Independent cyber and digital trust diligence for private equity, investment committees and risk advisory firms — pre-acquisition red flags, confirmatory diligence, post-close remediation and exit readiness, across IT, OT, IoT and AI environments.
I advise private equity sponsors, investment committees and risk advisory firms on cybersecurity due diligence, technology risk and AI governance across the transaction lifecycle.
I bring more than thirty years of international executive leadership to that work. Across sixteen security leadership mandates spanning global, group, executive director and advisory remits, several of them above CISO level with the CISO reporting to me, and eighteen major enterprise transformation programmes, I have delivered more than one hundred Board and Audit Committee briefings in over seventy countries — spanning IT, OT, IoT and AI cybersecurity risk, from securing the smart and cognitive city to industrial manufacturing and critical national infrastructure.
My experience combines executive leadership within multinational organisations with consulting expertise gained through Hewlett-Packard, Grant Thornton and Control Risks. I have advised organisations whose combined annual revenues are measured in the trillions of dollars, overseen budgets exceeding US$1bn+ and conducted more than 150 executive cyber maturity, governance and strategic risk assessments, from SMEs to international conglomerates and national governments.
I have operated inside sponsor-backed environments on both sides of the table: Executive Director, Cybersecurity at Systal Technology Solutions, an Inflexion Private Equity-backed platform, and Group CISO at NEOM, backed by Saudi Arabia’s Public Investment Fund. Earlier, as UK Managing Director of DNV (Det Norske Veritas), the Norwegian certification and assurance body — the equivalent of Lloyd’s in its field — with revenues measured in billions of euros, I led a practice of 88 senior consultants conducting maturity assessments and issuing ISO 27001 certifications; I founded and ran the Ascot Barclay Group for fifteen years before its sale via management buyout, and have served as a technology company CEO.
That operating history is the point: it is what allows a finding to be expressed as a cost, a timeline and a decision, rather than a risk rating. I currently serve as Non-Executive Chairman and investor in a Thai functional food business, maintaining an active board seat alongside my advisory practice.
Cyber and digital trust diligence for investment committees and private equity sponsors, pre- and post-acquisition.
Executive roles inside Inflexion Private Equity and Public Investment Fund-backed businesses. Understands the sponsor’s clock and the value-creation plan.
UK Managing Director of DNV (Det Norske Veritas) leading 88 senior consultants issuing ISO 27001 certifications; founder and CEO of Ascot Barclay Group, sold via MBO after fifteen years.
Over one hundred Board and Audit Committee briefings across organisations in more than seventy countries.
From sovereign-scale programmes to industrial crisis recovery, with zero material breaches across all tenures.
UK CISO of the Year 2020 · UK Cyber Security Hall of Fame · Nominated Global C|CISO of the Year (Finalist) · Author, CISO: Defenders of the Cyber Realm, Cyber Book of the Year.
Engagements are structured around the pace of the transaction and sized to the mandate — from a five-day red flag screen to a full post-close remediation programme. Delivered on-site or remotely across Asia, Europe and the Middle East.
Rapid outside-in read on a target before terms are set.
Findings quantified in terms an investment committee can price.
Turning diligence findings into a de-risked asset.
A cyber narrative that survives buyer-side scrutiny.
Sixteen security leadership mandates, several above CISO level, including greenfield builds at sovereign scale. Remediation estimates come from having run the programmes, not from a benchmark table.
Over one hundred Board and Audit Committee briefings. Findings arrive as value at risk, cost to remediate and time to defensible — in language investment committees already use.
IT, OT, IoT, ICS and AI. Industrial manufacturing, critical national infrastructure, energy, pharma, 5G and the smart and cognitive city — where the un-priced risk usually hides.
Five major cyber recovery programmes, including a breach that halted production and threatened insolvency, restored to full capability in six months. I know which findings are genuinely existential.
No product to sell, no managed service to upsell, no downstream remediation contract to protect. The recommendation is the deliverable.
