Cyber Security & GRC
Cyber Security and GRC specialist. Most recently audited COMSEC compliance against HMG IS4 v8.1 with HMG. I help organisations identify control gaps, assess risk and turn audit findings into practical remediation.
Previously DV clearedBased in London, UK
Background
I'm a Cyber Security and Governance, Risk and Compliance (GRC) specialist with over ten years across government, public sector and regulated environments. I most recently audited COMSEC compliance against HMG IS4 v8.1 with HMG: reviewing evidence, assessing control effectiveness and supporting risk-rated findings, and investigating cryptographic incidents from initial escalation through to corrective action. That sits alongside broader work in IT compliance, information assurance, incident management, audit readiness and secure service governance. I managed and improved key parts of the Service Request Catalogue (SRC) for HMG, and before that supported IT infrastructure at Lewisham Homes. Across both, the constant has been turning technical control gaps into remediation actions that service owners, managers and senior stakeholders can act on.
COMSEC Audit
Built the HMG IS4 audit readiness pack used across every account I audit, the same pack behind the AuditFlow OS case study.
Service Governance
Ran ServiceNow and Service Manager governance for HMG's SRC, cutting new starter onboarding from up to three months down to under one.
Clearance
Previously held Developed Vetting (DV) clearance, the level required for the most sensitive COMSEC and cryptographic incident work.
Frameworks
HMG IS4 v8.1NCSC CAFNIST CSFISO 27001
Tools & Methods
Risk & Control AssessmentAudit Evidence ReviewITIL v4Access Governance / JMLServiceNowPowerShellPower BI
BSc Computer Networks, First Class Honours, University of East London
The Cyber and GRC Readiness Pack Series
I built a four-part cyber and Governance, Risk and Compliance (GRC) readiness pack series covering IS4, ISO 27001, NCSC CAF and NIST CSF 2.0. It started with the IS4 COMSEC audit question pack from my COMSEC audit work, then I used the same audit method to create the other three packs: evidence-led questions, deep-dive challenge points, good-practice and red-flag checks, findings capture and readiness scoring, each remapped to that framework's own domains. The ISO 27001, CAF and NIST CSF packs also close with an interview-preparation appendix. This series is also where AuditFlow OS started, see the full build story →




How I work an audit
The same sequence runs through the COMSEC audits, the Readiness Pack Series and AuditFlow OS itself.
Capabilities
What each part of this site demonstrates, and where to find the evidence.
Applied Professionally
- HMG IS4 v8.1 COMSEC compliance
- Cryptographic incident management
- Service Request Catalogue (SRC) governance
- Audit planning & evidence review
- IT infrastructure & access provisioning
Built
- AuditFlow OS (Notion workspace & SaaS beta)
- Cyber and GRC Readiness Pack Series (IS4, ISO 27001, NCSC CAF, NIST CSF)
- 8-week public audit and assurance content series
| Capability | Evidence | Shown |
|---|---|---|
| Audit & compliance readiness | HMG IS4 v8.1 COMSEC audits, Cyber and GRC Readiness Pack Series | ✓ |
| Risk identification & control assessment | COMSEC audits, cryptographic incident investigation | ✓ |
| Governance & service ownership | Service Request Catalogue (SRC) governance for HMG | ✓ |
| Stakeholder engagement | SRC approval routes and ownership records, audit findings briefings | ✓ |
| Process mapping & documentation | Readiness Pack Series, SRC conformance checks and audit-ready documentation | ✓ |
| Incident management | Cryptographic incidents, escalation through to corrective action | ✓ |
| Information assurance & infrastructure | IT infrastructure, device deployment and access provisioning at Lewisham Homes | ✓ |
| Product & systems thinking | AuditFlow OS, from Notion workspace to SaaS beta | ✓ |
AuditFlow OS
Built off the back of the COMSEC audit work and the SRC governance work above: a readiness pack series, a Notion audit operating system, a public build-in-progress series, and now a live SaaS beta. The full build story, screenshots and downloads are on its own page.