I help businesses design and implement risk-based security frameworks that support growth, protect assets and align with long-term goals. My focus is on building practical, scalable policies and strategies that reflect the real-world needs of your organisation, not just industry buzzwords or technical checklists.
I work with leadership teams to build tailored security programmes that align with business priorities. This includes setting clear governance structures, defining responsibilities and creating policy frameworks that grow with your organisation.
I specialise in reviewing and developing policies and controls that are proportionate to the actual risks your business faces. Whether you're starting from scratch or need to mature your existing approach, I ensure your policies are actionable, relevant and understood across the business.
I support organisations in setting long-term security objectives through realistic roadmaps. From defining key security outcomes to aligning with compliance goals such as ISO 27001, PCI-DSS, or SOC 2, I ensure that security decisions are grounded in business value.
I help technical teams articulate risk in a way business leaders can act on. Whether it's making the case for investment or communicating the impact of a policy, I provide clarity and alignment between operational detail and strategic direction.
I work with EU and NA startups, scale-ups and growing businesses that are ready to take a more structured approach to security.
I add the most value to organisations that:
Are scaling rapidly and need a strategic approach to security
Want to align security with business risk, not just compliance
Are preparing for audits or client assurance requests
Are building or refreshing their internal security governance
Are working through Mergers & Acquisitions and need a review of security best practices across their entities
I take a pragmatic, business-first approach to risk, governance and information security. I believe security should support the business, not slow it down. That means no one-size-fits-all templates, no jargon and no overengineering. Just well-informed, strategic advice that protects what matters most.