Expertise
Clarity, control, outcomes
I bring board-level clarity, rebuild operational control, and leave you measurably safer than before.
Enterprise Risk & Digital Trust
I enable boards and executives to make defensible decisions where digital, regulatory, and operational risk threaten enterprise value.
- Define enterprise risk posture, appetite, and tolerance across digital and operational risk;
- Integrate cyber, privacy, AI, and regulatory exposure into a unified risk model;
- Translate technical, legal, and operational exposure into decision-ready risk positions;
- Direct material risk, liability exposure, trade-offs, prioritisation, and acceptance;
- Frame decisions impacting enterprise value, capital allocation, and investor confidence;
- Direct decisions under incident, investigation, and external scrutiny;
- Govern alignment with EU digital regulation and engage authorities on risk posture;
- Provide challenge and escalate across risk, control, and governance functions.
Domain knowledge
Enterprise risk governance; digital and systemic risk integration; liability exposure; EU digital regulation; supervisory engagement; risk prioritisation and defensible risk acceptance.
Cybersecurity & Resilience
I provide security leadership that enables informed risk decisions, defensible assurance, operational resilience, and sustained trust.
- Define cybersecurity strategy aligned with enterprise risk, resilience, and continuity;
- Govern control environment to withstand audit, regulatory, and external scrutiny;
- Own risk posture, guiding acceptance, trade-offs, and liability exposure;
- Prioritise protection of critical assets, intellectual property, and sensitive data;
- Control third-party risk across critical suppliers and external dependencies;
- Direct crisis response, containment, and communication under operational pressure;
- Prove control effectiveness through measurable assurance and audit evidence;
- Reduce systemic exposure across systems, processes, and operational environments;
- Shape leadership decisions on resilience, assurance, security risk, and continuity.
Domain knowledge
Cybersecurity governance and assurance; operational resilience; crisis leadership; control framework integration; EU digital and sectoral regulation; critical asset protection.
Privacy & Data Protection
I lead privacy and data protection governance to ensure lawful, defensible, and accountable use of personal data.
- Define data protection strategy aligned with regulatory and liability exposure;
- Authorise high-risk processing, balancing data use, regulatory constraints, and liability;
- Govern privacy risk across data use, access, sharing, retention, and exposure;
- Control cross-border data transfers and third-party processing across jurisdictions;
- Engage supervisory authorities on regulatory posture and data protection approach;
- Direct breach response and notification to regulators and data subjects under scrutiny;
- Embed data protection into organisational processes, controls, and decision-making;
- Challenge and escalate decisions on privacy, AI, and data governance.
Domain knowledge
Data protection governance; GDPR and EU data law; cross-border data strategy; data subject rights enforcement; supervisory engagement; AI governance; liability exposure.
Why work with me
15+ years of delivery under pressure
I’m brought in when the cost of being wrong is high, whether legally, operationally, or reputationally.
I bring nearly two decades of senior experience across cybersecurity, data protection, security engineering, and regulatory compliance. My hybrid expertise is rooted in execution, not just theory. I’ve secured regulatory approvals, strengthened resilience through certified management systems, cut liability and risk exposure, and led organisations through audits and investor due diligence. I don’t just advise; I architect, implement, and deliver. I know what works and what wastes time.
-
Deep hands-on expertise Hard-won knowledge of what actually works.
-
Fluency across domains Connecting business, legal, and engineering.
-
Execution that builds resilience Strengthened trust and reduced risk.
-
Independent and discreet A neutral partner who cuts through politics.
-
Capability transfer I upskill your people, not replace them.
-
No guesswork Evidence-driven decisions, not assumptions.
-
No one-size-fits-all Solutions tailored to your risk reality.
-
No lock-in Autonomy delivered, dependency avoided.
-
No paper compliance Controls that function in practice.
-
No fear tactics I bring facts, clarity, and assurance.
Who I work with
Organisations needing clarity and assurance
If you need senior expertise across strategic, legal, and technical domains—you’re in the right place.
-
Boards & Executives
Discreet advisory, risk oversight, governance, and leadership balancing strategy with hands-on execution.
-
Legal & Compliance
TOMs, DPAs, cross-border transfers, M&A due diligence, and AI governance—made practical and defensible.
-
IT & Engineering
Secure architecture, DevSecOps, cloud resilience, and vulnerability triage embedded into delivery.
-
Start-ups & Scale-ups
Audit-readiness, certifications, M&A preparation, and investor due diligence, building trust at every growth stage.
-
Regulated Industries
Protecting high-risk and high-sensitivity data in finance, health, and other sectors under heavy scrutiny.
-
SaaS Providers
Designing multi-tenant platforms that scale securely, comply globally, and earn lasting customer trust.
FAQ
Straight answers
I lead with transparency so you can make informed decisions, not just comforting ones.
What differentiates you from a full-time employee?
