Independent director

A board needs someone
with nothing to sell.

Almost every significant board decision now carries a component of information risk: an acquisition, a critical supplier, an artificial intelligence platform, a statement to the market. Around that table there is rarely anyone able to read it who does not have an interest in the answer.

I am appointed to boards as the security expert supporting the chief executive, and I sit on risk committees and advisory boards. I do not bring training. I bring a position, and when it matters I put it in writing so that it stands on the record.

On these matters responsibility no longer belongs to the IT function. It has a name, a surname and a signature.

Since 1995
Thirty years in the trade
First software on the newsstand
Patents
Granted by the USPTO and EPO
Unitary effect in 17 countries
Institutions
European Commission
European Defence Agency
Capital
Co-founder of CyberGrant
Former managing partner of a fund
Why now

Information risk has stopped being a line of spending and become a duty of those who govern.

This is not a forecast. It has already happened, and it is why boards have started looking for a competence inside the room that they used to buy outside it.

Personal liability

The signature is yours

GDPR, NIS2, DORA and the AI Act place the obligation on the administrative body. Delegating is no longer enough: the board must be able to show that it decided knowing what it was deciding about.

In front of a regulator or a court, what counts is what the minutes say.

Irreversible decisions

It goes on the balance sheet

An acquisition, a critical supplier, a migration, the adoption of artificial intelligence tools. Choices that weigh as much as a balance sheet entry and that cannot be unwound.

Whoever brings them to the board almost always has an interest in seeing them approved. I do not.

Long horizon

Ten years, not twelve months

Criminal groups and state actors are already collecting vast quantities of encrypted data in order to read it once the technology allows: harvest now, decrypt later.

For a board that plans in multi-year cycles the question is not whether the data is protected today, but whether it will still be in ten years.

Independent voice

No product to place

An adviser who sells software cannot tell a board that the problem will not be solved by buying software. I can, and sometimes that is precisely the right answer.

It is the reason I am called, and the only thing that makes my presence at that table worth anything.

The mandate

A year on a board,
in four moments.

How I work once appointed
01

Taking the seat. I read what the board already has and no one has ever lined up: contracts with critical suppliers, audit findings, insurance policies, the continuity plan. In the first few weeks I deliver a single page.

02

The meetings. I sit on the board or on the risk committee. On items with an information component I take a position before the vote, and that position goes into the minutes.

03

Between meetings. A supplier to choose, a due diligence, an AI tool to authorise. Real decisions rarely wait for the calendar: on those days I am reachable.

04

The incident. When it happens, the board needs to know within two hours what to say to the regulator, to customers and to the market. I have done this part several times, and not from behind a desk.

At the table

The questions I answer.

They are almost always these. And they are almost never technical questions.

  • Can this supplier actually do what it claims, or does it only claim it?
  • If we sign this statement, are we able to prove it?
  • What happens to our data if the supplier is breached tomorrow?
  • Can we authorise this artificial intelligence tool, and on what conditions?
  • Does the plan we were shown cover the risk, or the budget of the person who wrote it?
  • Will what is protected today still be protected in ten years?
  • Under inspection, is the protection demonstrable or merely declared?
  • If something comes out tomorrow, who speaks, when, and in what words?
Forms of appointment

Three ways to sit down.

A

Independent director

A formal appointment to the board for the length of the term. It is the form that gives my opinion the weight of a vote, and gives the board the ability to show that the competence was in the room.

  • Attendance at board meetings
  • Position on the record for matters in my remit
  • Availability between meetings
B

Risk committee and advisory board

A scheduled presence without directorial liability. This is the most common form in groups that already have a full board and want the groundwork, not another vote.

  • Preparatory work on technology items before the board
  • Second opinion on suppliers, plans and investments
  • Crisis simulations for the administrative body
C

Fixed-term engagement

Support on a single decision: an acquisition, a critical supplier, the adoption of artificial intelligence, an incident under way. It starts and it ends.

  • Duration agreed at the outset
  • One document delivered to the board
  • Attendance at the meeting where it has to be defended

I accept a limited number of appointments each year, and only one per sector: I do not sit at two tables that compete. Appointments move slowly, and nomination committees look at profiles months ahead.

Conflict of interest

I am co-founder and technical director of CyberGrant, and the patents in the record are mine. When I sit on a board my technology is not among the options and does not become one: if an evaluation were ever to reach that point, I recuse myself and ask for the recusal to be minuted. It is the only condition I set before accepting an appointment, and I am the one who sets it.

If your board is about to open a seat, or a decision is already on the table, write to me. I answer personally.

Get in touch