Services

Senior technology leadership, scoped to what the firm actually needs.

Start with a fixed-fee diagnostic. Retained fractional leadership follows where the findings warrant it.

Fixed-fee entry points

Scoped diagnostics, priced and timed upfront. Each produces a single board-ready written report, with no obligation to continue into a retained engagement.

Cybersecurity diagnostic

Technology Risk Review

Control gaps, SOC readiness, and a prioritised remediation path across six review areas - control environment, identity and access, incident response, data and third-party exposure, human risk, regulatory mapping.

AED 28,000
Fixed fee · 3-4 days · report in 2-3 weeks
Discuss a review Download the PDF
Resilience diagnostic

Operational Resilience Baseline

Critical business services, preliminary impact-tolerance questions, and material dependency gaps, mapped against DFSA's proposed operational resilience framework.

AED 28,000
Fixed fee · 4-5 days · report in up to 4 weeks
Discuss a baseline Download the PDF
AI governance diagnostic

AI Governance Diagnostic

Tool exposure, policy gaps, and a prioritised adoption framework across six review areas - policy and data classification, tool exposure and shadow AI, authorisation workflow, AI register, supplier exposure, governance and regulatory mapping.

AED 28,000
Fixed fee · up to 4 days · report in 2-3 weeks
Discuss a diagnostic Download the PDF

Four areas. One point of accountability.

Each engagement is scoped to the specific need - from a focused diagnostic through to an ongoing fractional leadership arrangement, depending on the firm's stage, risk exposure, and regulatory pressure.

01

IT Leadership & Fractional CIO

Board-level technology leadership on a part-time basis. Covers IT strategy, team oversight, vendor governance, and delivery accountability - providing the senior function the business needs without the overhead of a full-time executive.

StrategyGovernanceVendor ManagementBoard Reporting
02

Cybersecurity Advisory

Independent assessment of the firm's security posture against recognised control frameworks, structured for UAE regulatory context. Covers control gaps, SOC readiness, incident response capability, and the practical steps required to move from exposure to defensible maturity. Informed by ISO 27001 and NIST CSF-aligned practice, mapped to DFSA control expectations - delivered as a prioritised, board-ready output, not a generic framework exercise.

DFSA AlignmentSOC ReadinessIncident ResponseISO 27001 / NIST CSF
03

Operational Resilience

End-to-end resilience programme design: service mapping, impact tolerance setting, RTO and RPO definitions, playbook development, and supplier continuity review. Structured to satisfy regulatory scrutiny and give the board a clear line of sight to the firm's actual exposure - not just what the documentation says.

Service MappingImpact TolerancesBCDRSupplier Risk
04

AI Governance & Policy

Structured framework for the governance of AI and generative AI tools across the business. Acceptable use policy, data classification, authorisation workflows, and ongoing oversight mechanisms. Designed to enable controlled adoption rather than blanket restriction - giving the firm a defensible position with the regulator and the board.

Acceptable Use PolicyGenAI RiskData ClassificationAI Governance Controls

Retained engagements

Retained work usually follows audit pressure, cyber exposure, or AI adoption reaching board level without a senior technology owner. Firms that act on a review's findings internally do so. Firms that want the findings owned and delivered retain one to three days per week, with direct accountability at board or committee level.

Every engagement is delivered personally. No associates, no handoffs, no subcontracting - the person in the boardroom is the person doing the work.

No software resale, no vendor commissions, and no managed services contract sitting behind the advice. When I recommend a control, a supplier, or a tool, there is no revenue attached to the answer.

Start with a conversation

A 30-minute call is enough to establish whether there is a fit and what the right starting point looks like for your firm.