Cybersecurity leadership built on trust, not authority
I'm a cybersecurity executive with 25 years' experience across defence, technology and higher education, with a track record of building security functions from the ground up and enabling organisational growth through risk-informed leadership.
Security functions succeed when they earn trust rather than demand it
Teams that operate as gatekeepers eventually get circumvented, while those that help the business move faster and more confidently become indispensable. I focus on early engagement with project teams rather than late-stage compliance reviews, and measure a function's value through business outcomes rather than activity metrics alone.
I'm equally committed to developing the next generation of security leaders through inclusive hiring and deliberate team development.
Where I add the most value
A blend of governance, technical depth and people leadership, shaped by roles spanning defence, critical research infrastructure and higher education.
Governance & Leadership
Board and executive reporting, cyber security strategy, enterprise risk management, budget ownership, regulator engagement and crisis response planning.
Frameworks & Standards
ISO 27001, NIST CSF 2.0, Cyber Essentials Plus, NHS DSPT, DEF STAN 05-138, and GDPR / DPIA practice across regulated and research environments.
Technical & Operational
Identity and access management, MFA, SOC and managed detection & response, EDR/XDR, SIEM, vulnerability management and incident response.
People & Culture
Team building and leadership development, security awareness and culture change, and inclusive hiring within technical teams.
Roles that have shaped my practice
A career built primarily at the University of Southampton, following an earlier decade in infrastructure and managed security services at QinetiQ.
Associate Director Cyber Security (CISO), University of Southampton
Led cybersecurity strategy, operations and risk for a £600m+ university, growing the team from two to nine and delivering ISO 27001 certification.
Head of Cyber Security, University of Southampton
Authored the organisation's first board-approved Cyber Security Strategy and executive-level Incident Response Plan.
Senior Internet Systems Engineer, QinetiQ
Led technical development of QinetiQ's first commercial hosting services and 24/7 secure hosting infrastructure for UK Government and commercial clients.
Recent speaking engagements
Gartner C-Level Communities, UK & Ireland CISO Inner Circle
Table discussion leader: "Resilient Leadership: Optimising Cybersecurity in a Dynamic World"
Gartner C-Level Communities, UK & Ireland CISO Community Town Hall
Panel member: "Fostering a Digital Native Mindset to Cybersecurity"
Jisc Security Conference
Keynote panel: "AI in Cyber Security: The Benefits, Pitfalls, and Implications for the Future"
Take the guesswork out of your first 90 days
The CISO First 90 Days Playbook is a practical, framework-led guide for any incoming CISO or Head of Cyber Security, built around Michael Watkins' STARS model — with editable companion templates to track your diagnostics, conversations and outputs from day one.
Download the Playbook →