About

I’m a cyber security leader with more than 25 years of experience delivering security and resilience outcomes across insurance, financial services, telecommunications, and critical infrastructure.

I specialise in leading cyber uplift programmes — particularly in organisations starting from a low or uneven maturity baseline, or facing regulatory pressure, audit findings, or heightened risk exposure.

Several times throughout my career, I’ve walked into organisations with little or no existing security capability and built it from the ground up — establishing the operating model, governance, technology stack, and delivery roadmap required to create a function a Board and regulator can rely on.

Most recently, as General Manager of Information Security for a New Zealand life insurer regulated by the Reserve Bank and Financial Markets Authority, I grew the security function from a team of one into a fully resourced capability with 24/7 security operations. During that time:

  • Detection times reduced by more than 80%
  • Critical vulnerabilities reduced by over 90%
  • A risk-based investment programme established and embedded at executive level

Earlier in my career, I have:

  • Built enterprise security strategy and ISO 27001-aligned control frameworks for a major telecommunications provider following corporate separation
  • Led governance and capability uplift programmes for insurers starting from low maturity baselines
  • Delivered NZISM certification for a regulated cloud transformation
  • Designed Board-level risk reporting for an APRA CPS 234 remediation programme at a New Zealand bank under Australian regulatory oversight

My work typically sits at the intersection of strategy, execution, and assurance — translating technical risk into clear, actionable decisions for Boards, regulators, and executive teams.

Most of my career has been in complex, multi-vendor and outsourced environments, where delivery depends on aligning internal teams, service providers, and technology partners around a coherent programme of work.

I’ve also acted as the executive escalation point for major security incidents, with a focus on operational resilience, incident response, and recovery capability.

Before moving into security leadership, I spent close to a decade in operational technology roles, including running data centre and network operations for a regulated bank and leading a distributed team of 18 engineers across the UK, Germany and Brazil with full P&L accountability. This operational grounding continues to inform how I design and deliver security programmes today.

Alongside an early career in banking technology, I co-founded an ISP in South Africa in 1997, building its core infrastructure from scratch — WAN, email, DNS, and hosting. The business was profitable within nine months and remains in operation today.

Based in Auckland, New Zealand, I work with organisations across New Zealand and Australia on contract and advisory engagements.

Credentials: CISM (held), ITIL v3 Foundation, PCI DSS QSA (former), Cisco CCDA & CCNA, Checkpoint CCSA Firewall-1