Services
Human-centered security awareness, paired with governance and compliance programs built to withstand audit.
My practice spans both pillars of security relevant to financial-sector organizations: the human element, through security awareness culture programs, phishing simulations, and role-based training that reduce human risk where technology alone falls short.
And the governance element: governance and policy design, risk assessment and third-party risk management, and compliance program management aligned to DORA, NIS2, GDPR and ISO 27001 — built to satisfy regulators and hold up in daily practice too.
Engagements range from focused, one-off projects to ongoing advisory retainers — whichever fits where your organization is right now.

Security Training & Awareness
Technology can't stop every threat. People are often the strongest layer of defense, or the weakest, depending on whether the training actually lands. I build programs that go beyond compliance boxes: grounded in where your organization actually stands today, tailored to real risk profiles, and measured over time so you can see behavior genuinely changing.

Security awareness culture programs
I start with a current-state analysis, then build a program from the ground up — aligned to your company's culture, combining mandatory training with ongoing awareness, and tailored to each team's actual risk profile.

Phishing simulation campaigns
I onboard a platform or work within your existing tooling to build the annual phishing strategy, run the campaigns, and report findings that show real behavior change — not just click-rate numbers.

Role-based
training
Executives, developers, and new hires face different risks and respond to different material. Training is built around each group's actual risk profile rather than a one-size-fits-all module everyone clicks through and forgets.

Cyber and physical security awareness
Human risk doesn't stop at the firewall. I build awareness content covering physical security practices alongside cyber hygiene — the two are usually taught separately, when in reality most real incidents involve both.

Incident response tabletop exercises
A facilitated, scenario-based walkthrough where the right people talk through their actual response, compared against what your plan says should happen. The gap between the two is where the real fixes are.

Awareness maturity metrics & reporting
Every program starts with a clear baseline. From there, I measure progress against it using platform data, turning years of metrics into a picture of behavior change leadership can act on.
Governance, Risk & Compliance
Regulators don't reward good intentions, they reward evidence that your organization actually manages risk day to day. I build and run the governance structures, risk assessments, and compliance programs that hold up under real scrutiny, for the frameworks that matter most to financial-sector organizations right now.

Compliance program management
Building and managing compliance programs against DORA, ISO 27001, GDPR, and PCI DSS — the frameworks that actually apply to financial-sector organizations today, not generic best practice.

Policy & procedure development
Policies and procedures written to be followed, not filed — aligned to how your teams actually operate and to the regulatory frameworks you need to satisfy.

Risk assessments
Regulatory gap analysis and readiness assessments that tell you exactly where you stand against ISO 27001 or NIST CSF, and what needs to close before an external audit does.

ISMS implementation
Reviewing and strengthening an existing ISMS, or building one from scratch aligned to ISO 27001, depending on where your organization is starting from.

Third-party & vendor risk management
Assessing the risk your vendors and outsourcing partners bring into your organization, including full outsourcing risk assessments — a growing regulatory expectation under DORA specifically.