Khwaja Naveed Rasheed Cybersecurity GRC · AI Security

Cybersecurity GRC · AI Security · Virtual CISO

Cybersecurity governance,
AI security & assurance

Twenty years building security, risk and AI governance functions for large enterprises across insurance, banking, petrochemicals, energy and telecom. I turn regulatory obligation into assessed, defensible outcomes — and write the books I wanted on my own desk.

  • CISSP
  • CISM
  • CISA
  • CRISC
  • CDPSE
  • PMP
  • PMI-RMP
Khwaja Naveed Rasheed
  • 20+ Years in security, risk and governance
  • 3 Books published on Amazon
  • 500+ Cyber risk assessments and DPIAs directed
  • 30+ Enterprise standards authored

Published on Amazon

Three books, written for the practitioner who has to produce evidence

All books
AI Cybersecurity Governance cover
Second edition

AI Cybersecurity Governance

Standards, Regulation and Assurance for Resilient and Trusted AI Systems

  • 766 pages
  • 616 tables
  • 72 figures
AI Security Strategy cover

AI Security Strategy

The CISO's Operating Manual for Governing, Assuring and Defending Enterprise AI

  • 524 pages
  • 281 tables
  • 27 figures
Cloud Security Strategy cover

Cloud Security Strategy

A Customer-Centric Guide to Managing Risk, Compliance and Zero Trust

  • 397 pages
  • 103 tables
  • 70 figures

Regulatory & standards coverage

The instruments I implement, assess and defend

Saudi and Gulf regulation alongside the international standards that boards and auditors recognise. Implementation record spans every instrument listed here.

The full record

Saudi & regional

  • NCA ECC-2:2024
  • NCA DCC · TCC · CCC · CSCC · OTCC
  • NCA AICG-1:2026
  • SAMA CSF
  • Insurance Authority CSF
  • IA Cybersecurity SAT 2026
  • SDAIA AI Ethics
  • PDPL
  • NDMO
  • CCHI

AI governance & security

  • AI TRiSM
  • ISO/IEC 42001:2023
  • ISO/IEC 23894
  • ISO/IEC 22989
  • NIST AI RMF
  • EU AI Act
  • MITRE ATLAS
  • OWASP LLM Top 10 (2025)

Governance & risk

  • ISO/IEC 27001:2022
  • ISO/IEC 27005
  • NIST CSF
  • NIST RMF
  • COBIT
  • SABSA
  • OCTAVE Allegro
  • STRIDE
  • Three Lines of Defense
  • Zero Trust
  • ISO 22301
  • GDPR

Building an AI governance capability, or preparing for a regulator?

Available for Head of Cybersecurity GRC, Director of Cybersecurity GRC and Virtual CISO mandates with large Saudi and regional enterprises.