Where my experience sits.
The areas I have worked in hands-on, and write about here.
Core areas
Specialist areas
Narrower areas where I have direct delivery experience.
AI Security and Governance
Assessment, adversarial testing, and governance for AI systems: from agent least-privilege reviews to the EU AI Act.
Cyber Security Leadership
Embedded vCISO leadership and incident readiness: board-level direction, and response plans tested before they are needed.
Compliance and Assurance
Internal audit and third-party assurance that covers AI suppliers properly, as a Lead Auditor.



















