Cloud compliance readiness
Take an organisation to audit-ready against the frameworks that actually apply — NCA (ECC & CCC), SAMA CSF and PDPL in the Gulf; GDPR and NIS2 in the EU — mapped onto ISO 2700x and NIST so one control set answers all of them. Gap assessment, control mapping, and the roadmap to certification.
NCA · SAMA · PDPL · ISO 2700x · NIST · SOC 2 · GDPR · NIS2
Virtual CISO & program build
Stand up or mature a security function the way I built Unifonic's from the ground up — governance, enterprise risk, incident response, and the team behind it. Delivered as a fractional CISO or a fixed-term engagement.
vCISO · GRC · risk · incident response · board reporting
Cloud security architecture & review
Assess and harden production estates across AWS, Azure, GCP and OCI — exposure, identity, egress and the control stack (SIEM, IAM, WAF, DLP, Zero Trust), grounded in a decade of research on quantitative cloud-security assessment.
AWS · Azure · GCP · OCI · threat modelling · Zero Trust
AI security & AI governance
Put controls around the AI you are already shipping. Threat modelling for LLM and agentic systems — prompt injection, tool abuse, data leakage and model supply chain — mapped onto the EU AI Act, ISO/IEC 42001 and the NIST AI RMF, with the conflicts between those rulebooks resolved rather than ignored. This is the subject of my current research.
EU AI Act · ISO 42001 · NIST AI RMF · SDAIA · OWASP LLM Top 10
Courses, academies & enablement
I design and deliver cyber security curricula for a living — as a professor at IU Internationale Hochschule and previously as a co-lecturer at TU Darmstadt. The same work for your organisation: a corporate security academy, a role-based training track for engineers, or an executive and board-level briefing. Built to your stack, delivered on-site or remotely, in English, Arabic or German.
curriculum design · corporate academy · secure development · board briefings
Digital transformation & secure modernisation
Large modernisation programmes fail at the seams — identity, data residency, legacy integration and the governance nobody owns. I lead that work end to end on national-scale and enterprise digitalisation programmes: target architecture, cloud and data foundations, the security and compliance layer, and the local capability needed to run it after handover.
target architecture · cloud migration · data residency · capability build