Building Secure Agents for Public Sector Services
Agentic automation security curriculum.
Twelve years securing the world's most regulated industries, banking, insurance, defense. Now architecting the security perimeter for autonomous AI agents, MCP infrastructure, and the cloud platforms they run on.
From Anthropic AI Fluency to NVIDIA Generative-AI LLMs, ISACA CISM/CRISC, and the full Microsoft Cybersecurity Architect & AWS Security tracks.
Agentic automation security curriculum.
ud6tp3nbypsc
bqps2dqo8oaa
qn62hbyfx7ky
cyrei883psj9
pok9weot8j3p
EAB47D8F4EDC1058
D7EF2C23EF149EA4
A6B7126C06F9C786
8B08474D2BE410E8
BD23427E7A5DF944
B7635962A1631A02
H344-1450
6S5MRC92DFR11RCW
FZN3QCE2J21E1N5F
WH8FRT11JNBQQXCM
4NBMCXH12EVEQB36
AWS-ASA-14402 · 3Z8KF6HK22VQQ83R
From securing autonomous AI agents to underwriting cyber risk for global insurers, my work sits at the intersection of regulated industries and emerging AI.
Securing autonomous LLM agents end-to-end: MCP servers, tool-call authorization, prompt-injection defense, sub-agent isolation, and runtime guardrails.
Signature practiceOperationalizing ISO/IEC 42001, NIST AI RMF and the EU AI Act. Bringing Anthropic's AI Fluency Framework into the enterprise risk register.
Multi-cloud security architecture for AWS, Azure and GCP. Global Prisma Cloud deployment at AXA. Cloudflare estate at Thomson Reuters. Hardened blueprints, IaC and SRE practices.
Founder & CEO of Rankiteo, the first AI-powered cyber underwriting desktop platform. Pricing, exposure and portfolio analytics for insurers and reinsurers.
ISO/IEC 27001 group certifications, SOC 2, HIPAA, DORA, NIS2, UAE & KSA PDPL. Built the GRC program at Seddiqi Holding and the BNP Paribas maturity roadmap.
Published OWASP research in Hakin9. Pentesting, exploit prediction, attack-surface intelligence and the Rankiteo Cyber Incident Chronicle (100k+ incidents).
From ISO/IEC 27001 to the EU AI Act, my engagements bridge engineering and regulation. I translate frameworks into deployable controls, and prove them with measurable assurance.
Hands-on roles, from Vice-President at Swiss Re to Deputy CISO at the BNP Paribas Asset Management group, and now CEO of an AI cyber-underwriting company.
Cyber strategy and ISMS for a Southeast-Asia asset-backed securities platform (SC Ventures · Standard Chartered).
Building the world's first multi-OS AI cyber-underwriting desktop platform. Cyber ratings, third-party risk, exposure modeling, and MCP-native distribution to Cursor, Claude Desktop, ChatGPT and n8n.
Group ISO/IEC 27001 certification program across the holding. Risk register, Statement of Applicability, UAE & KSA PDPL alignment for every department.
Built a NIST-based cybersecurity program from the ground up. After BNP Paribas acquisition, drove the maturity transformation from 0% to 30% within the group framework.
Technical lead for the worldwide rollout of Palo Alto Prisma CSPM across every AXA entity. Aligned global standards with local regulatory constraints.
Security architecture gatekeeper within enterprise architecture governance. Global Cloudflare deployment. Cyber-underwriting advisory bridging engineering and insurance.
Security by design across the enterprise. Architecture review for every major program. Reusable security blueprints across cloud, application and infrastructure domains.
Defined and enforced the cloud security framework for the bank. Risk-based cloud governance and security-by-design for every cloud initiative.
Cloud migrations under PCI-DSS, HIPAA and regulated workloads. IaC, hardened blueprints, vulnerability automation, native cloud SSO.
End-to-end advisory and implementation across the agentic security stack, from boardroom strategy and architecture blueprints to production-grade guardrails on Azure AI Foundry, LangGraph, NeMo, SageMaker and Prisma Cloud.
Boardroom-level diagnostic of your AI agent estate. Target architecture, regulatory posture, and the 12-month roadmap to get there.
Forward-deployed engineering on your stack. Guardrails, sub-agent isolation, tool authorization, Langfuse observability, shipped to production.
Independent agentic security audit. Red-team prompt injection, tool-chain abuse, data exfiltration. Boardroom-ready evidence pack.
Anonymised summaries of recent missions across cyber insurance, multi-cloud security and group GRC. Details vary by industry and are kept deliberately broad to respect client confidentiality.
Insurers and reinsurers needed real time, evidence based cyber risk data to replace static questionnaires and accelerate the pricing workflow.
Designed and shipped a multi OS desktop application backed by an AI rating engine, with MCP native distribution to common assistant clients and an underlying incident intelligence corpus.
A production grade platform recognised across the cyber insurance market.
A multinational insurer operating across dozens of entities had a heterogeneous cloud security posture and no unified visibility.
Technical lead for the global deployment. Cross entity workshops, alignment of group security standards with local regulatory constraints and translation into implementable controls.
