Home About Experience Insights Projects Resources Contact
Insights & Speaking

Writing and speaking on cybersecurity leadership

A record of recent speaking engagements, and the future home for longer-form writing on security governance, leadership and strategy.

Selected articles, published on Medium

Longer-form writing on cyber security governance, leadership and culture, published externally while this page grows into its own home for new content.

Aug 2026

The New CISO's First 90 Days: Diagnose Before You Prescribe

Applying Michael Watkins' First 90 Days framework to CISO transitions — diagnosing whether you've inherited a start-up, turnaround, realignment or growth problem before choosing a playbook, and negotiating expectations with your boss up front rather than by accident.

Jul 2026

Paths of Desire

Why the most effective security controls are the ones users never notice, and why a circumvented control is worse than no control at all — illustrated by two decades of workarounds, from disk encryption codes on Post-it notes to shadow file-sharing over mobile data.

Nov 2023

The Floor is Lava

Why a cyber incident is inevitable, and how peer networks, shared threat intel and layered defences build resilience. Co-written with Ambrose Neville (University of Surrey).

Nov 2022

Phishing simulations — do they really work?

Results from phishing our own IT department, and why fast response and a no-blame reporting culture matter more than click-rate metrics.

Jun 2022

The £1m laptop

Why the data on an executive's laptop is worth far more than the device, and why leaders must visibly follow the security guidance they expect from everyone else.

Jun 2022

My home office setup

A personal walkthrough of the desk, display, chair and video-call kit behind a well-equipped home office.

Jun 2022

Achieving Cyber Essentials compliance

Practical gaps between the Cyber Essentials requirements and the Evendine question set, and the BYOD scoping challenges facing UK higher education.

Jun 2022

TL;DR — How to implement ISO 27001

A short, practical answer to a common question: read the standards, and follow them without second-guessing.

View All Posts on Medium →

Panels, keynotes and guest lectures

Dec 2025

Gartner C-Level Communities, UK & Ireland CISO Inner Circle

Table discussion leader: "Resilient Leadership: Optimising Cybersecurity in a Dynamic World"

Jul 2025

Gartner C-Level Communities, UK & Ireland CISO Community Town Hall

Panel member: "Fostering a Digital Native Mindset to Cybersecurity"

Mar 2025

University of Southampton

Guest Lecture: "Advanced Topics in Security (Cyber & Physical)"

Nov 2024

Jisc Security Conference

Keynote panel: "AI in Cyber Security: The Benefits, Pitfalls, and Implications for the Future"

Nov 2023

Jisc Security Conference

Presentation: "The Floor is Lava: Lessons from the Field" (reprised by request, Spring 2024)

More writing, hosted here

This page will grow into a home for original articles and commentary on cyber security governance, CISO leadership and building security functions from the ground up, alongside the writing published on Medium above. Check back soon.