Available for new engagementsCambridge, United Kingdom
Parminder Kumar Sharma.
Cyber security and AI systems leader. Inventor. Independent adviser. 16 years of senior delivery across regulated sectors, now applied to AI governance and adversarial assurance from Cambridge.
I. Human intelligence
Judgement
Context, ethics, accountability.
Artificial precision II.
Pattern
Scale, recall, deterministic logic.
Neither half is the product. The work is the join: knowing which decisions a machine should never be handed, and which ones a person can no longer make alone.
Judgement
Pattern
One point belongs to both halves
- 16
- Years in delivery
- 7
- Senior roles
- 5
- Lead credentials
- 2
- Ventures built
Since 2010
Regulated sectors
Audit and management
Healthcare AI
01 / The practice
What this site is for
Written by a practitioner who runs the assessments and audits the frameworks he writes about.
This site does two things. The Briefing publishes daily analysis of cyber and AI security news: what happened, why it matters, and what to do about it. The practice behind it advises organisations on AI security and governance, security leadership, and compliance.
The work spans a fractional vCISO practice, ISO/IEC 42001 and 27001 programmes delivered through certification, adversarial testing of LLM systems, and healthcare AI ventures built first-hand. Everything published here comes from that delivery experience; nothing is rewritten vendor material.
02 / Credentials
Certified where it counts
Lead-auditor level on both standards this practice delivers, and management-track credentials rather than tool-specific ones.
01
ISACA AAISM
Advanced in AI Security Management
AI risk, assurance and governance at management level.
02
ISO/IEC 42001 Lead Auditor
AI management systems
Audits the standard this practice implements.
03
ISO/IEC 27001 Lead Auditor
Information security management systems
Delivered through certification, not to readiness.
04
CISM
Certified Information Security Manager
ISACA's management-track security credential.
05
CCISO
Certified Chief Information Security Officer
Executive security leadership across five domains.
Memberships
- ISACA UK Advocacy Task Force 2026
- AWS Security certified
Appointments
- Volunteer Cyber Threat Intelligence Team Lead, CSFI
03 / Experience
The work, without the logos
16 years across security leadership, AI governance and healthcare technology. Employers are not named: most of this work sits under confidentiality, and the sector and the accountability tell you more than a logo would.
Aug 2024 – present
Head of IT and Cyber Security
UK tools and equipment business
Single point of accountability for information security, IT operations, governance and digital risk, and technical lead for a leadership-backed AI product programme. Most delivery time sits on the AI side: taking new tools from concept toward commercial launch, currently a pipeline of five initiatives.
- Built and runs an AI assurance capability: data governance, model evaluation, LLM and agent guardrails, secure deployment
- Designs and ships LLM and agent applications with retrieval, tool use and workflow automation, rather than specifications alone
Apr 2024 – Mar 2025
Cyber Threat Intelligence Team Lead
Cyber Security Forum Initiative, volunteer appointment
Led a volunteer intelligence team producing analytical reporting with evidence-based recommendations for senior leadership, as part of the Cyber Intelligence and Collections Project. Also developed the CyberOps course for the same organisation.
Aug 2021 – Aug 2024
Cyber Security Consultant
Data and insight firm, remote
Infrastructure hardening, vulnerability management and penetration testing, translating findings into risk-based remediation plans and audit-ready evidence.
Jul 2020 – Jul 2024
Vice President of Information Technology
Global managed security services provider
Directed security service delivery to a client base exceeding 500 organisations, including enterprises of 3,000 or more employees. Ran a managed detection and response practice and carried board-level strategy alongside hands-on incident work.
- Grew the security operations team from 6 to 18 analysts and engineers across SIEM, SOAR, threat intelligence and 24/7 detection and response
- Led readiness and evidence for six third-party certification audits across two client organisations, with zero major non-conformities
- Led ransomware response, digital forensics and recovery decisions in constrained environments
May 2020 – Mar 2024
IT and Cyber Security Instructor
Global training provider, freelance
Designed and delivered technical training across security and IT disciplines. The teaching practice behind the training and career coaching offered today.
May 2018 – present
Independent Cyber Security Consultant and Virtual CISO
Global, remote and onsite
Security and AI governance advisory: ISO 27001 and ISO 42001 implementation and audit, AI and LLM security assessment, regulatory readiness across the EU AI Act, NIS2 and DORA, and board-level briefing. Engagements run from a two-hour session to a full certification programme.
- ISO/IEC 42001:2023 and ISO/IEC 27001:2022 Lead Auditor
- Publishes open tooling and datasets used by practitioners
Sep 2010 – Apr 2018
IT and PACS Administrator
Diagnostic imaging provider, India
Eight years inside clinical imaging: PACS, DICOM, HL7, HIS and RIS implementation, vulnerability management and security audit across critical clinical environments, and training clinical staff on privacy and secure operation.
- The origin of the healthcare AI assurance practice: clinical systems learned from the inside rather than from a standard
Built, not held
Ventures
Named, unlike the roles above. An employer’s identity is theirs and sits under confidentiality; a venture you founded is your own record.
- ZeromedCommercialised 2017
Inventor
A medical imaging technology taken to commercial release and into clinical use, covering radiology, pathology and back-office workflow.
Building a clinical product means meeting clinical safety and information governance from the inside rather than assessing someone else's answer to them.
- OxRad
Technical co-creator
A federated AI radiology research platform, architected so that model work can happen without centralising patient data.
Federation is a data protection decision expressed as architecture, which is the shape most healthcare AI assurance questions eventually take.
Visit OxRad
Offered, not applied for
Appointments and recognition
Roles somebody else decided to offer, which is what separates these from a certificate.
2026
ISACA UK Advocacy Task Force
Appointed member, contributing to ISACA's UK policy and advocacy positions.
2026
ISACA AAISM Quality Assurance Review Team
Reviewing the Advanced in AI Security Management certification, the credential itself.
EC-Council C|RAGE beta testing committee
Pre-release review of the certification's content and assessment design.
2024 – 2025
Cyber Security Forum Initiative
Volunteer cyber threat intelligence team lead, and CyberOps course developer.
Work with me
Assessments, readiness, and advisory, delivered personally.
AI security assessments, ISO 42001 readiness, vCISO advisory and compliance assurance, documented so your team can operate independently once the engagement ends.