Set strategy in the boardroom.
Still write the code.
Twenty-five years across digital, cyber, and AI risk for boards, governments, and critical infrastructure. Risk has been the constant throughout, rather than a specialism arrived at late. Antan IRM, the risk platform I built and use with clients, is one of the tools.
- Cybersecurity
- AI risk & governance
- R&D
- Quantitative risk analysis
- Cyber & technology risk
- Security architecture & design
- Privacy & compliance
- Security strategy (vCISO)
Senior advisory and delivery across risk and security
From risk and control assurance for the audit committee to the code that runs in your SOC. Engagements scale from a four-week certification sprint to multi-year programme leadership.
Some of the work
A sample of anchor achievements in risk, governance, and security across regulated, public-sector, and critical-infrastructure environments.
Delivered a FAIR-based quantitative risk framework at one of New Zealand's largest technology organisations, sharpening executive decisions and materially reducing enterprise risk exposure, alongside ISO/IEC 27001:2022 and SOC 2 Type 2 certification.
Owned enterprise security architecture and the GRC programme at a government agency, then designed and built its Security Operations Centre end to end across people, process, and technology.
Defined the corporate threat profile at a lines utility and integrated IT and OT cyber risk into the enterprise risk framework, with a sector-specific maturity model to guide the uplift.
Co-founded the OWASP New Zealand chapter and continues to contribute to the security community.
Antan IRM - risk that has left the spreadsheet
An AI-powered cyber risk platform I built and use for quantitative risk and decision analysis. It began as a replacement for the risk register in a spreadsheet and grew, function by function, into a tool that turns scattered security data into quantified, board-ready decisions, with a deterministic guardrail that keeps its own AI agents in check.
It is still a work in progress, and improving steadily. Try the demo, and if you would like to know more, get in touch.
Explore Antan IRMLet's talk about your security programme
Whether it is testing whether your controls actually work, quantifying a risk in dollars, securing an AI deployment, or standing up the SOC that runs it, the work starts with a conversation. The first one is on the house.