Khwaja Naveed Rasheed Cybersecurity GRC · AI Security

Advisory & vCISO

Engagements

Available for Head of Cybersecurity GRC, Director of Cybersecurity GRC and Virtual CISO mandates with large Saudi and regional enterprises. A build-from-zero record in GRC framework, AI governance, privacy and third-party assurance — in each of the sectors below.

What I am engaged to do

01

Virtual CISO (vCISO)

Interim and fractional security leadership for organisations that need the seniority without the permanent headcount. Board and executive reporting included.

02

Cybersecurity GRC build-out

Standing up the second line from nothing: operating model, framework, control library, RACI, and the workforce mapping that makes it stick.

03

AI governance & AI TRiSM

AI inventory, risk assessment method, assurance gating, and the standard that stops a Generative AI deployment reaching production ungoverned.

04

Regulatory readiness & uplift

NCA, SAMA and Insurance Authority maturity assessment, gap closure sequencing, and preparation for supervisory review.

05

Regulatory returns & self-assessment

Consolidated multi-regulator filings, the traceability record behind every answer, and the corrective programme that follows.

06

Third-party & outsourcing assurance

Vendor lifecycle model, security and privacy clauses, concentration and nth-party risk, and pre-contracting regulatory approval.

07

PDPL & data protection control design

Privacy by Design at scale, DPIA method, cross-border transfer controls, and the classification and retention scheme underneath.

08

Executive & board advisory

Translating cyber and AI risk into the terms a board actually decides on, including quantification and scenario work.

Sector coverage

  • Insurance
  • Banking & financial services
  • Petrochemicals
  • Energy & utilities (IT/OT)
  • Telecom

How an engagement usually starts

  1. A conversation. Twenty minutes on what is actually in front of you — a regulator, a deployment, a gap an auditor found, or a function that needs building.
  2. A written scope. What I would do, in what order, with what you would hold at the end of it. No engagement begins without this.
  3. Delivery against evidence. Every workstream produces something assessable: a control set, a filing, a standard, a decision record.
kn@khnaveed.com