Cybersecurity · Risk · Transformation

From compliance pressure to measurable resilience.

I help boards, leadership teams and regulated organisations turn cybersecurity obligations into defensible decisions, quantified risk reduction and operational capabilities that can be demonstrated with evidence.

Areas of focus

Bridging regulation, technology, finance and leadership so that cybersecurity becomes a managed business capability rather than a collection of isolated controls.

01

NIS2 and Cybersäkerhetslagen

Governance, management accountability, capability assessment and evidence-based compliance for essential and important entities.

02

Cyber Resilience Act

Secure-by-design governance, product lifecycle assurance, vulnerability handling, SBOM traceability and supplier responsibility.

03

Quantitative cyber risk

FAIR-based analysis that translates loss event frequency and magnitude into monetary exposure and decision-ready scenarios.

04

Supply-chain assurance

Procurement requirements, contractual flow-down, acceptance criteria and verifiable evidence across complex supplier ecosystems.

05

AI-assisted OSINT

Structured open-source intelligence to establish an external risk baseline, identify dependencies and support prioritisation.

06

Transformation leadership

Mobilising multi-stakeholder organisations, establishing practical methods and leading change from strategic intent to measurable operation.

A decision-oriented approach

Effective compliance requires more than policies. The organisation must be able to show how obligations become owned risks, funded controls, tested capabilities and retained evidence.

Cybersecurity is credible when leadership can explain the risk, justify the investment and prove that the capability works.
Principle for resilient governance
1

Establish the baseline

Map assets, dependencies, threat exposure, vulnerabilities and regulatory scope.

2

Quantify the exposure

Translate scenarios into financial and operational impact with explicit uncertainty.

3

Trace requirements to evidence

Connect legal duties to controls, owners, tests, acceptance criteria and retained proof.

4

Measure and improve

Use capability and process measurements to shorten remediation time and demonstrate progress.

Background

A multidisciplinary foundation combining technology, mathematics, operational leadership, business transformation and information-security governance.

International IT and telecom

Long experience in strategy, business development, operations and large transformation programmes involving multiple stakeholders.

Cybersecurity leadership

Experience from a CISO role in a cybersecurity company and advisory work on security programmes, NIS2 and ISO 27001.

Risk and performance

Development of methods for quantitative risk assessment, prioritisation and improved delivery performance in complex environments.

Science and engineering

Bachelor-level studies in physics and applied mathematics at KTH, with continuing interests in mathematics, Ada/SPARK and applied AI.

Contact

Make cyber risk understandable, actionable and provable.

Connect to discuss executive briefings, regulatory readiness, quantitative risk, supply-chain assurance or AI-assisted cybersecurity analysis.