A single CSPM signal across the entire group, with regulatory alignment per jurisdiction.
A newly acquired entity needed a formalised cyber programme aligned to the acquirer's group framework, with measurable, defensible evidence of progress.
Built a NIST based cybersecurity programme from the ground up. Controls, policies and procedures, risk register, structured reporting to group level stakeholders.
Validated maturity progress within the acquirer's framework.
A multi business holding with no unified information security management system, operating under regional data protection laws.
High level designs, application level IT risk assessments, group policy framework, Statement of Applicability, and alignment to regional regulatory requirements.
Group wide ISO 27001 readiness with structured assurance per department.
A global enterprise required consistent security by design across every major digital initiative.
Acted as security architecture gatekeeper within enterprise architecture governance, with reusable blueprints across cloud, application and infrastructure domains.
Accelerated secure delivery and stronger, more consistent control maturity.
An emerging investment platform needed senior cyber leadership to define its information security strategy and ISMS from day one.
Fractional CISO engagement covering target operating model, risk appetite, control catalogue and the regulatory roadmap, in coordination with a global banking parent.
A defensible cyber posture, ready for investor and regulator scrutiny.
OWASP vulnerability research, an early social media search engine recognised at the highest level, and ongoing coverage of the agentic cyber underwriting work.
In depth research on OWASP based vulnerabilities affecting major platforms, published in a renowned international IT security magazine.
Built an early social media search engine extracting signal from more than twenty networks. Recognised as a top national IT project of the year and presented to top CEOs and to the French Minister of Defense.
Featured commentary on AI driven cyber underwriting and data driven cyber insurance in leading international reinsurance media.
Open documentation and integrations for an MCP native cyber rating server, deployable in mainstream assistant clients and automation platforms.
Listed as a reference MCP server for cyber rating workflows in one of the leading MCP discovery directories.
Legacy security was built for humans clicking buttons. Agents click thousands per minute, call external tools, spawn sub-agents and chain decisions across systems. The blast radius is no longer a session, it's a workflow.
My work re-anchors the perimeter at the place where intent meets execution: the tool call. I design authorization, observability and policy guardrails that make autonomous agents auditable, reversible and trustworthy at enterprise scale.
"In the agentic era, the question isn't can the AI take an action. It's should it, and can we prove it after the fact."
Short answers to the questions that come up most often from boards, CISOs and AI platform teams scoping their first agentic security engagement.
Agentic Security is the discipline of securing autonomous AI agents and the infrastructure they call into. Unlike a chatbot, an agent reasons, plans, invokes tools, spawns sub agents and chains decisions across systems. Each tool call is an executable action with real world impact, which means the security perimeter must move from the user session to the tool invocation itself. With the rapid adoption of Model Context Protocol, LangGraph, LangChain and frameworks like Azure AI Foundry, enterprises now ship agents into production faster than their security teams can catch up. Agentic Security is what closes that gap.
Traditional LLM security focuses on the prompt and the model output: jailbreaks, prompt injection, hallucinations, data leakage at inference time. Agentic Security extends that perimeter to everything the agent can do once it has produced a plan, including authorization of tool calls, isolation of sub agents, observability of multi step workflows, reversibility of actions, and red teaming against tool chain abuse and data exfiltration. The blast radius is no longer a single response but an entire workflow.
Three primary engagement models. Strategy: a board level diagnostic of your AI agent estate with a target architecture and a twelve month roadmap. Build: forward deployed engineering with your teams to implement guardrails, sub agent isolation, tool authorization and Langfuse observability in production. Assure: an independent agentic security audit including red teaming and a regulatory mapping pack ready for boardroom review. Fractional CISO engagements are also available for emerging platforms.
Regulated industries with high stakes, including banking, insurance and reinsurance, asset management, financial information providers, defense, healthcare, and the public sector. Twelve years of engagements span Europe, the GCC and Asia, with hands on experience for Swiss Re, AXA, BNP Paribas, Standard Chartered, Thomson Reuters, Société Générale, Seddiqi Holding, NusaVest, Thales, Dassault Systèmes, Veolia, Baxter and Gemalto.
ISO/IEC 42001 for AI management systems, NIST AI Risk Management Framework, and the EU AI Act for AI specific governance. ISO/IEC 27001 and 27701, SOC 2 Type II, HIPAA, PCI DSS, DORA, NIS2, and regional regimes such as UAE PDPL, KSA PDPL and GDPR for information security and data protection. Engagements consistently translate these frameworks into deployable controls rather than paperwork.
Based across Singapore, Dubai, Paris and Palo Alto, with active engagements across three continents. Most work is delivered remotely, with on site visits scoped to the engagement. Typical projects run from a few weeks for a strategy or audit, to multi quarter programmes for full builds and fractional CISO mandates.
A short scoping call, typically thirty minutes, no commitment. The call clarifies your agent estate, your regulatory exposure and the outcome you need. Most engagements start with a structured diagnostic and a written proposal within ten working days.
Boards, CISOs, insurers and AI platform teams, if you're shipping autonomous agents, multi-cloud workloads, or building cyber-underwriting capability, I can help.