Information security for senior leadership and people in the public eye

«Who can I trust?»

Information security · since 1995

It is the only question anyone asks me. Nearly always in those words. It comes from a chief executive before a delicate decision, from a board with nobody around the table it can really rely on for this, from someone in the public eye about to have something surface that never should have. It has very little to do with technology.

Where I sit

Decisions that matter are no longer taken without somebody in the room who can read technical risk. That changed in the last few years, and it will not change back.

A board today signs off on investments, acquisitions and technology suppliers that can be worth as much as a balance sheet. A chief executive signs statements about data protection they are personally answerable for. A public figure stakes a reputation on a file that was never meant to travel. In each of these cases what is needed is someone independent, with nothing to sell.

Boards and advisory boards

The independent voice at the table

I am appointed to boards as the security expert supporting the chief executive, and I sit on advisory boards. They call me to help decide, not to deliver training: when what is on the table is a technology investment, an acquisition, a critical supplier or an incident already under way. How I work on a board →

Funds and investors also ask me to establish whether a technology company can genuinely do what it claims, and whether what it claims holds together. It is the same examination I bring to a boardroom. Technology due diligence →

On these questions there is often nobody around that table to be relied on, because almost everyone has something to sell. When I sit there, I am not selling software.

Chief executives

One more certainty before signing

Responsibility for information security now rests personally with the people at the top. It is no longer a question of reputation or budget: it has a name attached, and it is the name of whoever is in charge.

Before an executive tells the market, a regulator or a board that the data is safe, somebody has to be able to verify that it actually is. I do that check, and I say so even when the answer is unwelcome.

I also protect the privacy of people who live in the public eye: recognisable faces, parliamentarians, business owners, artists. How I work in those cases

Since 1995
First security program
published in the press
Patented
The method that protects
the data, not the perimeter
Institutions
European Commission
European Defence Agency
Defence
Adviser to military bodies
cryptography for public institutions
Live sessions

All three formats run both on a public calendar and in-house, behind closed doors. Upcoming dates are announced here.

If you would like to be told when a date opens, or would prefer a session held privately for your company, write to me.
How I work in the room
Frequently asked

What people want to know
before they pick up the phone.

What exactly do you do?

I am an information security expert. I sit on boards and advisory boards as the independent voice supporting the chief executive. I protect the privacy of people who live in the public eye. I establish, for funds and investors, whether a technology company can genuinely do what it claims. And I teach courses and seminars for senior leadership.

What is data-centric security?

It is a model in which protection lives inside the data rather than in the infrastructure holding it. It stays encrypted wherever it is copied, forwarded or stored: nothing changes for anyone holding the keys, and for everyone else the contents are mathematically inaccessible. It is the principle behind my patents, and I first set it down in writing on 22 March 2006.

Why is an AI agent a risk to corporate data?

Cloud platforms do encrypt data, but the platform holds the keys rather than the data itself, so it decrypts for anyone it considers authorised. An agent acting on an employee's behalf is, as far as the system is concerned, that employee. It reads everything in the clear within seconds and raises no alert. I demonstrated this live in front of an audience of security leaders.

Does anti-phishing training still work?

Less and less, if it teaches people to spot the artefact. Conventional training drills the odd link, the wrong sender or the spelling mistake: signals generative AI has erased, because those messages are now written better than ours. What still works is teaching the mechanism. Phishing, smishing and social engineering always pull the same three levers: authority, urgency, reciprocity. Anyone who recognises the lever also recognises the attack they have never seen before.

Which patents have you filed?

US 12,596,770, granted in the United States on 7 April 2026, and EP 4,427,154, granted by the European Patent Office on 3 September 2025 with unitary effect across seventeen EU member states. Both derive from Italian application IT 102021000027959, filed 3 November 2021. Before those, US 11,200,349, granted in 2021.