Interim CISO · Cybersecurity · AI Governance · Enterprise Architecture

Senior security leadership,
without the twelve-month hire.

Athencis provides interim and fractional CISO leadership, cybersecurity consulting and enterprise architecture — delivered by a Global CISO who has held the role at global banks, pharmaceutical manufacturers, healthcare SaaS and critical national infrastructure. Not a bench. Not a framework deck. The person who does the work.

Recent mandates2024–2026
Interim CISO Leadership of the global security organisation for a PE-backed SaaS group operating across the UK, Europe, the US and Asia: team, budget and vendor ownership, AI governance, public-sector compliance, successful SOC 2, ISO 27001 and Cyber Essentials Plus audits, and the groundwork for GovRAMP and TX-RAMP authorisation. Healthcare SaaS
AI Governance & Security Enterprise AI governance framework including agentic AI: governance processes, model cards and an AI Architecture Review Board — plus IAM for AI, SIEM for AI and AI detection & response. Global SaaS
IAM Transformation Identity and access programme across nine business entities: maturity assessment, IAM standard, IGA architecture and policy design. Global insurer
OT Authentication Strategy Phishing-resistant, passwordless authentication for operational technology across five global manufacturing sites. Pharmaceutical
Fractional CISO Security leadership for a building products manufacturer — plant and concrete fabrication: NIST CSF assessment, OT risk analysis and OT security architecture aligned to IEC 62443 and ISO 27001. Manufacturing / OT
Fractional CISO Security leadership for a regulated fintech startup: NIST CSF programme with FCA and PRA regulatory alignment, GDPR compliance and DORA operational resilience readiness. Fintech
Data Architecture & Governance Data architecture and data governance framework design for a major drinks manufacturer: target data model, governance operating model, ownership and stewardship, and analytics platform strategy. FMCG / Drinks
Technology Strategy End-to-end technology strategy for a renewable energy company: capability assessment, digital roadmap, cloud adoption and investment prioritisation aligned to rapid business growth. Renewable Energy

Some of the brands we've helped — in senior security and architecture roles

Logos of organisations Athencis has helped, including Fidelity International, Wella, Chaucer, Monument Re, Aviva, China Re, London Stock Exchange Group, AQA, Travis Perkins, British Gas, Hive, BP, Islands Energy Group, National Gas, Centrica, Gestetner, The Open University, Mowlem, Pop Media, Charity Commission, Pizza Hut, BBC, Sky, BBC iPlayer, ITV, Channel 4, Racing TV, HSBC, Acas, Carillion, Refinitiv, Home Retail Group, Argos, Yum!, Pepsi, Wagamama, the AA, SIS, Healthspan, Coventry University, Bupa, Sandoz and RLDatix

…and others across pharmaceuticals, healthcare, insurance and critical national infrastructure.

Recent work

What we've actually delivered lately.

Not case studies polished into fiction — a running list of real deliverables from recent engagements, anonymised where the work is confidential. If the piece of work you need looks like one of these, we've done it recently enough to do it fast.

  • Negotiated a $2M saving on an enterprise SIEM platform renewal
  • Negotiated 50% off a compliance automation platform and 45% off an application security platform
  • AI governance framework including agentic AI, governance processes and model cards
  • Established an AI Architecture Review Board (AI ARB) and review processes
  • AI security: IAM for AI, SIEM for AI and AI detection & response (AIDR)
  • End-to-end security architecture and design for a global reinsurance business
  • Proof of value of Palo Alto Cortex XSIAM across five use cases for a national energy business
  • Identification and remediation of gaps in a Sentinel SIEM for a CNI business
  • Complete security testing strategy for a national energy business
  • Major incident tabletop exercise and remediation plan
  • Data architecture & governance framework for a drinks manufacturer
  • Technology strategy for a renewable energy company
  • Interim CISO for a healthcare SaaS group
  • SIEM logging & telemetry strategy
  • SIEM logging & telemetry detailed design
  • Selection & procurement of risk and compliance tooling
  • Risk & compliance tooling strategy
  • Risk & compliance tooling roadmap
  • RFP for SIEM platform
  • Design of SIEM platform
  • Implementation of SIEM platform
  • Recruitment of CISO
  • Design of CIS Benchmark strategy
  • Implementation of CIS Benchmarks & analysis of findings
  • Roadmap & strategy to remediate CIS findings
  • Design of identity trust model for a 100,000-person business

What we do

Three practices. One standard of judgement.

Most consultancies sell you a menu. We do three things, deeply, because they are the three things that decide whether a security and technology function actually works.

