work.
One board seat at a time, taken seriously. A Non-Executive Director who still reads the logs — cyber security, information security, IT and AI oversight from someone who has actually operated all four. Full board appointment, a standing advisory seat, a retainer, or a scoped piece of work — chosen to fit what the board actually needs.
Four ways to put an operator in the room.
Not every board needs a full directorship, and not every problem needs a permanent seat. These are the shapes the work takes — from a formal NED appointment down to a few scoped days. Each one is the same person: an operator who has carried the pager, not a slide-deck advisor.
Non-Executive Director
Board Cyber Advisor
Strategic Advisory Retainer
Programme & project advisory
Three specialisms the board can interrogate.
Most boards get their cyber oversight second-hand — a slide from the CISO, a paragraph from the auditors. An operator in a non-executive or advisory seat gets it first-hand, in plain English, with the follow-up questions asked before the meeting rather than after the incident.
Cyber & information security
Security posture the board can interrogate: what the risk register should say, what the CISO's report leaves out, what an incident will demand of directors — and whether the recovery plan survives contact with an actual Tuesday-morning breach.
IT & technology
Technology oversight from someone who still builds: whether the platform bet is sound, whether the resilience claims are tested or theatrical, and whether the IT budget is buying risk reduction or shelfware.
AI governance
The newest line on the risk register. Where AI genuinely helps the business, where it quietly leaks its data, and what the board must be able to evidence — UK GDPR, the EU AI Act where it reaches, and the questions insurers have started asking.
What I bring to a boardroom is the combination: 29 years as a practitioner, a decade at executive level, current CREST European Council and IR Pan Europe seats, and a working knowledge of what regulators, insurers and incident rooms actually ask for. I can challenge an executive's security narrative because I have written those narratives — and occasionally had them fall apart under a real attack. For boards weighing what the role actually demands, I have written it up plainly in the writing for boards.
Where the judgement was earned.
Thirty years of it, at board and executive level, across sectors where getting security wrong has consequences. A selection — the full record is on the credentials page.
Chief Information Security Officer of one of Europe's largest privately-held gaming groups — £4.5bn turnover, group-wide information risk, security strategy and architecture, and the PCI-DSS programme. Board- and executive-level accountability at scale.
Invited member of Microsoft UK's European CISO Council, chaired by Edward Gibson, then CSO of Microsoft UK — a peer forum for senior European CISOs on the threats then emerging. Governance among peers, not vendors.
Built a CREST-accredited testing and incident-response firm recognised internationally, with clients including Microsoft, Tesla, Virgin Atlantic and Tokio Millennium Re. Full board accountability for strategy, finance and regulatory compliance (ISO 27001, PCI-DSS, CREST).
Two non-executive seats on the body that accredits much of the industry: shaping standards, codes of conduct and accreditation frameworks, and engaging with regulators, national CERTs and law enforcement across Europe.
Non-executive trustee of a UK bereavement-counselling charity, providing board-level data-protection and cyber-security oversight (ISO 27001, Cyber Essentials, PCI-DSS). Governance in the third sector, where the stakes are personal.
Where it started: officer-level operations and technical work across the electromagnetic spectrum — signals, electronic warfare, communications security, and the integration of early computer-based capability. Ten years before "cyber" was a boardroom word.
On specifics: named clients are those already a matter of public record. Current and recent engagements are covered by confidentiality and discussed only under NDA — as any board would expect of the person they are vetting.
Endorsements you can verify.
Attributed, linked to the people who said them, and trimmed only for length — never for meaning. An endorsement you can't verify is just copy.
"I so enjoyed Peter as a member of my Chief Information Security Officer Council at Microsoft Ltd UK. He always provided a unique insight into IT security issues of import to many global companies who were also members. A respected and senior member of the IT community, Peter stands out as honorable and the person you would want on your side."
"Peter is a rare breed of individuals who (like me) have a unique combination of heavy technical skills coupled with excellent managerial and other soft skills that make him a prize for any company. The brief time I worked with Peter was great fun. He is very practical but does not give in to any argument if he knows he is in the right. Brilliant person. Highly Recommended."
"Met Peter at an event where he was the guest speaker at a hacking workshop. I knew from that moment I would work with him on many projects going forward. What Peter didn't know about gaining access to an organisation's 'crown jewels' wasn't worth knowing. … A trusted partner and advisor whom I'd have no problem recommending to people who need to protect valuable data within their organisation."
Further board and client references available on request.
Start the conversation.
For NED and advisory-board approaches: the sector, the board's shape, and what has prompted the search. For a retainer or a scoped piece: the situation and rough timescale. The full record is on the credentials page; a one-page board CV is there to download, and the detailed CV is on the gated CV page.
→ back to home · credentials · writing for boards · ai security starter kit