Cyber Security — Risk & Controls

Cyber security in the language
of the boardroom

David Viney

Most boards are receiving cyber risk reporting written by technical people for technical people. I translate it — into fiduciary language, commercial consequence, and decisions that boards can actually make. Then I help deliver the programmes that close the gaps. Previously SC Cleared and available at short notice.

Book a Technology MOT Start a conversation
What this covers

Three things I do here,
each with real depth

Mode 1 — Consulting Mode 2 — Assurance Mode 3 — Delivery
01

Fractional CISO & Ongoing Risk Advisory

Most organisations that need a CISO cannot justify a full-time one. A Fractional CISO provides the board with a named, accountable individual who owns the cyber risk agenda — attending relevant board and risk committee meetings, setting and maintaining the cyber strategy, and ensuring the organisation's security posture is appropriate to its risk profile and regulatory environment.

As ongoing adviser I work across the full security landscape — endpoint protection, threat intelligence, SOC management, security awareness, identity, and access management — translating the technical picture into board-level risk language on a regular cadence.

Mode 1 — Consulting
Economic & Social Development Agency · $6bn turnover · 96,000 staff · Africa & Asia
Cyber Security Programme — AKDN
Delivered a comprehensive cyber security programme across a complex, federated international organisation spanning health, education, banking, and rural development operations. Scope included CrowdStrike for endpoint security & threat intelligence, Obrela as outsourced SOC for managed threat detection & response, and KnowBe4 for end-user awareness training and cloud email protection across the network.
Endpoint protection · SOC delivery · cyber awareness training
02

Independent Cyber Assurance & Board Reporting

The board cannot rely solely on management's assessment of cyber risk — particularly where the people responsible for security are also the people reporting on it. Independent cyber assurance provides the board with a second opinion: an honest, external view of the organisation's actual security posture, its gap to relevant frameworks, and the materiality of its exposure.

As independent reviewer I assess cyber risk from the board's perspective — covering regulatory exposure, supply chain risk, incident response capability, and the adequacy of the security investment being made. Extensive experience in regulated and classified environments.

Mode 2 — Assurance
Regulated Critical National Infrastructure · 80m+ passengers · 90,000 staff · Heathrow Airport
Cyber Assurance & Programme Oversight — Heathrow
IT Sponsor for the £22m Cyber Readiness component of Heathrow's £1.3bn AMC Programme — providing board-level assurance on cyber risk across the enterprise asset portfolio. Turned around a stalled cyber programme (Microsoft Defender, Sentinel, Purview, Azure Monitor Agent) and delivered a new Isolated Recovery Environment (IRE) and Digital Control Tower for National Air Traffic Control.
Accelerated cyber programme · IRE & Digital Control Tower delivered
03

Cyber Programme Delivery & Incident Response

When cyber incidents happen — and they do — the organisation needs someone who has been in the room before. I have led the response to DDoS attacks from state actors, and major operational incidents at critical national infrastructure. The experience of having done this at scale, under genuine pressure, is not something that can be replicated in a tabletop exercise.

As delivery lead I run cyber programmes from strategy through to implementation — technology selection, vendor management, and the cultural change that makes security awareness stick. Available at short notice for urgent engagements, and previously SC-Cleared.

Mode 3 — Delivery
Global Marketing Services · $18.5bn revenues · 100,000+ people · 110 countries
State Actor Cyber Attack Response — WPP
Led the response to a major DDoS and cyber attack from state actors following WPP's withdrawal from their market. Rapidly hardened over 300 vulnerable endpoints and web services using an innovative combination of Okta and Cloudflare — under live threat conditions, at global scale, against a sophisticated adversary. The hardest four weeks of a long career in technology leadership.
Attack contained · 300+ endpoints hardened · services protected

The right starting point
is usually the MOT

Whether you need a Fractional CISO, independent assurance for your board, or urgent delivery support — the Technology MOT gives both of us a clear picture of your current cyber posture first. Fixed price. Fixed scope. No ongoing commitment. The MOT pays for itself.

Book an MOT 30m Therapy Session

“David is a gifted, knowledgeable, skilled, and inspiring technology professional and a highly effective manager, leader and Director.”

— Tom Saunders, CIO, British Standards Institution