credentials.
The record a board needs to vet me — appointments, executive career and qualifications, in plain English and with no email wall. Three decades in cyber security, a decade of it at executive and non-executive level. Where an acronym would slow a non-technical director down, I've explained what it actually means.
Board-level cyber security executive with three decades of experience and a deep portfolio of non-executive and advisory work. CEO of UK Cyber Defence — the firm I founded as Hedgehog Security in 2009 and rebranded in 2025 — with a growing focus on governance and advisory. I hold two non-executive-style seats at CREST, the industry's accreditation body, shaping standards and regulatory engagement across Europe.
In one line for a nomination committee: an operator who has run the security function, built and led the company, sat on the accrediting body, and can hold a board's cyber, IT and AI risk to account in language the whole board understands.
Governance seats, and what each one is.
CREST is the international not-for-profit that accredits and certifies the technical cyber security industry — the standard governments and enterprises rely on when they buy penetration testing or incident response. A seat on its councils is a governance role, not a membership badge.
CREST — European Council · Council Member (non-executive)
A non-executive seat on CREST's European Council. I help shape strategy, standards and codes of conduct for technical security testing and accreditation across Europe.
what it means · a board-level policy seat at the body that sets the rules for the industry I operate in.
CREST — Advisory Board for Incident Response, Pan Europe (non-executive)
A non-executive seat on CREST's pan-European Advisory Board for Incident Response. I advise on strategic direction and accreditation frameworks for cyber incident-response services, and on engagement with regulators, national CERTs and law enforcement.
what it means · oversight of how incident response is held to a standard across borders — the discipline a board most needs when the worst day arrives.
The Dove Service — Trustee (non-executive)
Trustee on the board of a UK bereavement-counselling charity, providing board-level data-protection and cyber-security oversight (ISO 27001, Cyber Essentials, PCI-DSS).
what it means · a full non-executive trustee role — fiduciary duty, board papers, the lot — in the third sector.
Microsoft UK — European CISO Council · Council Member
Invited member of Microsoft UK's European CISO Council, chaired by Edward Gibson, then Chief Security Officer of Microsoft UK. A peer forum for senior European Chief Information Security Officers on the threats then emerging.
what it means · a seat among the most senior security leaders in Europe, by invitation.
Where the operating judgement comes from.
A NED's value is the executive experience behind the questions. Mine runs from a national-security start, through a FTSE-scale CISO role, to founding and running a cyber firm for over fifteen years.
UK Cyber Defence (founded as Hedgehog Security) · Founder & Chief Executive Officer
Founded Hedgehog Security in 2009 and built it into an internationally recognised, CREST-accredited testing and incident-response firm, with clients including Microsoft, Tesla, Virgin Atlantic and Tokio Millennium Re. Rebranded the firm as UK Cyber Defence in 2025. Board-level accountability for strategy, financial performance and regulatory compliance (ISO/IEC 27001, 9001, 14001, 22301, PCI-DSS, CREST); founded a veteran-to-cyber transition pathway.
Gala Coral Group · Chief Information Security Officer
CISO of one of Europe's largest privately-held gaming groups — £4.5bn turnover, £1.25m annual security budget. Group-wide responsibility for information risk, security strategy and architecture, and the PCI-DSS programme.
what it means · executive accountability for security at genuine scale, reporting to the top of the business.
HM Government · Officer, latterly reservist
Full-time officer at governmental level (1996–2003), latterly reservist (2003–2006). Operations and technical work across the electromagnetic spectrum — signals, electronic warfare, communications security, and the integration of early computer-based capability.
what it means · a decade of high-consequence security work before "cyber" was a word boards used.
The letters, decoded.
Kept current, and explained — because a credential a board can't interpret is a credential wasted.
| MSc Cyber Security | A master's degree in the field itself. |
| FBCS · Chartered IT Professional | Fellow of BCS, The Chartered Institute for IT — the profession's senior grade — with Chartered IT Professional status (2011). |
| CISSP | Certified Information Systems Security Professional (ISC²) — the benchmark senior information-security certification (2007). |
| CISA | Certified Information Systems Auditor (ISACA) — the audit-and-assurance credential (2007). |
| OSCP · CREST RT | Offensive Security Certified Professional and CREST Registered Tester — hands-on offensive-security qualifications (2015). The board wants a director who understands how attacks actually work. |
| SANS GIAC (CFA, CPT) | GIAC certifications in forensic analysis and penetration testing (2005). |
The rest of the picture.
A board is hiring a person, not a certificate list.
SC Magazine — Information Security Person of the Year (runner-up)
Recognised by the industry's leading publication, among the security professionals of the year.
Volunteer leadership
Group Scout Leader, 2nd Cheadle (2015–2019). RNLI lifeboat crew, Mersea Island, Atlantic-class lifeboats (2002–2007). The habit of taking responsibility when something is going wrong is not confined to the day job.
Need more than a web page?
The one-page board CV is here to download. The full, detailed CV is on the gated CV page — enter a work email, get a code, no sales follow-up. Or just write, and tell me what the board is weighing.