AI Security & Governance
Shadow AI, EU AI Act, and what CISOs must get right before AI becomes a liability.
Thirty years of experience in the CISO seat, the boardroom, and building cyber ventures. I work with organizations that need a trusted expert - not a vendor pitching a product.
Executive-level security leadership, without the full-time cost.
Many growing companies need a seasoned CISO - but can't justify a full-time C-suite hire. As your vCISO, I embed into your leadership team, own the security roadmap, manage vendors, and ensure you're audit-ready at all times.
Who this is for: CEOs and founders without a dedicated CISO
Learn moreStrategic guidance for enterprise security leaders.
Enterprise CISOs face unique pressures - board expectations, regulatory complexity, and an evolving threat landscape. I serve as a trusted advisor to help you make better decisions faster, backed by real-world experience at the highest levels.
Who this is for: Enterprise CISOs seeking a strategic sparring partner
Learn moreTurn compliance into a competitive advantage.
Compliance is not just a checkbox - it's a signal to your customers and partners that you take security seriously. I guide organizations through the full certification lifecycle, from gap analysis to audit readiness.
Who this is for: Companies pursuing certifications or facing audits
Learn moreFind your vulnerabilities before the attackers do.
A security assessment gives you an honest, outside-in view of your risk posture. I combine automated scanning with manual expert analysis to identify gaps that automated tools miss - and deliver a clear remediation plan.
Who this is for: Organizations wanting to understand their true risk exposure
Build products with security and AI embedded from day one.
I help companies define, build, and maintain technology products - any type of product - with security and AI built into the foundation. From strategic scoping to long-term maintenance, my team owns the full lifecycle.
Who this is for: Any company that builds, buys, or operates technology products
Learn moreExtended perspectives on the areas I work in most - how I see the problem, what organizations get wrong, and what actually works.
Shadow AI, EU AI Act, and what CISOs must get right before AI becomes a liability.
EU AI Act compliance, AI system inventory, shadow AI detection, and board accountability frameworks.
What directors need to own - not just approve - as regulatory accountability grows.
Structured board advisory: NIS2 management accountability, SEC disclosure obligations, and the governance framework directors need to own - not just approve - cyber risk.
Executive security leadership on a fractional basis - roadmap, board reporting, compliance ownership, without the full-time hire.
Strategic guidance for security leaders - from someone who has been in the seat at one of the world's most targeted organizations.
Why point-in-time audits fail and what continuous exposure management actually looks like.
GDPR, ISO 27001, NIST, EU AI Act - turning compliance into strategic advantage.
Build products with security and AI embedded from day one - not added as an afterthought.
Real-world cyber insights - no vendor fluff. Just experience-driven perspectives.
Beyond advisory, I build - enterprise security services through Cybecs and next-gen CTEM through RedRok.
cybecs.com
Enterprise cybersecurity services - from managed security operations to tailored consulting engagements for demanding organizations.
redrok.io
AI-powered Continuous Threat Exposure Management (CTEM) platform - giving security teams real-time visibility into their attack surface.
Book a free 30-minute risk review. We'll look at your current posture, identify the biggest gaps, and map out a practical next step - no commitment required.
Book Your Free Risk Review