Security leadership

An experienced CISO in the chair from day one — interim while you hire, or fractional for the long haul. Board reporting, budget ownership, team leadership and the hard calls in between.

  • Interim & fractional CISO
  • Security strategy and operating model
  • Board and investor reporting
  • Security team build, recruitment and succession
  • Regulator and auditor relationship management
  • Programme, budget and vendor ownership — $2M saved on one SIEM renewal
  • M&A security due diligence
  • Incident and crisis leadership
Explore security leadership →

Cybersecurity consulting

Assessment, architecture and compliance work grounded in what regulators and auditors actually accept — and what attackers actually do.

  • Risk & maturity assessment (NIST CSF, ISO 27001)
  • Compliance: SOC 2, GovRAMP, NIST 800-53, HIPAA, HITRUST, NCSC CAF, DORA, GDPR & global data privacy
  • Identity & access management, IGA and PAM
  • Passwordless & phishing-resistant authentication, IT and OT
  • SOC design, SIEM and detection engineering
  • Threat modelling and cyber threat intelligence
  • Data protection, classification and DLP
  • AI governance, AI ARB and AI security (ISO 42001)
Explore cyber consulting →

Enterprise architecture

Strategy and architecture that shows its own workings — so the roadmap survives contact with the budget, the board and the engineers.

  • Technology & digital strategy, business capability models
  • Operating model assessment and design
  • Application, technology & integration portfolio catalogues (4/5 Rs)
  • Cloud migration strategy, FinOps & cloud IAM
  • Data architecture, glossary, warehouse & hub design
  • API-led integration strategy and design
  • Modernisation of legacy estates
  • Mergers, acquisitions, divestments & carve-outs
Explore architecture →

Secure, governed AI

Governing AI before it governs you.

Your teams are already using AI — in products, in pipelines and, increasingly, as autonomous agents acting on your systems. The question your board, your customers and your regulators are asking is whether any of it is governed. We've built the answer from the CISO's chair, not the vendor's.

This is a security practitioner's view of AI: governance that people actually follow, and controls that treat models and agents as what they are — new identities, new attack surface, and new things to monitor.

Govern

AI governance framework

  • Enterprise AI governance framework, including agentic AI
  • Governance processes: intake, risk tiering, approval and review
  • Model cards and AI system inventory
  • AI Architecture Review Board (AI ARB) and operating cadence
  • ISO 42001 alignment

Secure

AI security

  • Identity & access management for AI: agents, service identities, least privilege
  • SIEM for AI: logging, telemetry and detection for models and agents
  • AI detection & response (AIDR)
  • Security review of AI tools, pipelines and agentic workflows
  • Prompt-injection, data-leakage and model-abuse controls

How we work

Evidence in weeks, not decks in months.

Every engagement follows the same discipline: understand the whole picture, intervene where it counts, and leave behind a plan that proves its own progress. See a typical engagement in detail →

01 — Understand

Assess holistically

A rapid, structured view of your security and technology estate — risks, maturity, spend and people — before anyone recommends anything.

02 — Target

Intervene precisely

A small number of interventions chosen for impact, not billability. We tell you what not to do as readily as what to do.

03 — Deliver

Lead the work

We take ownership — running the programme, the audits, the vendor negotiations and the difficult conversations, alongside your team.

04 — Prove

Show the evidence

Plans that show their own workings: measurable milestones, audit-ready evidence, and a handover your permanent team can run with.

About Athencis

Led by a Global CISO, not a partner track.

Athencis is the consulting practice of a Global CISO and chief architect with three decades across banking, insurance, pharmaceuticals, healthcare SaaS, consumer goods and critical national infrastructure. When you engage Athencis, that experience is who turns up.

CredentialsCISSP · TOGAF 9.2 · SABSA · PRINCE2
Roles heldGlobal CISO, Group CISO, Chief Security Architect, Chief Architect — FTSE-scale and global organisations
SectorsBanking, insurance & reinsurance, pharma, healthcare, healthcare SaaS, energy & CNI, public sector, media & broadcasting, education, retail, FMCG, restaurants, consumer goods, construction, IoT
ClearanceSC-cleared engagements delivered for UK critical national infrastructure
BaseOxfordshire, UK — working nationally and internationally

“Hiring a big firm gets you a partner at the pitch and a graduate at the keyboard. Hiring Athencis gets you the same person at both.”

— The Athencis operating principle

Get in touch

Tell us what's keeping you up at night.

A first conversation costs nothing and usually saves something. We'll tell you honestly whether we're the right fit — and if we're not, who is.

Emailsales@athencis.co.uk
LinkedInPeter Watson
RegisteredAthencis Ltd — England & Wales