Home / Expertise

Areas of Expertise

Seven areas where I work with leaders and institutions — each grounded in the same conviction: cyber risk is an institutional question before it is a technical one, and it should be governed accordingly.

What I advise on

Seven areas of practice

Most engagements draw on several of these at once. What they share is a starting point: understanding what is actually material to the institution, before deciding what to do about it.

01

Cybersecurity Strategy

Setting the direction before setting the budget. Most organizations do not have a security problem so much as a prioritisation problem — a long list of things that could be done, with no defensible basis for choosing between them. Strategy work establishes what the institution is actually protecting, what would genuinely hurt if it failed, and where finite resources should go first.

Typically includes
  • Multi-year cybersecurity roadmaps
  • Investment prioritisation
  • Programme design and sequencing
  • Independent strategy review
02

Digital Trust

Whether people can rely on the digital systems they are asked to use. Trust is the quiet precondition for every digital service — a payment platform, a health record, a digital identity programme. It is built through data protection, identity assurance, privacy and transparency, and it is lost far faster than it is earned.

Typically includes
  • Data protection and privacy posture
  • Identity and access management
  • Secure digital service design
  • Digital public infrastructure
03

Cyber Resilience

Planning for the day prevention fails. Resilience is the capacity to anticipate, withstand, recover from and adapt to disruption — and it is measured in how an organization behaves during a bad week, not in how many controls it owns. That means readiness rehearsed in advance rather than improvised under pressure.

Typically includes
  • Incident response readiness
  • Tabletop exercises
  • Business continuity and recovery
  • Critical infrastructure protection
04

Governance, Risk & Compliance

Making oversight defensible. Compliance frameworks are often treated as a hurdle to clear once a year; handled properly they are a structure for governing risk continuously. My work here is largely about translation — turning framework requirements into decisions a board can actually take responsibility for, and evidence that stands up to scrutiny.

Typically includes
  • Risk-based certification and accreditation
  • Security assessment and authorization
  • Board reporting and oversight design
  • Third-party and supply chain risk
05

Cloud Security

Moving to cloud without inheriting risk you cannot see. Cloud adoption redraws the boundary of what an organization controls, and the shared responsibility model is widely misread — often only discovered after something goes wrong. The work is establishing what you are still accountable for, and governing it across on-prem, cloud and hybrid environments.

Typically includes
  • Azure and AWS security posture
  • Cloud governance and shared responsibility
  • Secure architecture review
  • Hybrid environment security
06

Cyber Risk Forecasting

Looking further ahead than the last incident. Most assessments describe where an organization is exposed today. Forecasting asks a harder question: which cyber, technology and institutional risks are likely to become material over the next one to three years, and what should be started now — while there is still time for it to matter.

Typically includes
  • Emerging threat and technology analysis
  • Institutional and systemic risk
  • AI and cybersecurity implications
  • Forward investment priorities
07

Health Informatics & Data Protection

Where clinical systems meet security obligations. Health data carries a particular weight: the consequences of getting it wrong are felt by patients, and the regulatory exposure is unforgiving. Having worked directly on EHR adoption, interoperability and clinical training, I advise on the security and privacy of health information rather than treating healthcare as just another vertical.

Typically includes
  • EMR/EHR security and privacy
  • HIPAA compliance posture
  • Health data interoperability
  • Clinical systems risk
Frameworks

The standards I work within

Subject-matter expertise in risk-based certification and accreditation. Knowing a framework is not the same as knowing how to make an institution genuinely defensible under it.

FISMA
Federal information security management and reporting.
RMF & DoD RMF
Risk Management Framework, including defence implementations.
FedRAMP
Authorization for cloud services in federal use.
NIST CSF
Cybersecurity Framework for organizational risk management.
ISO 27001
International information security management standard.
HIPAA
Protected health information security and privacy.
PCI DSS
Payment card data security requirements.
GDPR & DIACAP
Data protection regulation and legacy accreditation.
Where this applies

On‑prem, cloud, or hybrid

Few institutions are cleanly one thing. Most are mid-migration, running old systems alongside new ones — which is precisely where risk tends to hide.

On‑Premises
Legacy infrastructure, network architecture, and the systems institutions cannot simply switch off.
Cloud
Azure and AWS environments, cloud governance, and the responsibilities that do not transfer with the workload.
Hybrid
The seams between old and new — usually the least governed and most consequential part of the estate.

Which of these is the live problem?

Most conversations start with one area and quickly touch three others. Tell me where things stand and we can work out what actually needs attention first.