Industry
Payments & Financial Services
Trust is the capital. Compliance is the licence to operate.
I help banks, investment firms, insurers and fintech companies manage cyber risk, strengthen controls and respond to incidents with confidence.
- Regulatory expertiseDeep understanding of your obligations and expectations.
- Risk-aware approachAligning cybersecurity with business and risk strategy.
- Resilient operationsBuilding cyber resilience across complex ecosystems.
- Independent adviceUnbiased, evidence-driven recommendations.
Key challenges
The most regulated sector is also the most targeted.
Financial institutions operate in a high-stakes environment where cyber risk can impact stability, reputation and regulatory standing.
- Evolving threats targeting financial assets and data
- Complex regulatory and supervisory requirements
- Third-party and supply-chain dependencies
- Legacy systems and digital transformation
- High availability and business-continuity demands
DORA & supervisory readiness
Prepare for DORA, NIS2 and supervisory expectations, with evidence that stands up to scrutiny.
ICT third-party risk
Assess and monitor critical ICT providers and outsourcing, with the concentration and exit-risk view supervisors now expect.
Operational resilience testing
Scenario-based and threat-led testing of the systems that must keep processing payments and settlements.
Incident readiness & reporting
Build the detection, escalation and regulatory-notification capability DORA and supervisors require.
Cyber due diligence
Assess cyber risk in acquisitions, fintech investments and partnerships before capital is committed.
Governance & board oversight
Give the board a defensible view of ICT risk, controls and accountability.
My impact
Security that strengthens confidence and performance.
I strengthen controls where it matters most and give the board a clearer view of exposure, while supporting growth, innovation and customer trust.
View case studies- 1Dedicated advisorAccountable end to end, with no hand-off to junior staff.
- 15+Years of experienceIn cybersecurity and risk management.
- RetainerIncident responseContracted availability under retainer when it counts most.
- Cross-borderInternational contextsSupporting international operations and regulatory engagements.
Outcomes for your sector
- a defensible view of ICT and third-party risk that holds up in front of supervisors
- clarity on which resilience gaps could interrupt payments or settlement, and which can wait
- an incident-reporting path that meets regulatory deadlines without improvisation
- confidence in the cyber posture of a fintech target before the deal closes
My engagement model
Tailored to your needs.
- 01. Understand
I learn your business, risk context and strategic objectives.
- 02. Assess
I evaluate risks, controls and compliance against industry standards.
- 03. Advise
I provide clear, prioritised recommendations aligned with your goals.
- 04. Support
I help you implement improvements and build resilience.
- 05. Evolve
I continuously monitor, review and adapt to emerging risks and regulations.
Work & insights
What I’ve done
Due diligenceBuy-side cyber due diligence on a fintech target
Technical due diligence on a payments platform that surfaced material exposures, with a direct impact on price negotiation and a Day 1 remediation plan.Private equity / M&A
DORADORA readiness for a mid-sized financial institution
A DORA readiness programme that closed the main gaps in ICT risk management, incident reporting, and critical ICT providers, with an operational resilience testing cycle in place.Financial services / Banking
DORADORA for the financial sector: digital operational resilience
Regulation (EU) 2022/2554 harmonises ICT risk management, incident reporting, resilience testing and oversight of critical providers.21 Nov 2025 · 4 min read
Ready to strengthen your cyber resilience?
Let's discuss how I can help.
Let's talk about how I can help you understand your exposure, meet regulatory expectations and act on what is material.