Independent Consultant

Turning cyber risk into financial certainty

I help organisations make smarter security investment decisions by quantifying cyber risk in dollar terms — using actuarial models grounded in the Open FAIR standard.

Start a conversation About me →
£M+
Risk quantified per engagement
FAIR
Open FAIR certified methodology
C-suite
Board-ready risk reporting
ROI
Prioritise controls by return

What I do

Services

Combining strategic advisory with technical rigour — so risk conversations happen in the language of business, not just technology.

Cyber Risk Quantification

Monte Carlo actuarial models using Open FAIR translate your threat landscape into annualised loss exposure — numbers your board can act on.

Security Strategy

Roadmap development, control prioritisation, and programme design — all anchored to risk-adjusted ROI rather than compliance checklists.

Board & Executive Advisory

Translating technical risk into clear financial narratives for board packs, audit committees, and executive leadership teams.

The engagement process

01
Scoping call
A 45-minute conversation to understand your threat profile, data assets, and decision context.
02
Data collection
Structured workshops to gather loss event data, asset valuations, and control effectiveness inputs.
03
Model & analysis
FAIR-based Monte Carlo simulation producing probabilistic loss distributions and risk scenario ranking.
04
Board deliverable
A concise executive report with risk heat maps, control ROI analysis, and prioritised recommendations.

"Security risk is a financial problem. It deserves financial tools."

Too many security programmes are driven by frameworks that tell you what to do, but not how much to spend or which risk matters most. I bring actuarial rigour — the same discipline insurers use to price uncertainty — into the security decision room.

Open FAIR Monte Carlo simulation Actuarial modelling CISO advisory Board reporting Control ROI

Open FAIR (Factor Analysis of Information Risk) is the international standard for cyber risk quantification. Unlike maturity models or heat maps, it produces defensible probability distributions over financial loss — enabling investment decisions based on expected value.

My models are built to be transparent, auditable, and repeatable. You own the model after every engagement, so your team can run scenarios independently going forward.

Read more about my background →

Ready to put a number
on your cyber risk?

No obligation. Just a conversation about what uncertainty costs you.

Book a free scoping call