I have worked as a cybersecurity practitioner and Threat-Informed Defence (TID) specialist with over 20 years of experience across IT infrastructure, cloud architecture, and enterprise security programmes. I have also specialised at the intersection of governance, architecture, and operational security, helping organisations move from reactive compliance to proactive, intelligence-led defence. I have developed and implemented security programmes aligned with international standards such as ISO 27001, NIST 800-53, CIS Controls, and OWASP, and have guided multiple organisations through PCI DSS certification and regulatory alignment initiatives.
My expertise spans cyber hygiene and awareness, security programme development, data centre security, cloud security architecture, zero trust roadmapping, exposure management, and secure by design/secure by default oversight. I currently specialise in Threat-Informed Defence principles, integrating cyber threat intelligence, adversary emulation concepts, and control validation methodologies (such as MITRE ATT&CK mapping) to help organisations understand how real-world threat actors operate and how to measure defensive effectiveness against them.
In my spare time, I advocate and evangelise the importance of cyber knowledge sharing and mentoring, and find time to play pickleball.