Cybersecurity executive with 25 years' experience across defence, technology, and higher education, with a track record of building security functions from the ground up and enabling organisational growth through risk-informed leadership.
I believe security functions succeed when they're built on trust rather than authority. Teams that operate as gatekeepers eventually get circumvented, while those that help the business move faster and more confidently become indispensable.
I focus on early engagement with project teams rather than late-stage compliance reviews, and measure a function's value through business outcomes rather than activity metrics alone. I'm equally committed to developing the next generation of security leaders through inclusive hiring and deliberate team development.
Board and executive reporting · Cyber security strategy · Enterprise risk management · Budget ownership and business case development · Regulator engagement (NCSC) · Business continuity and crisis response planning · Stakeholder management
ISO 27001 · NIST Cyber Security Framework (CSF 2.0) · Cyber Essentials and Cyber Essentials Plus · NHS Data Security and Protection Toolkit (DSPT) · DEF STAN 05-138 · GDPR and Data Protection Impact Assessments (DPIA)
Identity and access management (IAM) · Multi-factor authentication (MFA) · Security operations centre (SOC) and managed detection and response (MDR) · Endpoint detection and response (EDR/XDR) · SIEM and protective monitoring · Vulnerability management · Incident response planning and tabletop exercises
Team building and leadership development · Security awareness and culture change · Inclusive hiring and diversity in technical teams
AI governance · Responsible AI / AI ethics frameworks
CISSP — (ISC)²
CISM — ISACA
BSc (Hons) Computer Science, Cardiff University (1999)