I advise leadership teams across industries on the full arc of cyber risk — strategy, technology investment, audit readiness, and vendor selection — and design the governance models that keep the AI systems inside their organizations accountable. The result: cost-effective programs built to withstand real scrutiny, not just pass a checklist.
Over 28 years in technology, the last 15 in dedicated cybersecurity leadership, I have built a career spanning the technical, commercial, and strategic dimensions of the field — beginning as an Oracle database administrator and advancing through presales, program management, IT operations, and, since 2013, executive cybersecurity strategy. I have led security and governance functions across the UAE, Saudi Arabia, Kuwait, Bahrain, Mauritius, South Korea, Europe, and the USA, for organizations ranging from entrepreneurial startups to multinational corporates — across FMCG, healthcare, government, and retail, with additional experience in telecom and banking.
My deepest specialization is the Gulf — the UAE, Saudi Arabia, Kuwait, and Bahrain — where cybersecurity and data protection expectations differ sharply from market to market. I have spent years on the ground there, in business development and delivery alike, and I build programs that respect those local requirements rather than applying a single template everywhere.
Today, I advise executive committees on AI governance and ISO 27001/42001 audit readiness, lead large-scale cyber drill and exercise programs, and guide organizations through the RFP and vendor-selection process — ensuring the technology they invest in actually strengthens their security posture.
I have limited patience for buzzwords and a firm commitment to outcomes. Every policy, process, and program I design is built to withstand audit, pressure, and real-world attack alike.
AI governance frameworks aligned to ISO/IEC 42001, responsible-AI policy design, and risk assessments before your regulator or customer asks for one.
Lead Auditor-led gap assessments, documentation, and remediation plans that get organizations through certification audits the first time.
The full policy backbone — information security, incident response, business continuity, disaster recovery, and vendor risk — built to actually be followed.
Independent, vendor-neutral guidance on security tooling and OT/IT convergence — decisions based on your risk, not a vendor's roadmap.
I write RFPs that ask the right questions, score incoming proposals objectively, and help you choose the vendor that will actually deliver.
End-to-end delivery of cyber drills, SOC builds, and cross-border security programs — on time, on budget, on message with the board.
Map the business context first — compliance obligations, threat profile, and where confidentiality, integrity, and availability actually matter most to your operations.
Architect the governance framework, security program, or vendor strategy suited to that specific risk profile, industry, and regulatory footprint — not a generic template.
Roll out the solution end to end — documentation, stakeholder coordination, technology deployment, and execution against a clear timeline.
Support ongoing governance, review cycles, and course correction so the program holds up under real-world pressure, not just on delivery day.
Ballpark figures, benchmarked against current market rates for senior, credentialed independent consultants — your actual quote depends on organization size, industry, number of entities or locations, and specific scope.
Led GDPR-aligned due diligence across 8 business functions and ISO 27001 alignment for 12 newly acquired companies — fully integrated within a single year, without disrupting operations.
Built a global security operations center from the ground up in Budapest, then led enterprise incident response during the WannaCry ransomware crisis.
Owned information security policy, risk, and compliance at enterprise scale — including vulnerability management and disaster recovery testing across multiple markets.
Led the deployment of core security technologies for a Middle East government entity in the immediate aftermath of COVID-19, closing the gaps exposed by an abrupt shift to remote and distributed operations and bringing the environment up to a defensible security standard.
Whether it's an AI governance framework, an ISO audit deadline, or a vendor decision you don't want to get wrong — let's talk about what you need.