Back to home
CISO

Chief Information Security Officer

Security the business can move at: measured detection, fast remediation, and certifications passed on the first audit.

I came up through the technical side of security: penetration testing and IAM at KPMG, standing up the first security program at a global SaaS travel provider, running threat and vulnerability management for one of the largest payment processors in the world, then a year inside a bank's IT audit function seeing how controls actually get tested. That path leaves you with little patience for security theater. A control that cannot be measured is a hope.

As CIO I owned security outright, which is the cleanest way to learn what a CISO needs from the rest of the organization. We built a secure digital core across cloud, network, data, and platform, cut mean time to detect by 75% and mean time to respond by 60%, brought average vulnerability age from 45 days to 12, and took ISO 27001, HITRUST, HIPAA, GDPR, and Cyber Essentials through certification on the first audit with zero critical findings. Those certifications opened more than a billion dollars of revenue. Security done well is a growth function.

What I have done

Cinch: a production collaboration platform built on evidence, not demos

Independent · 2025 to present

A multi-tenant Slack alternative in production at cinchme.app, with tenant isolation proven in the database, a browser suite run against the production image, and a release gate that refuses to promote traffic without evidence.

2,566
Unit and integration tests
92
Browser scenarios against the production image

Five certifications, first audit, zero critical findings

North Highland · 2014 to 2026

A risk and compliance program aligned to ISO 27001, HITRUST, HIPAA, GDPR, and UK Cyber Essentials that certified on the first pass and opened more than a billion dollars of revenue.

5
Standards certified on the first audit
0
Critical findings

Building the secure digital core

North Highland · 2014 to 2026

A global security foundation spanning cloud, network, data, and platform that cut mean time to detect by 75%, mean time to respond by 60%, and average vulnerability age from 45 days to 12.

75%
Reduction in mean time to detect
60%
Reduction in mean time to respond

Standing up a first security program for a global SaaS provider

TRX · 2008 to 2012

Established the first information security program at a SaaS travel-technology company, including PCI-DSS and NIST SP 800-53 compliance and an enterprise threat and vulnerability management program.

From zero
Security program established
PCI-DSS, NIST 800-53
Compliance maintained

Proof

75%
Reduction in mean time to detect
45 to 12
Days of average vulnerability age
99%
Critical patch compliance
0
Critical findings across five first-pass certifications
$1B+
Revenue enabled by compliance certifications

Writing

  • Rebuilding the SOC for an AI-Speed Adversary

    Attackers compressed breakout time to minutes and deleted the cost of expertise. You cannot defend a machine-speed adversary at human speed.

  • Shrinking the Blast Radius

    You cannot guarantee a breach will not happen. You can decide how much it costs when it does. Encryption, tokenization, and minimization are blast-radius controls, not prevention controls.

Tools and frameworks

  • ISO 27001
  • HITRUST
  • HIPAA
  • GDPR
  • PCI-DSS
  • SOC 2
  • NIST SP 800-53
  • UK Cyber Essentials
  • Threat and vulnerability management
  • Security operations and incident response
  • IT audit and SOX controls
  • Penetration testing and IAM