About

Detailed Biography

About Andrew

I build and scale high performing security and operations teams for organisations that cannot afford for things to break. I turn strategy into execution, remove ambiguity from how work gets done, and make sure decisions actually stick.

For almost 25 years I have worked across cybersecurity, data, and operations as a practitioner, analyst, executive, and board adviser. I have led global engineering, research, sales, marketing, and security teams through early growth, pivots, acquisitions, and integration on both sides of the Atlantic.

Today I serve as Chief Operating Officer and Chief Information Security Officer at Damovo, an international ICT provider. My remit covers operational execution, enterprise risk, and security strategy across multiple countries and business units. I am known for challenging leadership teams to confront awkward trade offs before incidents or growth expose the weaknesses.

What I Actually Do

People usually call me when something is messy, political, or starting to escalate and it is not clear who owns the problem. I specialise in turning vague intent into standards, processes, and guardrails so the organisation can execute at scale without relying on heroics.

That has meant leading threat and vulnerability research teams, building incident response and forensics capabilities, designing cloud and network security architectures, and aligning all of that with revenue, product, and customer expectations. I treat security as a business function with risk, cost, and customer impact, not a compliance ceremony or a collection of tools.

I write, speak, and advise on topics including security operations, incident response, forensics, threat intelligence, and how to make security programmes actually work in real organisations. My work and commentary have appeared in a range of business and technology press over the years.

Where I Have Been

I have held senior roles as a CISO, CTO, research director, and co founder across several cybersecurity companies. Before Damovo I led research, product, and security functions at firms focused on cloud security, threat intelligence, and data protection. Earlier in my career I worked as a security analyst and practitioner in higher education and financial services, which is where I learned what actually breaks in production.

Over the years I have authored several books on advanced security topics, contributed to the OpenStack project, and published a large body of research and conference material. I have spoken at industry events including Black Hat and many others around the world.

Outside Work

Outside of Damovo I split my time between family, coaching, and competitive sport. I am an internationally ranked competitive powerlifter, a certified rugby coach, and a strength and conditioning coach, and I hold multiple Texas State powerlifting records. These pursuits keep me honest about discipline, feedback, and the reality that progress is earned, not announced.

I live in Perth, Ontario, Canada, but spend a material amount of time working with teams and customers across North America and the EU. If you want to talk about security, operations, coaching, or how to make complicated things run properly, you can reach me through the contact page on this site.

Scroll to top