether what is in them reflects the organisation's actual control environment.
Deciding What the Board Needs to Know About Cyber Risk
A board cannot delegate accountability for the adequacy of the information on which it oversees material cyber risk. Management may develop and produce the reporting, but the board must determine whether it supports the judgements the board is required to make. Where the board never exercises that accountability, its oversight is defined by management by default.
A simple, defensible approach.
Every engagement follows the same arc: understand the position, give clear advice, build the evidence to stand behind it.
Assess
Establish scope, maturity and the questions that actually need answering.
Advise
Deliver clear, prioritised guidance the board and leadership team can act on.
Assure
Build the governance, ownership and evidence that holds up under scrutiny.
Ready to talk?
Book a 20-minute advisory call, or send an enquiry.