Professional life

Safer digital journeys begin with clear decisions.

I help leaders turn cybersecurity, quality, privacy and resilience from a maze of requirements into a practical system of trust.

My professional mission

Helping people be safe in a digital world.

Cybersecurity can feel like a storm of standards, threats and technologies. My role is to help organisations see the whole landscape, understand what matters most and take the next sensible step.

I bring more than 20 years of experience across consulting, auditing, team leadership, managed services and executive quality. As Chief Quality Officer and internal CISO at Northwave Cybersecurity, I am responsible for the integrated management of quality, security, privacy, continuity, risk and compliance. Alongside that, I have served as CISO for organisations across six sectors—from energy grids to insurers to manufacturers—and increasingly help leaders navigate EU regulation such as NIS2, DORA, the CRA and the AI Act.

Good governance is not paperwork. It is the quiet system that helps people keep their promises—even under pressure.

Board questions

What decision is your organisation facing?

Board members usually recognise their problem before they recognise the service they need. Three questions I am often asked to help answer:

Resilience

Can we keep operating through a serious cyber incident?

Understanding whether leadership can keep deciding—and the organisation keep its critical promises—during disruption.

Discuss resilience readiness
Oversight

Does the board receive information that supports real oversight?

Turning reporting into decision support: the right questions, honest indicators and a clear risk appetite.

Discuss board reporting
Ownership

Are cybersecurity, AI and regulatory responsibilities clearly owned?

NIS2, DORA, the CRA and the AI Act all assume clear ownership. Clarity of accountability beats volume of paperwork.

Discuss governance ownership

How I can help

From complexity to capability.

My work sits where governance, people and operations meet.

Consulting & sparring

Independent perspective for leaders navigating security management, privacy, business continuity, risk and regulatory expectations.

You leave with: clearer ownership, priority oversight questions and an agreed sequence of next steps.

Training & speaking

Clear, practical learning experiences on ISO standards, auditing, cyber resilience, AI governance and digital trust.

You leave with: shared language, sharper questions and knowledge people can use the next day.

Quality leadership

Building integrated management systems that support consistent delivery, real improvement and calm under audit pressure.

You leave with: one coherent system across quality, security, privacy and continuity—rather than parallel paperwork.

CISO in the field

Security leadership across six sectors.

Every sector keeps different promises. I have had the privilege of guarding them in very different worlds.

Manufacturing

Basler AG

CISO · 2022 – present

Insurance

Scildon

CISO · 2021 – 2024

Food

Royal Cosun

CISO · 2021 – 2023

Energy

Alliander

CISO · 2019 – 2021

Government

Municipality of Apeldoorn

CISO · 2018 – 2019

Education & finance

Fontys · Rabobank

CISO 2016 · Manager Global SOC 2013 – 2014

Areas of expertise

Broad view, practical focus.

Information security management
ISO 27001 · 27701 · 22301
SOC 2 & assurance
Cyber resilience & continuity
Quality management (ISO 9001)
Privacy & digital trust
Risk-based prioritisation
EU regulatory readiness — NIS2 · DORA · CRA
AI governance & the AI Act
Application security (ISO 27034)
OT security (IEC 62443)
Cloud security

Professional credentials

Experience backed by recognised practice.

More than 45 certifications and qualifications spanning information security, quality, audit, risk, privacy and continuity—because credibility should be earned twice: in the classroom and in the field. As a PECB Certified Gold Trainer and BSI trainer, I also help others earn theirs.

CISSPCISACISMCRISCCDPSEMBCIISO 27001 MasterPECB Gold Trainer
View more credentials
ISO 9001 Lead ImplementerIEC 62443 Senior Lead ImplementerISO 27034 App SecuritySOC 2 Senior Lead AnalystNIST CSFFAIRPRINCE2 Practitioner

View my ISACA trainer profile

Memberships & affiliations

Active in the professional community.

Standards, ethics and knowledge-sharing that reach beyond any single organisation.

ISC2 memberISACA memberBusiness Continuity Institute (BCI)American Society for Quality (ASQ)PECB Certified Gold TrainerBSI trainerCybersecurity Tech Accord — participantNEN — ISMS standards commissionEditor · Informatiebeveiliging Magazine (PvIB)TIAS Business School alumnus

In the media

Public mentions along the way.

A few third-party articles and institutional mentions that trace the journey.

Computable · 2014

Northwave wijzigt aansturing van organisatie

Named in Northwave’s management team as director Business Security Netherlands.

Read at Computable

Infosecurity Magazine · 2016

‘Alleen een samenhangende aanpak van security houdt stand’

On integrated security: ISO 27001, privacy compliance and business continuity.

Read the article

Cybersecurity Tech Accord · 2019

Northwave joins the Tech Accord

Quoted as Chief Quality Officer on international collaboration for a safer digital environment.

Read the announcement

PvIB · 2024

Joop Bautz Information Security Award

Serving the Dutch security community as a member of the JBISA jury.

Read at PvIB

Open letter · 2025

International Cybersecurity Regulatory Alignment

Co-signatory, alongside CISOs worldwide, of the call on G7 and OECD member states to align cybersecurity regulation.

Read the letter (PDF)

Work together

Need clarity for the next stage of your digital journey?

Let’s explore what safer, simpler and more resilient could look like for your organisation or learning programme.

Professional engagements are considered in line with my responsibilities at Northwave Cybersecurity and any applicable organisational approvals.