Available for new engagements · UAE, Saudi Arabia, Kuwait, Bahrain & remote worldwide Cybersecurity, AI Governance & ISO 27001/42001 Advisory

15 years in cybersecurity, built on 28 in technology.

I advise leadership teams across industries on the full arc of cyber risk — strategy, technology investment, audit readiness, and vendor selection — and design the governance models that keep the AI systems inside their organizations accountable. The result: cost-effective programs built to withstand real scrutiny, not just pass a checklist.

Nandhini Duraisamy, CISM — Cybersecurity, AI Governance and ISO 27001/42001 Consultant
CISM ISO/IEC 42001:2023 Lead Auditor ISO/IEC 27001:2022 Lead Auditor CAISP v2.0
Gulf markets United Arab Emirates Saudi Arabia Kuwait Bahrain
Industries served FMCG Healthcare Government Retail
Also experienced in Telecom Banking
About

From the server room to the boardroom.

Over 28 years in technology, the last 15 in dedicated cybersecurity leadership, I have built a career spanning the technical, commercial, and strategic dimensions of the field — beginning as an Oracle database administrator and advancing through presales, program management, IT operations, and, since 2013, executive cybersecurity strategy. I have led security and governance functions across the UAE, Saudi Arabia, Kuwait, Bahrain, Mauritius, South Korea, Europe, and the USA, for organizations ranging from entrepreneurial startups to multinational corporates — across FMCG, healthcare, government, and retail, with additional experience in telecom and banking.

My deepest specialization is the Gulf — the UAE, Saudi Arabia, Kuwait, and Bahrain — where cybersecurity and data protection expectations differ sharply from market to market. I have spent years on the ground there, in business development and delivery alike, and I build programs that respect those local requirements rather than applying a single template everywhere.

Today, I advise executive committees on AI governance and ISO 27001/42001 audit readiness, lead large-scale cyber drill and exercise programs, and guide organizations through the RFP and vendor-selection process — ensuring the technology they invest in actually strengthens their security posture.

I have limited patience for buzzwords and a firm commitment to outcomes. Every policy, process, and program I design is built to withstand audit, pressure, and real-world attack alike.

15
Years in cybersecurity leadership
28
Years in technology overall
12
Companies integrated in one year (M&A security)
10k+
Users secured across 10+ EU countries
Services

Where I help

AI governance & readiness

AI governance frameworks aligned to ISO/IEC 42001, responsible-AI policy design, and risk assessments before your regulator or customer asks for one.

ISO 27001 / 42001 audit prep

Lead Auditor-led gap assessments, documentation, and remediation plans that get organizations through certification audits the first time.

Security policies & governance

The full policy backbone — information security, incident response, business continuity, disaster recovery, and vendor risk — built to actually be followed.

Cybersecurity technology advisory

Independent, vendor-neutral guidance on security tooling and OT/IT convergence — decisions based on your risk, not a vendor's roadmap.

RFP development & vendor selection

I write RFPs that ask the right questions, score incoming proposals objectively, and help you choose the vendor that will actually deliver.

Cyber program & project leadership

End-to-end delivery of cyber drills, SOC builds, and cross-border security programs — on time, on budget, on message with the board.

Process

How an engagement runs

Understand

Map the business context first — compliance obligations, threat profile, and where confidentiality, integrity, and availability actually matter most to your operations.

Design

Architect the governance framework, security program, or vendor strategy suited to that specific risk profile, industry, and regulatory footprint — not a generic template.

Implement

Roll out the solution end to end — documentation, stakeholder coordination, technology deployment, and execution against a clear timeline.

Sustain

Support ongoing governance, review cycles, and course correction so the program holds up under real-world pressure, not just on delivery day.

Packages

Ways to work together

Ballpark figures, benchmarked against current market rates for senior, credentialed independent consultants — your actual quote depends on organization size, industry, number of entities or locations, and specific scope.

