Testimonials
Friendly
Services
Video meeting . 30 mins
5
Free Discovery Call — GRC & Cybersecurity
No pitch. Just an honest talk about your situation.
Video meeting . 60 mins
GRC Strategy Session — 1:1 Advisory
Diagnose your GRC posture & define your next 3 moves.
Priority DM . a day reply
GRC & Cybersecurity Questions
Ask your compliance question. Get an expert answer in 24h.
Video meeting . 60 mins
ISO 27001 Readiness Review
Find your audit gaps before the auditor does.
Priority DM . 2 days reply
CV & Profile Review
Senior feedback on your GRC/cybersecurity positioning.
Video meeting . 60 mins
VAPT Advisory — Scoping & Findings Review
Turn vulnerability findings into board-level decisions.
About me
Most cybersecurity consultants advise from the outside.
I come from the inside.
For over 10 years I've served as Director of Operations for a multi-subsidiary data networks and infrastructure group — functioning as a CEO across four business units, owning P&L, strategy, vendor relationships, client delivery, and every operational decision that comes with running a real business under commercial pressure.
Alongside that, I've built a focused GRC and cybersecurity advisory practice serving enterprises and government organizations across the Middle East and Gulf region.
That combination is rare — and it fundamentally changes how I work.
When I help you build an ISO 27001 program, I don't work from a template. I ask: will your operations team actually follow this control under deadline pressure? Will this incident response plan survive a real crisis — not just an audit? Those are the questions that separate governance that works from governance that looks good on paper.
They come naturally when you've been the person responsible for the whole business, not just the security function.
─────────────────────────────────────────
CREDENTIALS
─────────────────────────────────────────
🔐 ISO/IEC 27001:2022 Lead Auditor
🤖 ISO/IEC 42001:2023 Lead Auditor (AI Governance)
🛡️ VAPT Certified — Ministry of Communications
🛡️ Cybersecurity Professional Certificate – IBM
📊 GRC advisory across enterprise and government sectors
🏢 Director of Operations — multi-subsidiary technology group, 4 business units
─────────────────────────────────────────
WHAT I HELP WITH
─────────────────────────────────────────
→ ISO 27001 implementation & certification preparation
Gap analysis, risk assessment, policy suite, internal audit, and seeing you through to passing your certification audit
→ NDMO & data privacy compliance
Data mapping, gap assessment, and a board-ready remediation roadmap aligned to national and international data protection requirements
→ AI Governance — ISO 42001
For organizations deploying AI who need a governance framework before regulators or clients start asking for one
→ GRC maturity assessment & strategy
An honest assessment of where you are and a clear, prioritized roadmap for where you need to be
→ Vulnerability assessment & penetration testing (VAPT)
Finding what your team didn't know to look for — with findings presented in language your board can act on
→ Executive cybersecurity awareness
Half-day program for C-suite and board members — translating technical risk into the business decisions that actually protect an organization
─────────────────────────────────────────
HOW I WORK
─────────────────────────────────────────
I don't deliver 200-page reports that sit in folders.
Every engagement produces something your team can actually execute — a working roadmap, a tested process, or a governance structure built around how your organization actually operates, not how a framework assumes it does.
Sessions available in Arabic and English.
Remote and on-site engagements available worldwide.
─────────────────────────────────────────
WHO BOOKS WITH ME
─────────────────────────────────────────
✔ CISOs and IT Directors preparing for ISO 27001 certification
✔ Operations and business leaders handed a GRC mandate without a clear path
✔ Compliance managers working through data privacy requirements
✔ C-suite executives who need to understand cyber risk in business terms
✔ GRC and security professionals seeking a senior peer to think through real challenges with them
Not sure if your situation fits? Book a free 30-minute discovery call.
I'll tell you directly whether I can help — and if not, point you toward
who can.