I help leadership teams turn regulatory pressure into operating clarity.
My practice combines the technical depth of a CISO with the legal literacy of a Data Protection Officer. The objective is rarely "more compliance" — it is a programme that holds up to inspection, scales with the business, and stops consuming disproportionate executive attention.
Before establishing this independent practice, I led the global information security governance, risk and compliance function and served as Privacy Officer for Atlas Copco, a multinational industrial group. That work spanned EU, UK and US regulatory landscapes, M&A integration, regulator engagement and the design of governance structures intended to outlast their architects.
Today I work with a small number of medium-to-large clients at any one time. Engagements are senior, hands-on and oriented around decisions that need to be defensible — to a board, an auditor or a supervisory authority.