Areas of Expertise
Seven areas where I work with leaders and institutions — each grounded in the same conviction: cyber risk is an institutional question before it is a technical one, and it should be governed accordingly.
Seven areas of practice
Most engagements draw on several of these at once. What they share is a starting point: understanding what is actually material to the institution, before deciding what to do about it.
Cybersecurity Strategy
Setting the direction before setting the budget. Most organizations do not have a security problem so much as a prioritisation problem — a long list of things that could be done, with no defensible basis for choosing between them. Strategy work establishes what the institution is actually protecting, what would genuinely hurt if it failed, and where finite resources should go first.
- Multi-year cybersecurity roadmaps
- Investment prioritisation
- Programme design and sequencing
- Independent strategy review
Digital Trust
Whether people can rely on the digital systems they are asked to use. Trust is the quiet precondition for every digital service — a payment platform, a health record, a digital identity programme. It is built through data protection, identity assurance, privacy and transparency, and it is lost far faster than it is earned.
- Data protection and privacy posture
- Identity and access management
- Secure digital service design
- Digital public infrastructure
Cyber Resilience
Planning for the day prevention fails. Resilience is the capacity to anticipate, withstand, recover from and adapt to disruption — and it is measured in how an organization behaves during a bad week, not in how many controls it owns. That means readiness rehearsed in advance rather than improvised under pressure.
- Incident response readiness
- Tabletop exercises
- Business continuity and recovery
- Critical infrastructure protection
Governance, Risk & Compliance
Making oversight defensible. Compliance frameworks are often treated as a hurdle to clear once a year; handled properly they are a structure for governing risk continuously. My work here is largely about translation — turning framework requirements into decisions a board can actually take responsibility for, and evidence that stands up to scrutiny.
- Risk-based certification and accreditation
- Security assessment and authorization
- Board reporting and oversight design
- Third-party and supply chain risk
Cloud Security
Moving to cloud without inheriting risk you cannot see. Cloud adoption redraws the boundary of what an organization controls, and the shared responsibility model is widely misread — often only discovered after something goes wrong. The work is establishing what you are still accountable for, and governing it across on-prem, cloud and hybrid environments.
- Azure and AWS security posture
- Cloud governance and shared responsibility
- Secure architecture review
- Hybrid environment security
Cyber Risk Forecasting
Looking further ahead than the last incident. Most assessments describe where an organization is exposed today. Forecasting asks a harder question: which cyber, technology and institutional risks are likely to become material over the next one to three years, and what should be started now — while there is still time for it to matter.
- Emerging threat and technology analysis
- Institutional and systemic risk
- AI and cybersecurity implications
- Forward investment priorities
Health Informatics & Data Protection
Where clinical systems meet security obligations. Health data carries a particular weight: the consequences of getting it wrong are felt by patients, and the regulatory exposure is unforgiving. Having worked directly on EHR adoption, interoperability and clinical training, I advise on the security and privacy of health information rather than treating healthcare as just another vertical.
- EMR/EHR security and privacy
- HIPAA compliance posture
- Health data interoperability
- Clinical systems risk
The standards I work within
Subject-matter expertise in risk-based certification and accreditation. Knowing a framework is not the same as knowing how to make an institution genuinely defensible under it.
On‑prem, cloud, or hybrid
Few institutions are cleanly one thing. Most are mid-migration, running old systems alongside new ones — which is precisely where risk tends to hide.
Which of these is the live problem?
Most conversations start with one area and quickly touch three others. Tell me where things stand and we can work out what actually needs attention first.