Now accepting advisory engagements

Cybersecurity Assurance for Critical Infrastructure.

20+ years protecting IT and OT environments for utilities, energy, and government. Now available to advise your organization.

Previously served as Head of IT & Cybersecurity Assurance — Dubai Electricity & Water Authority (DEWA)

Independent advisory engagements offered in personal capacity

Credentials: GICSP, ISA/IEC 62443 Expert, ICS612, OSCP, GPEN, GCPN, GCCC, C|CISO, CIA, CISA, CISSP, CISM, CGEIT, CRISC, CDPSE, CSXP, PMP, GCFE, OSWP, GXPN, CEH, CRTP, CORELAN, GRCP, GRCA
20+
Years of Experience
30+
Certifications
6
Service Lines
IEC 62443
OT Expert · CISA · CRISC

For

Built for the organizations that keep things running.

Utilities & Energy

Power generation, transmission, water networks. SCADA, ICS, IEC 62443.

Government & Public Sector

Critical national infrastructure, regulators, sovereign assurance frameworks.

Banking & Financial Services

Regulated GRC, ISO 27001, ISO 22301, internal audit, third-party assurance.

Enterprise & Boards

Cyber strategy, board briefings, M&A due diligence, post-incident reviews.

03 / Experience

Three decades. Six chapters.

From early ERP implementations to leading AI-driven assurance — every chapter compounds. The OT audit work in 2006 is the foundation that makes today's IIoT and Copilot governance possible.

  1. 1996–2006

    ERP & IT Foundations

    Pak Petrochemicals, Artistic Milliners

    Built foundations across ERP rollouts, IT operations, and process automation.

  2. 2006–2008

    OT Security Audits

    Pak Arab Refinery

    Hands-on SCADA/DCS audits across oil & gas — including pipeline pilferage controls.

  3. 2008–2010

    Big-4 Advisory

    Ernst & Young

    IT/OT strategy, SAP GRC, COBIT, and SOX engagements across multiple sectors.

  4. 2011–2020

    Head IT & Cybersecurity Assurance

    Dubai Electricity & Water Authority

    Designed the IT/OT audit program. Delivered the first SAP GRC implementation in the Middle East.

  5. 2021–2022

    GRC & Compliance Head

    Dubai Electricity & Water Authority

    Built the ISO 37301 compliance framework and digitized compliance operations.

  6. 2023–Present

    Head AI & Digital Assurance

    Dubai Electricity & Water Authority

    Leading AI/Copilot analytics, IoT, Cloud, and IIoT governance programs.

04 / Credentials

30+ certifications. Earned, not collected.

Each one represents real fieldwork — from offensive engagements to OT plant audits to board-level governance design.

Cybersecurity / Offensive

08
OSCP
GPEN
GXPN
GCPN
OSWP
CEH
CRTP
CORELAN

OT / ICS

04
GICSP
IEC 62443 Expert
ICS612
GCCC

Audit / Assurance

03
CIA
CISA
GCFE

Governance / Risk / Privacy

07
CISSP
CISM
CGEIT
CRISC
CDPSE
CSXP
C|CISO

GRC Programs

02
GRCP
GRCA

Project Management

01
PMP

05 / Selected engagements

Anonymized outcomes from 20+ years of practice.

Client identities are protected. Outcomes are real.

Designed and delivered the IT/OT Cybersecurity Assurance Program for a major Middle East utility — full coverage across IEC 62443, NIST CSF, and DESC ISR.

First integrated SAP GRC implementation (AC, PC, RM) in the Middle East.

Reduced audit cycle time by 25% using Power BI, Copilot, and automation.

Stood up a Compliance Department supporting transition from state-owned to publicly listed entity (SCA / DFM regulated).

Developed ISO 37301-aligned compliance framework leading to certification.

Reduced manual whistleblowing-case effort by 80% via digital channels.

Delivered cybersecurity assurance on oil pipeline operations — addressed pilferage and theft controls.

07 / How to engage

Four engagement models. Pick the shape that fits.

All commercials on request — sized to scope, sector, and the level of regulatory scrutiny involved.

Advisory Retainer

Monthly executive advisory, board prep, and on-call guidance.

Best for

CISOs, CIOs, and Audit Committees who need a sounding board year-round.

PricingOn request

Project Engagement

Defined-scope assessments, audits, and framework design.

Best for

Programs with clear deliverables — typically 4–16 weeks.

PricingOn request

Workshops & Training

Board briefings, executive cyber simulations, and OT security workshops.

Best for

Leadership teams that need to align fast on cyber posture.

PricingOn request

Certification Training (No Exam Required)

Multi-day cohort training on the body of knowledge for major IT/OT certifications (IEC 62443, GICSP, CISSP, CISM, OSCP and more).

Best for

In-house corporate programs and executive bootcamps focused on applied knowledge.

PricingOn request