My Approach: 

I help organisations navigate the complex intersection of business, governance, and cybersecurity. My work is rooted in a simple principle: security must serve business strategy. I bring a strategic yet pragmatic perspective — turning compliance into coherence, and regulation into opportunity.

I offer:

  • Advisory:
    • I provide executive advisory services, related to defining and establishing an effective information security strategy, including a alignment of strategy with the organisational business strategy as well as external regulatory and contractual environment. These services include designing a supporting Target Operating Model (TOM) for the information security function, as well as defining needed policies, structures, processes and competences.
    Facilitator:
    • I provide facilitation of workshops for executive leadership and boards, or conduct specified and custom designed training sessions within a diverse number of security domains. I also facilitate networks and have, over many years, delivered public speaking at conferences, company events and done internal training videos.
    Trainer:
    • I conduct PECB-based or similar certification training, preparing participants for exams or tests. In a similar fashion, I also design and deliver specified training sessions across personnel segments, ranging from management and technical staff.
    CISO-as-a-service:
    • I provide CISO-as-a-Service for a shorter or longer periods or function as a special advisor and support for operative CISOs.

Rethink Governance, Reduce Complexity, Redefine Structures.

— 20 years of experience

I operate at the intersection of strategy, compliance, and innovation—translating complex regulatory landscapes within the digital space into actionable security strategies, operational models and frameworks. My work empowers boards, executive teams, and operational leaders to navigate today's dynamic threat environment with confidence and clarity.

As a former CISO, senior advisor and practioner, with deep expertise across corporate governance, cybersecurity, and digital regulation, I bring close to two decades of experience in information and cyber security - and last but not least crisis management. I've worked in the highly regulated fields such as energy supply, pharmaceuticals, financial services and tech. 

I have specialized in how cyber regulation affect, not only information security functions, but business processes, as well as sectors and markets. My expertise spans information and cyber leadership, GRC (Governance Risk and Compliance) across spanning numerous sectors, many of which in an international context. My career has been defined by a commitment to strategic clarity, operational resilience, and cross-functional collaboration—anchored in a systemic understanding of risk, regulation, and technology and across the organisation.

My contribution is looking at information security in a business perspective and finding practical and operative solutions rethinking governance, reducing complexity, regaining clarity helping Boards, Management and key employees reclaim leadership and command.

— Key areas of impact:


  • Executive advisory and board-level reporting on cyber and data risk

  • Public speaking, certified training (PECB), and thought leadership

  • Design and implementation of enterprise-wide security strategies and governance models

  • Regulatory alignment across privacy, cyber, and contractual domains

  • Leadership of Security Operations Centres (SOC) and major incident response

  • Strategic team building, talent profiling, and leadership development

  • Supplier assurance, contract design, and service oversight

— Education

PhD in Industrial / Spatial Economics 

Roskilde University, Denmark 2008-2012 

MLitt in Management, Economics and Int. Rel. 

University of St Andrews, Scotland 2002-2003 

Global Business Engineer (Eksportingeniør) 

Copenhagen University College of Engineering, Denmark 1996-2002
 

— Certifications

  • PECB Certified trainer (multiple courses)
  • DORA Senior Lead Manager
  • Board Education - Certificate
  • Certified Chief Information Security Officer
  • ISO/IEC 27005 Lead Risk Manager
  • Certified ISO/IEC 27001 Lead Implementer
  • C-CISO - Certified Chief Information Security Officer
  • CISL – Certified Cyber Information Security Leader
  • CISM - Certified Information Security Manager
  • Certified ISO 27001: 2013 Lead Auditor
  • CGEIT - Certified in the Governance of Enterprise IT
  • CRISC - Certified in Risk and Information Systems Control
  • CISA - Certified Information Systems Auditor
  • CSX-F – Cybersecurity Fundamentals Certificate
  • Prince2 Practitioner
  • ITIL Foundation

 

"My extensive experience and a diverse educational background, has given me the ability to analyse, work and operate across strategic, technical, financial, regulatory, and organisational boundaries - looking at things in a holistic or systemic perspective. In my view, an essential need within todays multi-integrated, complex, dynamic and global environment."

Get in touch