Advisory & vCISO
Engagements
Available for Head of Cybersecurity GRC, Director of Cybersecurity GRC and Virtual CISO mandates with large Saudi and regional enterprises. A build-from-zero record in GRC framework, AI governance, privacy and third-party assurance — in each of the sectors below.
What I am engaged to do
Virtual CISO (vCISO)
Interim and fractional security leadership for organisations that need the seniority without the permanent headcount. Board and executive reporting included.
Cybersecurity GRC build-out
Standing up the second line from nothing: operating model, framework, control library, RACI, and the workforce mapping that makes it stick.
AI governance & AI TRiSM
AI inventory, risk assessment method, assurance gating, and the standard that stops a Generative AI deployment reaching production ungoverned.
Regulatory readiness & uplift
NCA, SAMA and Insurance Authority maturity assessment, gap closure sequencing, and preparation for supervisory review.
Regulatory returns & self-assessment
Consolidated multi-regulator filings, the traceability record behind every answer, and the corrective programme that follows.
Third-party & outsourcing assurance
Vendor lifecycle model, security and privacy clauses, concentration and nth-party risk, and pre-contracting regulatory approval.
PDPL & data protection control design
Privacy by Design at scale, DPIA method, cross-border transfer controls, and the classification and retention scheme underneath.
Executive & board advisory
Translating cyber and AI risk into the terms a board actually decides on, including quantification and scenario work.
Sector coverage
- Insurance
- Banking & financial services
- Petrochemicals
- Energy & utilities (IT/OT)
- Telecom
How an engagement usually starts
- A conversation. Twenty minutes on what is actually in front of you — a regulator, a deployment, a gap an auditor found, or a function that needs building.
- A written scope. What I would do, in what order, with what you would hold at the end of it. No engagement begins without this.
- Delivery against evidence. Every workstream produces something assessable: a control set, a filing, a standard, a decision record.