ISC2 Harold F. Tipton Lifetime Achievement Award

Deeply humbled to share that I’ve been named the recipient of the 2026 ISC2 Lifetime Achievement Award, given in memory of Harold F. Tipton (widely known as the “George Washington of information security”).

Over the past two decades, my career has taken me to leadership and advisory roles at AT&T, Bemol, Canonical, CIBC, Doodle, the European Commission, Gibraltar International Bank, INTERPOL, and the United Nations. I’ve worked with Hugo to redefine what business process outsourcing (BPO) excellence looks like when delivered by top-tier African talent. But the common thread has always been the same – building trust and resilience into the digital systems people depend on, and making sure security serves people, not just infrastructure.

I’ve had the privilege of working at the Internet Society finding opportunities for emerging talent in developing countries to work on maintaining an open, accessible, secure, and human-centric Internet. I’ve served on the ISACA and ISACA Foundation Boards of Directors and contributed to the UK Cyber Security Council’s Professional Standards Working Group; work rooted in a simple belief that our profession grows when we invest in certification, training, standards, in each other, and in the next generation of practitioners.

None of this happens alone. To every mentor who opened a door, every colleague who challenged my thinking, and every volunteer I’ve had the honor of working alongside in digital technology communities – thank you from the depths of my heart. This award belongs to all of us who believe cybersecurity is, at its core, about protecting people.

Here’s to continuing the work on advancing digital trust, strengthening resilience, and building a safer, more secure cyber world.

Congratulations to all the ISC2 Global Achievement Award winners.

The UK’s National Cyber Strategy signals a more ‘proactive’ approach to cyber power

The UK government unveiled its long-awaited National Cyber Strategy yesterday, outlining how it plans to improve the resilience of UK institutions and businesses while protecting the country’s interests in ‘cyberspace’. The strategy signals a more interventionist stance from the government, experts told Tech Monitor, which has previously looked to the private sector for leadership. Its commitment to a ‘whole of society’ approach, meanwhile, risks overlooking the need for more diverse perspectives in the cybersecurity workforce.”

I added my quick two cents to a Tech Monitor article on the UK National Cyber Strategy 2022, which can be found here.

Then I provided a more detailed breakdown of the strategy for CircleID…

The 2016 UK Cyber Security Strategy was largely focused on deeper involvement by the government across a broad range of activities, including building cyber offensive capabilities, skills development across key sectors, enhancing coordination and incident response (including the creation of the National Cyber Security Center), promoting innovation, and incubating the UK cyber commercial sector. The 2022 strategy seeks to sustain and build upon the progress from 2016, but taking a ‘cyber ecosystem’ approach that integrates a broader range of stakeholder groups across society in developing cyber risk responses. Think of it as an acknowledgment that cyber security issues are so broad, complex and interlinked that they need to be knitted into the very fabric of national policymaking, including education strategy, regulatory/legal reform, foreign policy, and industrial policy, among others.

The government has come to terms with the fact that it doesn’t have the resources or the depth of skills to tackle all the UK’s cyber-related problems on its own and that private-sector leadership won’t necessarily achieve the desired outcomes. The 2022 Cyber Security Strategy signals the government’s intention to carve out key roles—coordinator, convener, and enabler—in the UK’s cyber ecosystem. The 2016 National Cyber Security Strategy received heavy criticism from the Public Accounts Committee, which maintained there was a lack of evidence and no solid business case to justify the £1.9 billion funding it received—making it nearly impossible to measure success. The ‘whole of society’ approach outlined in the 2022 document illustrates a deeper understanding of cyber issues and brings together the full range of cyber activities domestically and internationally into a seemingly cohesive vision with more measurable outcomes and outputs […]

Feel free to view the entire blog article on the CircleID website.