Comfortable in front of a Board, an investment committee or a target’s management team — including the difficult conversation where the finding changes the price.
I am not the right fit if you need a twenty-person team on day one, audit sign-off, or a commodity compliance assessment. Where the requirement is senior oversight of that work, that is a different conversation. My work is concentrated on complex transactions where experienced judgement informs the investment decision.
A significant cyber breach halted production and placed the business at risk of insolvency.
Retained through a leading risk consultancy as independent crisis lead; directed containment, Board-level crisis communications and the rebuild of compromised OT and IT infrastructure.
Full operational capability restored within six months, with sustainable controls embedded and enterprise value preserved.
A £150m private equity-backed platform required enterprise-grade security capability to compete for global clients.
Built a 54-strong cybersecurity function from a blank canvas within six months, spanning IT/OT security, SecOps, CSIRT and Zero Trust services across more than thirty-five countries.
Won and delivered Board-level security mandates for Fortune 500 and financial institutions aligned to DORA, directly supporting the platform’s growth thesis.
A national German banking transformation programme, with an opening contract value exceeding US$1bn+, carried security-critical delivery risk.
Strategic cybersecurity and CISO advisor, shaping the security workstream and executive risk position, working with the client-side CISO to shape the tender and deliverables.
Delivered the firm’s largest cybersecurity refresh for a major European bank, protecting programme value and client confidence.
A sovereign wholesale 5G programme required independent cyber assurance over the selection of its sole network equipment provider.
Advised alongside a large European telco team on the cybersecurity dimension of the vendor selection process, assessing supply chain, national security and operational risk.
A defensible, evidence-based vendor decision for critical national telecommunications infrastructure.
A redacted investment committee summary, cyber risk heat map and worked remediation costing, taken from a live-format confirmatory diligence.
The environments behind the diligence — each one an estate I have operated, secured or recovered rather than only reviewed.
“Presenting awareness of and interest in cybersecurity is a priority for the Bank, and your presentation really helped bring together some difficult to communicate concepts about the threat. The tips on recognising social engineering were especially applicable to staff here. The pitch, content and tempo were spot on — not an easy thing to get right.”
“Balanced technical authority with the commercial instincts of an entrepreneurial dealmaker. Boards trust him because he tells them what matters and what it costs.”
“At sovereign scale, with everything at stake, Mike built from nothing a cybersecurity capability that gave leadership and investors genuine confidence.”
“One of the very few security leaders who can hold the attention of a Board and the respect of an engineering team in the same meeting.”
“I worked with Mike when he was the Company Secretary and Director for the ISSA. Great guy, very dependable and organised. Has a quiet steel about him, gets things done, and with a host of contacts. Recommend.”
As Co-Founder and Executive Director of the Cybersecurity & AI Governance Initiative (CAGI), a global not-for-profit membership body, I convene Board-level and practitioner audiences on emerging cyber and AI risk, anchoring my advisory work to recognised frameworks.
A twelve-part series for deal teams and investment committees, written from practice over thirty years rather than from research. The introduction and the first two papers are available now; the remaining ten are in preparation and can be requested.
What the series covers, who it is written for, and the practitioner basis it is written from. Two pages.
Why the scope matters more than the findings. Includes a worked example taking one finding through to a priced deal term, and six questions to ask before accepting a scope.
Why the quality of the report is often the wrong question. Covers the illusion of completeness, technical severity against commercial materiality, and what maturity scores do not tell you.
To receive additional titles in this series, click here to send me an email request.
The award-winning book that opens up the world of the Chief Information Security Officer — the unseen individuals keeping the lights on, the banks open and food on the shelves. With a foreword by Vint Cerf, widely regarded as a father of the internet.
Flexible commercial terms, engaged directly or through advisory, risk and consulting firms.
“Cybersecurity is no longer simply a technology issue. Coupled to AI, it is a determinant of enterprise value, investment confidence and organisational resilience.”
Available for cybersecurity due diligence, technology risk and AI governance mandates worldwide — engaged directly or through advisory and risk consulting firms.