Information security · since 1995
It is the only question anyone asks me. Nearly always in those words. It comes from a chief executive before a delicate decision, from a board with nobody around the table it can really rely on for this, from someone in the public eye about to have something surface that never should have. It has very little to do with technology.
Decisions that matter are no longer taken without somebody in the room who can read technical risk. That changed in the last few years, and it will not change back.
A board today signs off on investments, acquisitions and technology suppliers that can be worth as much as a balance sheet. A chief executive signs statements about data protection they are personally answerable for. A public figure stakes a reputation on a file that was never meant to travel. In each of these cases what is needed is someone independent, with nothing to sell.
I am appointed to boards as the security expert supporting the chief executive, and I sit on advisory boards. They call me to help decide, not to deliver training: when what is on the table is a technology investment, an acquisition, a critical supplier or an incident already under way. How I work on a board →
Funds and investors also ask me to establish whether a technology company can genuinely do what it claims, and whether what it claims holds together. It is the same examination I bring to a boardroom. Technology due diligence →
On these questions there is often nobody around that table to be relied on, because almost everyone has something to sell. When I sit there, I am not selling software.
Responsibility for information security now rests personally with the people at the top. It is no longer a question of reputation or budget: it has a name attached, and it is the name of whoever is in charge.
Before an executive tells the market, a regulator or a board that the data is safe, somebody has to be able to verify that it actually is. I do that check, and I say so even when the answer is unwelcome.
I also protect the privacy of people who live in the public eye: recognisable faces, parliamentarians, business owners, artists. How I work in those cases
I am an information security expert. I sit on boards and advisory boards as the independent voice supporting the chief executive. I protect the privacy of people who live in the public eye. I establish, for funds and investors, whether a technology company can genuinely do what it claims. And I teach courses and seminars for senior leadership.
It is a model in which protection lives inside the data rather than in the infrastructure holding it. It stays encrypted wherever it is copied, forwarded or stored: nothing changes for anyone holding the keys, and for everyone else the contents are mathematically inaccessible. It is the principle behind my patents, and I first set it down in writing on 22 March 2006.
Cloud platforms do encrypt data, but the platform holds the keys rather than the data itself, so it decrypts for anyone it considers authorised. An agent acting on an employee's behalf is, as far as the system is concerned, that employee. It reads everything in the clear within seconds and raises no alert. I demonstrated this live in front of an audience of security leaders.
Less and less, if it teaches people to spot the artefact. Conventional training drills the odd link, the wrong sender or the spelling mistake: signals generative AI has erased, because those messages are now written better than ours. What still works is teaching the mechanism. Phishing, smishing and social engineering always pull the same three levers: authority, urgency, reciprocity. Anyone who recognises the lever also recognises the attack they have never seen before.
US 12,596,770, granted in the United States on 7 April 2026, and EP 4,427,154, granted by the European Patent Office on 3 September 2025 with unitary effect across seventeen EU member states. Both derive from Italian application IT 102021000027959, filed 3 November 2021. Before those, US 11,200,349, granted in 2021.
Why defending the network is no longer enough, and what happens when an AI agent reads your information. Including the demonstration I ran live in front of security leaders.
Read the thesis →The guided assessment is not a lecture. We follow a real document from your organisation until it stops being protected, and you leave with a list of fixes in order of urgency.
See the three formats →Patents filed and granted, international awards, companies, institutions. Including the 2006 application I could not afford to keep alive.
Open the record →