Board Advisor

Cybersecurity and AI are now the board's business

I'm an independent board advisor. I give your board the judgement to oversee cyber-risk and artificial intelligence on its own terms.

What I bring to the board

From technical threat to board decision

Cyber-risk oversight

I put a number on the real exposure, question the risk appetite and give you the right questions to oversee the CISO without having to take it all on trust.

AI governance

A framework for using artificial intelligence sensibly, aligned with the AI Act and with what really adds to the business.

Regulatory compliance

NIS2, DORA and ISO 27001: what they demand of you as a board and how to show the oversight is real, not just on paper.

Crisis readiness

Board-level incident simulations and availability when a decision has to be made in the heat of the moment, crisis communication included.

The context

Boards are now accountable for cybersecurity

European regulation has pushed accountability for digital security up to the top governance body. Looking the other way is no longer an option.

NIS2

Direct management accountability for cyber-risk management, with personal liability.

DORA

Digital operational resilience for the financial sector and its supply chain.

AI Act

Governance and transparency obligations over artificial intelligence systems.

Frequently asked questions

About the board advisor role

What does a cybersecurity board advisor bring to a board of directors?

As a cybersecurity board advisor, I translate technology risk into board language: I put a number on the exposure, prioritise investment, oversee the CISO and make sure cybersecurity and AI are governed as a strategic risk, not as a purely technical matter.

How is a board advisor different from an independent non-executive director?

A board advisor sits with the board with a voice, but with no vote or formal fiduciary duty. It contributes deep domain expertise, cybersecurity and artificial intelligence, with far greater flexibility and lower onboarding cost than a full non-executive director.

Which regulations must a board watch on cyber and AI today?

Chiefly NIS2 and DORA for resilience and cybersecurity, the EU Artificial Intelligence Act for responsible AI, and governance frameworks (ISO 27001, NIST). Boards are accountable for effective oversight of all of them.

How is a board advisory engagement usually structured?

Usually as a recurring relationship: I attend the risk or audit committees, run board education sessions, review the cybersecurity and AI strategy, and stay on call for incidents or critical decisions.

Bring that judgement to your board

Let's talk about what your board or management committee needs, with no commitment.

Let's talk about your board or committee