Almost every significant board decision now carries a component of information risk: an acquisition, a critical supplier, an artificial intelligence platform, a statement to the market. Around that table there is rarely anyone able to read it who does not have an interest in the answer.
I am appointed to boards as the security expert supporting the chief executive, and I sit on risk committees and advisory boards. I do not bring training. I bring a position, and when it matters I put it in writing so that it stands on the record.
On these matters responsibility no longer belongs to the IT function. It has a name, a surname and a signature.
Information risk has stopped being a line of spending and become a duty of those who govern.
This is not a forecast. It has already happened, and it is why boards have started looking for a competence inside the room that they used to buy outside it.
GDPR, NIS2, DORA and the AI Act place the obligation on the administrative body. Delegating is no longer enough: the board must be able to show that it decided knowing what it was deciding about.
In front of a regulator or a court, what counts is what the minutes say.
An acquisition, a critical supplier, a migration, the adoption of artificial intelligence tools. Choices that weigh as much as a balance sheet entry and that cannot be unwound.
Whoever brings them to the board almost always has an interest in seeing them approved. I do not.
Criminal groups and state actors are already collecting vast quantities of encrypted data in order to read it once the technology allows: harvest now, decrypt later.
For a board that plans in multi-year cycles the question is not whether the data is protected today, but whether it will still be in ten years.
An adviser who sells software cannot tell a board that the problem will not be solved by buying software. I can, and sometimes that is precisely the right answer.
It is the reason I am called, and the only thing that makes my presence at that table worth anything.
Taking the seat. I read what the board already has and no one has ever lined up: contracts with critical suppliers, audit findings, insurance policies, the continuity plan. In the first few weeks I deliver a single page.
The meetings. I sit on the board or on the risk committee. On items with an information component I take a position before the vote, and that position goes into the minutes.
Between meetings. A supplier to choose, a due diligence, an AI tool to authorise. Real decisions rarely wait for the calendar: on those days I am reachable.
The incident. When it happens, the board needs to know within two hours what to say to the regulator, to customers and to the market. I have done this part several times, and not from behind a desk.
They are almost always these. And they are almost never technical questions.
A formal appointment to the board for the length of the term. It is the form that gives my opinion the weight of a vote, and gives the board the ability to show that the competence was in the room.
A scheduled presence without directorial liability. This is the most common form in groups that already have a full board and want the groundwork, not another vote.
Support on a single decision: an acquisition, a critical supplier, the adoption of artificial intelligence, an incident under way. It starts and it ends.
I accept a limited number of appointments each year, and only one per sector: I do not sit at two tables that compete. Appointments move slowly, and nomination committees look at profiles months ahead.
I am co-founder and technical director of CyberGrant, and the patents in the record are mine. When I sit on a board my technology is not among the options and does not become one: if an evaluation were ever to reach that point, I recuse myself and ask for the recusal to be minuted. It is the only condition I set before accepting an appointment, and I am the one who sets it.
If your board is about to open a seat, or a decision is already on the table, write to me. I answer personally.
Get in touchPatents filed and granted, appointments, institutions, companies. There are no claims about myself: only things filed with an office, awarded by a jury or entered in a register.
Open the record →Why protecting the network is no longer enough, and what happens when an artificial intelligence agent reads your information. With the demonstration performed live.
Read the thesis →The examination I bring to an investment committee before a deal is the same one I later bring to a board table. Technology, patents, security, people.
How I work →