Interim & Fractional CISO.
InterimWhen trust has broken
The CISO has departed, or been removed after conflict. A breach or regulatory sanction has landed. The audit and risk committee keeps finding exposures that never get fixed. The board no longer has confidence in what it is being told. I hold the seat, establish what is actually true, and rebuild the function's credibility with the board, typically inside 90 days.
FractionalWhen the function isn't defined
Common in PE-backed and mid-market companies: the sponsor knows the risk is real, but the organisation does not know what it needs. Full-time or part-time, what it reports into, what it should cost. I define the operating model, set the governance, carry the accountability at board level, and specify the permanent hire. You buy the right function, not just a person.
BRI AssessmentWhen the risk is behavioural
Boards receive financial, operational, legal, audit, and risk reporting. No discipline converges behavioural evidence from across the organisation into a single, credible judgement of behavioural risk. The Behavioural Risk Intelligence Assessment closes that gap. You define a target and a behavioural concern. I gather the evidence, apply the methodology, and deliver a judgement you can weigh alongside every other input to the decision.
Transaction work — cyber due diligence pre-close, post-acquisition integration, exit readiness — is delivered within interim and fractional mandates.
Most organisations still treat cyber as an IT issue, which is why it reports where it reports, gets funded how it gets funded, and surprises boards the way it does.
Boards are advised in a language they cannot make capital decisions in: audit findings, maturity scores, vulnerability counts.
I translate. The board receives a clear view of actual exposure, what it costs, and a prioritised set of decisions it can execute immediately. No frameworks to learn. No distraction to the management team.
Give me a target, and I will show you behavioural risk you currently have no way of seeing.
Decision integrity in a leadership team under merger pressure. Escalation suppression inside a critical programme. Key-person dependency at executive level. Governance behaviour diverging from governance record. Every declared risk event is the downstream presentation of a behavioural trajectory observable upstream — and no function reports it.
A judgement is issued only where independent lines of behavioural evidence converge on the same assessment. Where they do not, that is reported honestly, with the stated confidence and what would need to be learned. You are not buying an opinion. You are buying a judgement that is withheld unless the evidence earns it.
No surveillance. No access to private or personal communications. The methodology derives judgement from organisational work product: what people do, decide, record and change. Independent, time-boxed, typically four to six weeks, delivered directly by the architect of the methodology.
Most engagements are conducted under NDA. Sponsor and portfolio references available in conversation.
Earlier senior roles at Nomura, Dresdner Kleinwort and Credit Suisse First Boston. CISSP · CISM · ISO 27001 Lead Implementer.