P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Available for new engagementsCambridge, United Kingdom

Parminder Kumar Sharma.

Cyber security and AI systems leader. Inventor. Independent adviser. 16 years of senior delivery across regulated sectors, now applied to AI governance and adversarial assurance from Cambridge.

I. Human intelligence

Judgement

Context, ethics, accountability.

Artificial precision II.

Pattern

Scale, recall, deterministic logic.

Neither half is the product. The work is the join: knowing which decisions a machine should never be handed, and which ones a person can no longer make alone.

Judgement

Pattern

One point belongs to both halves

16
Years in delivery

Since 2010

7
Senior roles

Regulated sectors

5
Lead credentials

Audit and management

2
Ventures built

Healthcare AI

01 / The practice

What this site is for

Written by a practitioner who runs the assessments and audits the frameworks he writes about.

This site does two things. The Briefing publishes daily analysis of cyber and AI security news: what happened, why it matters, and what to do about it. The practice behind it advises organisations on AI security and governance, security leadership, and compliance.

The work spans a fractional vCISO practice, ISO/IEC 42001 and 27001 programmes delivered through certification, adversarial testing of LLM systems, and healthcare AI ventures built first-hand. Everything published here comes from that delivery experience; nothing is rewritten vendor material.

02 / Credentials

Certified where it counts

Lead-auditor level on both standards this practice delivers, and management-track credentials rather than tool-specific ones.

  • 01

    ISACA AAISM

    Advanced in AI Security Management

    AI risk, assurance and governance at management level.

  • 02

    ISO/IEC 42001 Lead Auditor

    AI management systems

    Audits the standard this practice implements.

  • 03

    ISO/IEC 27001 Lead Auditor

    Information security management systems

    Delivered through certification, not to readiness.

  • 04

    CISM

    Certified Information Security Manager

    ISACA's management-track security credential.

  • 05

    CCISO

    Certified Chief Information Security Officer

    Executive security leadership across five domains.

  • Memberships

    • ISACA UK Advocacy Task Force 2026
    • AWS Security certified

    Appointments

    • Volunteer Cyber Threat Intelligence Team Lead, CSFI

03 / Experience

The work, without the logos

16 years across security leadership, AI governance and healthcare technology. Employers are not named: most of this work sits under confidentiality, and the sector and the accountability tell you more than a logo would.

  1. Aug 2024 – present

    Head of IT and Cyber Security

    UK tools and equipment business

    Single point of accountability for information security, IT operations, governance and digital risk, and technical lead for a leadership-backed AI product programme. Most delivery time sits on the AI side: taking new tools from concept toward commercial launch, currently a pipeline of five initiatives.

    • Built and runs an AI assurance capability: data governance, model evaluation, LLM and agent guardrails, secure deployment
    • Designs and ships LLM and agent applications with retrieval, tool use and workflow automation, rather than specifications alone
  2. Apr 2024 – Mar 2025

    Cyber Threat Intelligence Team Lead

    Cyber Security Forum Initiative, volunteer appointment

    Led a volunteer intelligence team producing analytical reporting with evidence-based recommendations for senior leadership, as part of the Cyber Intelligence and Collections Project. Also developed the CyberOps course for the same organisation.

  3. Aug 2021 – Aug 2024

    Cyber Security Consultant

    Data and insight firm, remote

    Infrastructure hardening, vulnerability management and penetration testing, translating findings into risk-based remediation plans and audit-ready evidence.

  4. Jul 2020 – Jul 2024

    Vice President of Information Technology

    Global managed security services provider

    Directed security service delivery to a client base exceeding 500 organisations, including enterprises of 3,000 or more employees. Ran a managed detection and response practice and carried board-level strategy alongside hands-on incident work.

    • Grew the security operations team from 6 to 18 analysts and engineers across SIEM, SOAR, threat intelligence and 24/7 detection and response
    • Led readiness and evidence for six third-party certification audits across two client organisations, with zero major non-conformities
    • Led ransomware response, digital forensics and recovery decisions in constrained environments
  5. May 2020 – Mar 2024

    IT and Cyber Security Instructor

    Global training provider, freelance

    Designed and delivered technical training across security and IT disciplines. The teaching practice behind the training and career coaching offered today.

  6. May 2018 – present

    Independent Cyber Security Consultant and Virtual CISO

    Global, remote and onsite

    Security and AI governance advisory: ISO 27001 and ISO 42001 implementation and audit, AI and LLM security assessment, regulatory readiness across the EU AI Act, NIS2 and DORA, and board-level briefing. Engagements run from a two-hour session to a full certification programme.

    • ISO/IEC 42001:2023 and ISO/IEC 27001:2022 Lead Auditor
    • Publishes open tooling and datasets used by practitioners
  7. Sep 2010 – Apr 2018

    IT and PACS Administrator

    Diagnostic imaging provider, India

    Eight years inside clinical imaging: PACS, DICOM, HL7, HIS and RIS implementation, vulnerability management and security audit across critical clinical environments, and training clinical staff on privacy and secure operation.

    • The origin of the healthcare AI assurance practice: clinical systems learned from the inside rather than from a standard

Built, not held

Ventures

Named, unlike the roles above. An employer’s identity is theirs and sits under confidentiality; a venture you founded is your own record.

  • ZeromedCommercialised 2017

    Inventor

    A medical imaging technology taken to commercial release and into clinical use, covering radiology, pathology and back-office workflow.

    Building a clinical product means meeting clinical safety and information governance from the inside rather than assessing someone else's answer to them.

  • OxRad

    Technical co-creator

    A federated AI radiology research platform, architected so that model work can happen without centralising patient data.

    Federation is a data protection decision expressed as architecture, which is the shape most healthcare AI assurance questions eventually take.

    Visit OxRad

Offered, not applied for

Appointments and recognition

Roles somebody else decided to offer, which is what separates these from a certificate.

  • 2026

    ISACA UK Advocacy Task Force

    Appointed member, contributing to ISACA's UK policy and advocacy positions.

  • 2026

    ISACA AAISM Quality Assurance Review Team

    Reviewing the Advanced in AI Security Management certification, the credential itself.

  • EC-Council C|RAGE beta testing committee

    Pre-release review of the certification's content and assessment design.

  • 2024 – 2025

    Cyber Security Forum Initiative

    Volunteer cyber threat intelligence team lead, and CyberOps course developer.

Work with me

Assessments, readiness, and advisory, delivered personally.

AI security assessments, ISO 42001 readiness, vCISO advisory and compliance assurance, documented so your team can operate independently once the engagement ends.