Insights

Perspectives on security, resilience & transformation.

The themes shaping how boards and executive teams should think about cyber risk, technology, and change. Full articles published on LinkedIn.

Focus themes

What I write and speak about.

Translating the frontier of cybersecurity and technology into board-level strategy.

01
🛡️

Cyber Resilience by Design

Building organisations that withstand, respond to, and recover from cyber disruption — beyond compliance, towards true operational resilience.

02
🤖

Agentic AI & AI Governance

Adopting AI responsibly when the AI acts on its own: agent inventory, scoped identity, permission boundaries and audit trails — the controls that let enterprises capture value without losing control.

03
🏛️

Board-Level Cyber

Reporting cyber risk in the language of the board — connecting security investment to enterprise value and confidence.

04
⚖️

Regulation & Compliance

Turning regulatory obligation into competitive advantage across financial services and critical infrastructure.

05
🔄

Enterprise Transformation

Operating-model change, M&A integration, and modernisation delivered without compromising security.

06
☁️

Cloud & Modernisation

Modernising legacy estates and adopting cloud with security and resilience engineered in from the start.

07
🧬

Post-Quantum Migration

Cryptographic discovery and inventory, crypto agility, and a migration plan that lands before the 2030 deprecation of RSA-2048 and P-256.

08
🏭

OT/ICS & Critical Infrastructure

Resilience where cyber failure becomes safety failure — zone-and-conduit design and supplier assurance under IEC 62443.

Selected articles & commentary

Published perspectives.

Commentary on the strategic and regulatory issues shaping board-level technology decisions across the UK and internationally.

📄

UK Cyber Security & Resilience Bill

Analysis of what the Bill — through the Commons and now in Lords scrutiny — means for CISO accountability, supply chain security, and board governance obligations in regulated sectors.

Regulatory Strategy · Board Governance

📄

AI Governance: From Policy to Practice

How organisations move from regulatory compliance to genuine AI governance — building the controls, accountability structures, and board visibility that the EU AI Act and ISO 42001 demand.

AI Governance · EU AI Act · ISO 42001

📄

Board Cyber Liability: The Shifting Landscape

With DORA applying since January 2025, NIS2 national laws in force and CRA reporting obligations live, individual director liability for cyber failures is no longer theoretical. What boards need to understand now.

Board Risk · DORA · NIS2 · CRA

📄

Post-Quantum Migration: A Board Briefing

The standards landed in 2024 and the deadlines are now on the calendar: FIPS 140-2 validated certificates have moved to NIST's Historical list, and RSA-2048 and ECC P-256 are deprecated from 2030. The work that matters is cryptographic discovery, inventory and agility — and industry surveys in 2026 suggest most organisations have not started.

Quantum Risk · Emerging Threat · NIST PQC

📄

Operational Resilience vs Cyber Resilience

Understanding the distinction — and the overlap — between operational resilience frameworks and cyber resilience programmes, and how CISOs should brief boards on both.

Operational Resilience · DORA · NIST CSF

📄

The AI Copyright & IP Challenge for Enterprises

How organisations deploying generative AI face emerging intellectual property risks — and the governance framework senior leaders need to protect their organisations.

AI Risk · IP Governance · Responsible AI

Current perspectives

The issues that demand board attention now.

Where strategy, regulation, and technology converge — and what leadership teams need to act on.

⚖️

UK Cyber Security & Resilience Bill

Through all Commons stages on 16 June 2026 and past four Grand Committee sittings in the Lords, the Bill now awaits Report stage — date unannounced. Royal Assent is expected late 2026 or spring 2027 depending on parliamentary progress, with substantive obligations expected around 2028 through secondary legislation. Map your exposure now.

🤖

EU AI Act: Compliance is Just the Floor

Prohibited practices applied in February 2025, GPAI rules in August 2025, and transparency duties went live in August 2026; the Digital Omnibus pushed high-risk obligations out to December 2027 and August 2028 — a reprieve, not a reason to stop. Most organisations are focused on mapping systems to risk tiers. The harder question — and the one that creates competitive advantage — is how to build AI governance that improves decision quality, not just audit outcomes.

🔐

Post-Quantum: The Migration Is Overdue

NIST's PQC standards have been final since 2024, FIPS 140-2 certificates are now Historical, and RSA-2048 and P-256 fall off in 2030. Harvest-now-decrypt-later makes the exposure current, not future. Start with crypto discovery and agility, not algorithm shopping.

🏛️

DORA, NIS2 & the CRA: Beyond Checkbox Compliance

DORA has applied since January 2025 and is actively supervised; NIS2 national laws are in force with enforcement stepping up; CRA reporting obligations became applicable on 11 September 2026, with full application on 11 December 2027. Organisations treating this as a controls refresh — rather than a governance transformation — are underestimating their exposure.

🕵️

Shadow Agents: The Attack Surface Nobody Inventoried

Agent fleets are growing faster than the controls around them. Agents hold excessive permissions, act on behalf of users who never approved the action, and leave no audit trail. Every agent needs a scoped identity, a permission boundary, and a log that will hold up in front of a regulator.

🏭

OT/ICS: Resilience Where It Actually Hurts

Critical infrastructure is where a cyber failure becomes a safety failure. Zone-and-conduit design, secure remote access and supplier duties under IEC 62443 — now sitting alongside NIS2 and CRA obligations on the same estate.

Media & speaking

A trusted voice for boards, conferences & media.

Available for keynotes, panels, executive briefings, and media commentary on the issues reshaping enterprise risk.

🎤

Keynotes & conferences

Keynote and panel speaking on cybersecurity strategy, agentic AI governance, operational resilience, OT/ICS security, and post-quantum migration — translating complex risk into board-ready insight.

🏛️

Board & executive briefings

Closed-door briefings for boards, audit & risk committees, and executive teams on emerging threats and the decisions they demand.

📺

Media commentary

Commentary and thought leadership on cyber, AI, and quantum risk for industry and mainstream media.

“

Organisations don't lose systems first. They lose decision authority — and then everything else follows. Security leadership exists to keep the board in command.

Follow along

Read the full perspectives.

Articles, commentary, and updates are published on LinkedIn.