The management of cyber risk is a journey that adapts to changes in an organisation’s circumstances. Cyber risk develops as business strategy changes, as new and existing products and services are developed and enter markets, and as organisations grow organically and strategically.
Cyber risk management is a complex and ongoing process of evolution and adaptation. Evolving at a pace that exceeds the threats to an organisation as it travels across its supply chains. To address the threat of cybersecurity to national security, cybersecurity risk management is being regulated by nation-states. Requiring organisations and their leadership teams to take accountability and responsibility for the governance and management of cyber risk.
We don’t advise leadership teams to take this journey alone. Cyber regulation and compliance are expensive. Legal precedent has been set, with legal risk to organisations, their boards, and security professionals.
Andy is a leader in cybersecurity risk management. He has held roles leading both 1st and 2nd Lines of Defence for organisations as diverse as Group VP cyber risk Grupo Santander, European DGM Operational Risk and CISO Mizuho Corporate Bank, and global head of cyber Penguin Random House. He was the Council-appointed cybersecurity and risk expert to the UK Information Commissioner’s Office (ICO). He received a U.S presidential volunteer service award for his work on the U.S DoD Cybersecurity Maturity Model Certification (CMMC) program.
Andy is a Chartered Security Professional (CSyP) and CSyP assessor, recognised by the UK’s Centre for the Protection of National Infrastructure (CPNI), and holds a place on the UK Register of Chartered Security Professionals. He is a Chartered Engineer (CEng) received during his time at Rolls-Royce plc, and he is a member of the Institute of Mechanical Engineers (MIMechE). He was a past member of the board of the UK Security Institute (MSyI), he is a Freeman of the Worshipful Company of Security Professionals (WCoSP), and a Freeman of the City of London.
Andy has provided thought Leadership and helped formulate cyber strategy through many papers, webinars, and conferences. That has included discussions with the White House Office of the National Cybersecurity Directorate (ONCD), U.S Department of Defense, The Cyberspace Solarium Commission, Members of Congress, UK All Party Parliamentary Committees, conducted with the U.S DoD, he has led CMMC for UK defence trade associations and given webinars, presentations, and papers for the AICPA, IIA, AFCEA and NDIA, amongst many others.
Ted is a veteran of cybersecurity with over 40 years of experience in the design, delivery, oversight and assurance of cybersecurity and risk management systems. Ted’s area of expertise is the management of risk in Information Technology, developed over the years. He is an experienced systems Auditor and Integrator, giving him a unique insight as to the challenges associated with developing eGRC programs, which satisfy the compliance requirements faced by organisations of all types and sizes.
Ted is an internationally recognised cybersecurity, risk management and Information systems educator and a highly respected security trainer. He is authorised to train ISACA CISA, CISM, CRISC, ISC2 CAP, CCSP, and CISSP. He holds DoD secret clearance and has taught courses for a broad range of public and private sector organisations that include most U.S Federal Agencies, State and Local Government, and companies across financial services, consultancies, engineering, manufacturing, defence, healthcare, media and IT services providers and cloud.
Brian has over 30 years of experience in training design, development, facilitation, and human capital performance. Brian enables the best solutions for measurable impact and improvement, from pharmaceutical product launch training to reskilling thousands of developers in the financial sector to Department of Defense (DoD) compliance.
Brian has worked with every DoD service branch and most prime contractors and has deployed training globally. He has created global soft-skills programs for organizations such as Thomson Reuters, in multiple localized languages, recruited and staffed multilingual global facilitation teams, and architected multiple telecom programs for teams like Comcast and Verizon. Brian has placed the top echelon of cybersecurity, risk management, compliance, audit, and technology trainers for organizations such as Global Knowledge, Marines, University of Arizona, and leading “Bootcamp Styled” training providers.
Brian has created solutions as an Authorized Training Organization (ATO), delivering high-caliber training and programs in information management, audit, risk, and cyber, with resources to deploy globally.
LinkedIn: https://www.linkedin.com/in/bmccarthy/
George is an Analyst at Evolution Ltd., working with academics from London Business School on strategy consulting projects in Artificial Intelligence and digital ecosystems, while also coordinating Evolution’s project management and operations. Based in Athens, Greece, George also serves as the European Development Officer at Deon Policy Institute, expanding Deon’s reach across Europe and fostering its strong connection with Greece. Beyond Evolution, he is a Research Analyst at Aegis Labs supporting the ecosystem architecture of an end-to-end automatic cybersecurity compliance audit platform, leveraging networks and shaping partnerships with local stakeholders. George is also Co-Founder & CTO at Spark Trading S.A.
George holds an integrated master’s degree in Physics from Imperial College London, where he researched statistical methods and developed predictive epidemiological models to compress the time needed in devising public health policy for COVID-19 with the UK Scientific Advisory Group for Emergencies (SAGE). Earlier in his career, George worked as a trading analyst at Merrill Lynch International in the Global Credit Structured Products division.




