Experience

I am a pragmatic and commercially minded Chief Information Security Officer with experience building and leading security, risk, assurance and resilience capabilities in SaaS environments.

My career began closer to technical delivery and operations, but my work has increasingly focused on judgement: identifying material risk, explaining why it matters, setting proportionate direction and enabling capable people to execute.

Today I work across board and investor engagement, security governance, customer assurance, compliance, resilience, incident leadership and transaction readiness. I am particularly interested in the point where security becomes a business and customer-trust issue rather than simply a technical function.

Current role

As CISO at Preservica, I lead information security, governance, risk and assurance across the company and its SaaS services. My remit includes board-level risk communication, compliance and certification, resilience, customer assurance, incident leadership, due diligence and the commercial trust programme supporting enterprise customers and prospects.

I was promoted from Head of Information Security to CISO, reflecting the expansion of my role from building foundational security capabilities to leading company-wide risk, governance, assurance and resilience.

Alongside security strategy and Board reporting, I have established governance forums covering information security, AI and vulnerability management, rebuilt enterprise risk-management processes, and developed a multi-year security strategy aligned with business growth.

Areas of experience

  • Board and executive risk communication
  • SaaS security strategy
  • Governance and risk management
  • Customer and commercial assurance
  • Incident and vulnerability leadership
  • Business continuity and resilience
  • Data governance and lifecycle risk
  • Transaction and investor due diligence
  • Building and leading lean security functions
  • Security as a customer-trust and revenue enabler
  • Product and technology risk challenge
  • Acquisition diligence and technology integration

Compliance and assurance

My experience spans the design, operation and improvement of assurance programmes including ISO 27001, Cyber Essentials, Cyber Essentials Plus, ISO 9001 and SOC 2 Type II, with additional programme experience involving HIPAA and FedRAMP. I approach standards as tools for strengthening operating discipline and customer confidence, not as substitutes for risk judgement.

I led Preservica’s first ISO 27001 recertification completed with no nonconformities, established its public Trust Center and developed customer-facing assurance materials designed to help security, privacy, legal and commercial stakeholders make informed decisions.

Operational foundations

Earlier in my career, I led global IT operations, enterprise architecture and technical assurance across complex international environments. This included supporting several acquisitions and integrations, managing cloud and workplace-technology transformation, and leading service recovery following a major site disaster.

That operational background continues to shape how I approach security leadership: controls must work in practice, resilience must be demonstrable, and strategic direction must recognise the realities of technology delivery.

Professional credential

Certified Information Security Manager (CISM) credential badge

Certified Information Security Manager (CISM)
Issued by ISACA and maintained through continuing professional education.

Verify this credential on Credly

Microsoft Certified Azure Fundamentals credential badge

Microsoft Certified: Azure Fundamentals
Foundational knowledge of cloud concepts, Azure services, security, governance and management.

Verify this credential on Credly

Leadership philosophy

I believe a senior security leader’s value lies in identifying the material issue, explaining why it matters, setting proportionate direction and enabling capable people to execute.

Security should be rigorous without becoming theatrical, and commercially aware without pretending that every risk can be accepted in pursuit of revenue.