ISO 27001 / 42001 gap assessment

4–6 weeks
Starting at €4,500
per engagement, scope-dependent
  • Full gap analysis against ISO/IEC 27001:2022 or 42001:2023
  • Prioritized remediation roadmap
  • Executive-ready findings report
Discuss this package

Ongoing governance retainer

Month-to-month
Starting at €2,500
per month, scope-dependent
  • Continuous policy and governance oversight
  • Quarterly review cycles and board-ready reporting
  • On-call advisory for vendor, audit, or incident questions
Discuss this package
Track record

Where this experience was built

2026 — Present
Middle East Project Consultant · CYBER RANGES
Running cyber drill and exercise programs for large organizations — coordinating teams, timelines, and customers so high-stakes simulations deliver real value.
2020 — 2026
Managing Director / COO · Quadron Analytica & Cybersecurity
Led international portfolio management, client security interventions, and operational strategy across the Gulf region.
2018 — 2020
Director, IT Risk & Assurance · Affidea
Ran GDPR-aligned due diligence across 8 business functions and led ISO 27001 audits that integrated 12 acquired companies in a single year.
2016 — 2018
Cybertechnology & Risk, SOC · GE Digital
Built a follow-the-sun SOC from the ground up in Budapest; led incident response during the WannaCry crisis.
2013 — 2016
Director, IT Security & Governance · Anheuser-Busch InBev
Owned security strategy for 10,000+ users across 10+ EU countries — policy governance, risk and compliance, vulnerability management, and ISO maturity.
2006 — 2013
Presales, PMO & Program Management · Tata Consultancy Services
Ran presales and program management for Eastern European markets — proposals, pipeline, client relationships, and delivery.
1997 — 2006
Database & Technical Consulting · GE, ITC Infotech, DSQ Software
The technical foundation — Oracle DBA, data center management, and system delivery across India, Mauritius, Hungary, and Japan.
Selected work

Engagements that held up under pressure

M&A · Healthcare

Security integration across 12 acquisitions in one year

Led GDPR-aligned due diligence across 8 business functions and ISO 27001 alignment for 12 newly acquired companies — fully integrated within a single year, without disrupting operations.

SOC · Crisis response

A follow-the-sun SOC, tested by WannaCry

Built a global security operations center from the ground up in Budapest, then led enterprise incident response during the WannaCry ransomware crisis.

Enterprise · 10+ countries

Security governance for 10,000+ users, 10+ EU countries

Owned information security policy, risk, and compliance at enterprise scale — including vulnerability management and disaster recovery testing across multiple markets.

Government · Gulf region

Post-pandemic security hardening for a Gulf government entity

Led the deployment of core security technologies for a Middle East government entity in the immediate aftermath of COVID-19, closing the gaps exposed by an abrupt shift to remote and distributed operations and bringing the environment up to a defensible security standard.

Education & certifications

Still learning, deliberately

Central European University
MS, IT Management
2006 – 2007
University of Madras
Master of Computer Applications
1999 – 2001
Annamalai University
B.Sc., Mathematics
1993 – 1996
FAQ

Frequently asked questions

Do you work on-site or remotely?
Remote only. Every engagement — assessments, policy design, audit prep, RFP and vendor selection — is delivered remotely, and I have run projects across the UAE, Saudi Arabia, Kuwait, Bahrain, and Europe on this model without it limiting depth or responsiveness.
What size organizations do you work with?
The full range — from entrepreneurial startups and founder-led businesses preparing for their first ISO certification, to multinational corporates with 10,000+ users across multiple countries. The framework scales; the fundamentals don't change.
Do you specialize in a particular industry?
My core experience spans FMCG, healthcare, government, and retail, with additional experience in telecom and banking. The governance principles carry across industries even as the risk profile changes.
How long does ISO 27001/42001 audit prep typically take?
It depends on your starting maturity. A focused gap assessment can run four to six weeks; full certification readiness typically spans three to six months.
Can you help with AI governance if we're just starting to adopt AI tools?
Yes — that is often the best time to start, before informal AI use inside the organization creates risk nobody is tracking yet.
Let's talk

Ready to make security an advantage, not an obstacle?

Whether it's an AI governance framework, an ISO audit deadline, or a vendor decision you don't want to get wrong — let's talk about what you need.