Chris Leather, CISM

Global Director of IT Risk & Security (CISO) at Clifford Chance LLP

Woking, England, United Kingdom

About

As Global Director of IT Risk & Security (CISO equivalent) at a leading international law firm, I work at the intersection of cybersecurity, AI, risk, digital trust, and business strategy. I lead global security, resilience, and governance programmes that protect client confidentiality, strengthen operational continuity, and enable strategic growth. My role sits at the convergence of business strategy, client trust, and technology transformation, ensuring the firm can innovate securely, meet evolving regulatory expectations, and maintain the confidence of clients, partners, and stakeholders worldwide. My remit includes building and scaling a high-performing security function, securing executive sponsorship for complex multi-million-pound transformation portfolios, and delivering measurable, benchmarked, and risk-prioritised outcomes across global operations. I translate increasingly complex cyber threats, regulatory requirements, AI governance challenges, and client assurance expectations into clear, commercially aligned decisions that strengthen resilience and support business performance. Within the legal sector, I view security not as a control function but as a strategic enabler of client trust, operational excellence, market credibility, and competitive advantage. Increasingly, this means helping the business harness AI securely and responsibly, transforming emerging technology from a source of risk into a driver of innovation, productivity, and value. I bring a forward-looking perspective to modern security operations, integrating AI-enabled analysis, intelligent automation, data-driven decision support, and adaptive security controls into core operational and governance capabilities. This approach accelerates assurance activities, improves decision quality, strengthens resilience, and enables teams to operate with greater speed, precision, and business alignment. As a trusted advisor to senior leadership, partners, and clients, I help shape security strategy as a business enabler and differentiator in the global legal market. My experience spans cybersecurity strategy, enterprise risk management, operational resilience, security transformation, client assurance, regulatory alignment, and the practical application of emerging technologies within regulated professional services environments. I contribute to the wider industry as a conference chair and speaker, roundtable facilitator, and advisory board member, supporting the advancement of cybersecurity, operational resilience, digital trust, and responsible AI practices across the sector.

Experience

  • Global Director of IT Risk & Security at Clifford Chance
    May 2017 - Present · 9 yrs 3 mos

    Experienced CISO across diverse sectors who brings a strong focus on business enablement and achieving objectives. Practiced at creating new security functions aligned with the rest of the business and taking existing security teams to high maturity levels at pace in multiple worldwide locations. Significant budget responsibility.

  • Group Head of Information Security at Balfour Beatty Plc
    Jun 2010 - May 2017 · 7 yrs

  • Owner at Tay Technologies Ltd
    Apr 2001 - Jun 2010 · 9 yrs 3 mos

    Freelance consultant assisting clients with their information security needs at strategic and tactical levels.

  • Freelance Security Consultant – ISO 27001 at Security services company
    Apr 2010 - May 2010 · 2 mos

  • Freelance - Interim Head of Global IT Security Risk & Technical Assessment at Royal Bank of Scotland
    Jan 2010 - Mar 2010 · 3 mos