When you hire me, you’re not onboarding someone who needs training, hand-holding, or months to get up to speed. You’re getting nearly two decades of hard-won experience across security, privacy, engineering, and legal domains. I ask the right questions, extract what matters, and get to work. You get outcomes, not overhead.
Unlike full-time hires, I’m not caught up in office politics or role preservation. I bring clarity, challenge assumptions, and lead with transparency. You get facts, not theatre. I’ve seen how internal politics and noise can obscure risk, slow progress, and distort reality. I cut through that with facts and focus. No employer risk. No hidden agenda. Just discreet, senior execution, where and when you need it.
How do your engagements typically work?
Flexible, independent, and outcome-driven.
Some clients retain me on a monthly basis for strategic oversight, risk advisory, or interim leadership. Others bring me in for tightly scoped projects, such as DPIAs, vendor assessments, internal ISO/IEC 27001 audits, or high-pressure remediation projects after incidents.
Scope, deliverables, and check-ins are defined up front—for focus, clarity, and accountability. I’m flexible, but lead decisively to protect outcomes and budgets. I’ve seen how some consultants inflate hours or let projects drift. That’s where I’m different: I keep scope tight, delivery sharp, and outcomes accountable.
I work independently on my own secured devices and drive execution while collaborating through your preferred tools, whether that’s email, Teams, Slack, or something else. This keeps things practical, efficient, and compliant with the Dutch Wet DBA—ensuring a clear, professional, and truly independent working relationship.
Are you hands-on, or do you just advise?
Both. Most assignments require a mix of strategic input and hands-on execution to deliver real results. I’ve seen teams left with abstract frameworks or stuck with vague recommendations that never land in practice. That’s not me. I make sure strategy translates into action, delivers outcomes, and holds up under scrutiny.
When you’re short on time, under pressure, or hitting roadblocks, I step in and help. Whether that means building registers, writing policies, conducting assessments, negotiating contracts, or managing crises, I roll up my sleeves and get it done. However, my goal isn’t to create dependence. Ultimately, I embed practices and transfer capabilities, leaving you stronger and more resilient than before.
What industries do you have experience in?
While I’m sector-agnostic, I’ve supported clients across e-commerce, healthcare, fintech, education, digital media, and government—handling regulated data, sensitive workloads, and critical systems.
I’ve worked across high-risk environments and apply proven methods tailored to your risk, regulatory obligations, and growth stage. I know what regulators expect, what partners and clients demand, and what investors scrutinise most. I’m also keenly aware of conflicting risk appetites and interests, particularly in commercial environments.
How do you handle sensitive or confidential work?
Trust and discretion underpin everything I do. I routinely operate under NDA. If required, we can extend confidentiality to cover the fact of our engagement. You can expect strict independence, secure working practices, and absolute protection of sensitive information.
I’ve supported clients through regulatory investigations, breach response, and other situations where discretion was critical to survival. My role extends beyond safeguarding intellectual property, personal data, systems, and compliance posture: it’s also about protecting your reputation and trust.
Do you also perform internal ISO/IEC 27K audits?
Yes, I conduct independent, standards-based assessments in line with ISO 19011 across ISO/IEC 27001, 27701, 27017, 27018, and Dutch BIO2 and NEN 7510. Provided I haven’t designed the controls or processes being audited, of course.
As a Certified Information Systems Auditor (CISA) and a Certified ISO/IEC 27001 and 27701 Lead Implementer, I help clients strengthen posture, prepare for certification, and meet internal assurance goals without conflict of interest.
Case studies
Proven outcomes
I’ve led high-stakes engagements where discretion was essential and the stakes were regulatory, financial, and reputational. While most of my work is under NDA, these examples highlight the outcomes I deliver.
Pricing
Responsibility priced accordingly
My work reflects a lifelong commitment to protecting people, systems, and data.
My services are tailored, not templated. Whether you need ongoing leadership, targeted delivery, or flexible access to expertise, we will structure our engagement to meet your specific needs.
-
Retainer model
Fixed hours per month · Ongoing strategic and operational support. From acting as your vCISO, vCPO, or vDPO, to leading risk management, advising teams, or handling sensitive issues as they arise.
-
Project-based
Fixed scope, defined outcomes · Scoped initiatives with clear goals. Including audits, DPIAs, security reviews, TOMs analysis, OSINT & vulnerability reports, as well as ISO/IEC 27001 preparation.
-
Prepaid model
Prepaid hours, flexible use · Expertise on call without the monthly commitment. Buy a package of hours and use them as needed. For reviews, second opinions, or other quick interventions.
-
Interim placement
On-demand interim coverage · For short-term placement or urgent assignments. When you need a CISO, CPO, or technical expert to step in quickly and focus on restoring clarity and control.
Contact
Straight answers, no sales pitch
Whether you’re scaling, raising funding, preparing for certification, facing regulatory scrutiny, or simply stuck, I help you get the controls and confidence you need.
Need clarity and hands-on expertise?
I’m currently limited in availability to take on new assignments. However, I’m always happy to connect and explore how I can assist at a later time.
Connect on LinkedIn