I'm a cybersecurity executive with 25 years' experience across defence, technology and higher education, with a track record of building security functions from the ground up and enabling organisational growth through risk-informed leadership.
Teams that operate as gatekeepers eventually get circumvented, while those that help the business move faster and more confidently become indispensable. I focus on early engagement with project teams rather than late-stage compliance reviews, and measure a function's value through business outcomes rather than activity metrics alone.
I'm equally committed to developing the next generation of security leaders through inclusive hiring and deliberate team development.
A blend of governance, technical depth and people leadership, shaped by roles spanning defence, critical research infrastructure and higher education.
Board and executive reporting, cyber security strategy, enterprise risk management, budget ownership, regulator engagement and crisis response planning.
ISO 27001, NIST CSF 2.0, Cyber Essentials Plus, NHS DSPT, DEF STAN 05-138, and GDPR / DPIA practice across regulated and research environments.
Identity and access management, MFA, SOC and managed detection & response, EDR/XDR, SIEM, vulnerability management and incident response.
Team building and leadership development, security awareness and culture change, and inclusive hiring within technical teams.
A career built primarily at the University of Southampton, following an earlier decade in infrastructure and managed security services at QinetiQ.
Led cybersecurity strategy, operations and risk for a £600m+ university, growing the team from two to nine and delivering ISO 27001 certification.
Authored the organisation's first board-approved Cyber Security Strategy and executive-level Incident Response Plan.
Led technical development of QinetiQ's first commercial hosting services and 24/7 secure hosting infrastructure for UK Government and commercial clients.
Table discussion leader: "Resilient Leadership: Optimising Cybersecurity in a Dynamic World"
Panel member: "Fostering a Digital Native Mindset to Cybersecurity"
Keynote panel: "AI in Cyber Security: The Benefits, Pitfalls, and Implications for the Future"
The CISO First 90 Days Playbook is a practical, framework-led guide for any incoming CISO or Head of Cyber Security, built around Michael Watkins' STARS model — with editable companion templates to track your diagnostics, conversations and outputs from day one.
Download the Playbook →