Can we keep operating through a serious cyber incident?
Understanding whether leadership can keep deciding—and the organisation keep its critical promises—during disruption.
Discuss resilience readiness
Fook Hwa TanFaith · Clarity · ServiceProfessional life
I help leaders turn cybersecurity, quality, privacy and resilience from a maze of requirements into a practical system of trust.
My professional mission
Cybersecurity can feel like a storm of standards, threats and technologies. My role is to help organisations see the whole landscape, understand what matters most and take the next sensible step.
I bring more than 20 years of experience across consulting, auditing, team leadership, managed services and executive quality. As Chief Quality Officer and internal CISO at Northwave Cybersecurity, I am responsible for the integrated management of quality, security, privacy, continuity, risk and compliance. Alongside that, I have served as CISO for organisations across six sectors—from energy grids to insurers to manufacturers—and increasingly help leaders navigate EU regulation such as NIS2, DORA, the CRA and the AI Act.
Good governance is not paperwork. It is the quiet system that helps people keep their promises—even under pressure.
Board questions
Board members usually recognise their problem before they recognise the service they need. Three questions I am often asked to help answer:
Understanding whether leadership can keep deciding—and the organisation keep its critical promises—during disruption.
Discuss resilience readinessTurning reporting into decision support: the right questions, honest indicators and a clear risk appetite.
Discuss board reportingNIS2, DORA, the CRA and the AI Act all assume clear ownership. Clarity of accountability beats volume of paperwork.
Discuss governance ownershipHow I can help
My work sits where governance, people and operations meet.
Independent perspective for leaders navigating security management, privacy, business continuity, risk and regulatory expectations.
You leave with: clearer ownership, priority oversight questions and an agreed sequence of next steps.
Clear, practical learning experiences on ISO standards, auditing, cyber resilience, AI governance and digital trust.
You leave with: shared language, sharper questions and knowledge people can use the next day.
Building integrated management systems that support consistent delivery, real improvement and calm under audit pressure.
You leave with: one coherent system across quality, security, privacy and continuity—rather than parallel paperwork.
CISO in the field
Every sector keeps different promises. I have had the privilege of guarding them in very different worlds.
CISO · 2022 – present
CISO · 2021 – 2024
CISO · 2021 – 2023
CISO · 2019 – 2021
CISO · 2018 – 2019
CISO 2016 · Manager Global SOC 2013 – 2014
Areas of expertise
Professional credentials
More than 45 certifications and qualifications spanning information security, quality, audit, risk, privacy and continuity—because credibility should be earned twice: in the classroom and in the field. As a PECB Certified Gold Trainer and BSI trainer, I also help others earn theirs.
Memberships & affiliations
Standards, ethics and knowledge-sharing that reach beyond any single organisation.
In the media
A few third-party articles and institutional mentions that trace the journey.
Named in Northwave’s management team as director Business Security Netherlands.
On integrated security: ISO 27001, privacy compliance and business continuity.
Quoted as Chief Quality Officer on international collaboration for a safer digital environment.
Serving the Dutch security community as a member of the JBISA jury.
Co-signatory, alongside CISOs worldwide, of the call on G7 and OECD member states to align cybersecurity regulation.
Work together
Let’s explore what safer, simpler and more resilient could look like for your organisation or learning programme.
Professional engagements are considered in line with my responsibilities at Northwave Cybersecurity and any applicable organisational approvals.