Cybersecurity and GRC
Security governance, risk and compliance advisory for regulated organizations.
15 years in cybersecurity, technology risk and IT audit, including EY and Accenture. I help financial-sector and regulated organizations build the security program their board, auditors and regulators expect, as a project-based advisor or your fractional CISO.
Services
What I help with.
Every engagement is scoped in writing with fixed deliverables. I advise, design and help your team build to your requirements, recognized frameworks and peer benchmarks.
Security program build
Stand up or mature a cybersecurity program on the NIST CSF or ISO 27001, with a control set your auditors and supervisors accept.
Audit and regulatory readiness
Prepare for and clear audits and regulatory examinations in Switzerland, the United States and the UAE. Findings closed, controls evidenced, review-ready.
Risk assessment and board reporting
Quantify and prioritize cyber risk, then present it in board-ready terms with a treatment plan leadership can approve and fund.
Policies, standards and controls
Author the policies and standards that turn intent into daily practice, mapped to your obligations and sized to your organization.
Third-party and AI governance
A vendor risk process that keeps your suppliers from extending your exposure, and an AI governance framework aligned to ISO 42001 and the EU AI Act.
Fractional CISO
Ongoing security leadership on a part-time retainer: strategy, governance, reporting, team mentoring and regulator engagement, without a full-time salary.
How an engagement runs
Three steps, no surprises.
Call
20 minutes, free. You describe the gap and the deadline. I say whether I can close it and roughly what it takes.
Written scope
Deliverables, timeline and a fixed price in writing within two business days. You approve before anything starts.
Delivery and handover
I work with your team, document everything, and hand over a program you can run and evidence without me.
Questions
Before you reach out.
Which industries and regions?
Banking, insurance, asset management and other regulated industries. I have delivered in Luxembourg, Switzerland and the United States and am now based in Dubai, so Gulf, European and US time zones all work.
Project or retainer?
Both. A defined gap (a framework, an audit, a risk assessment, a policy set) runs as a fixed-price project. Ongoing leadership runs as a fractional CISO retainer, usually one to two days a week.
Which frameworks?
NIST CSF, ISO 27001 and 27002, ISO 42001 and the EU AI Act for AI governance, and the local supervisory requirements that apply to you (FINMA, NYDFS, DFSA and ADGM among them).
What does it cost?
A fixed price per project, quoted in writing after the call. Retainers are priced per day. No hourly billing and no change orders on an agreed scope.
Tell me about the gap.
A 20-minute call or an email is enough for me to say whether I am the right person and what it would take.