Umhlanga, KwaZulu-Natal, South Africa
As a technology and information security leader with over two decades of experience, I specialise in building resilient, compliant, and intelligence-driven environments that safeguard organisations most valuable assets; their people, data, and reputation. My career spans the full spectrum of Governance, Risk, and Compliance (GRC), from establishing ISO 27001-aligned frameworks and driving PCI-DSS/PIN, GRDP and POPIA compliance, to leading enterprise-wide security initiatives that balance regulatory obligation with business agilities. Currently serving as Head of Business Solutions at IT Anywhere (Pty) Ltd, I bridge the gap between cybersecurity, business operations, and strategic growth. I lead multidisciplinary teams that deliver managed services in virtual Chief Information Officer (vCIO), Policy & Procedure Management (PPM), Security Awareness Training (SAT), and Reporting Intelligence ensuring our clients achieve measurable maturity across technology and governance pillars. Having guided numerous organizations through successful attestations of compliance (AoC) and security audits with Mastercard, VISA, and PCI authorities, I remain committed to embedding continuous improvement, data protection, and operational resilience into every layer of the enterprise. Core Competencies: ISO 27001 | PCI-DSS | PCI PIN | POPIA | GDPR | GRC | Cybersecurity Strategy | Information Risk | SOC / SIEM / SOAR / MDR | Policy & Procedure Management | Data Privacy | Leadership | Business Process Transformation | Security Awareness & Culture Development
The Business Solutions department manages business strategies, client reporting, policy frameworks, and strategic roadmaps, ensuring efficiency, compliance, and continuous improvement in ICT services. Reporting & Analytics The department delivers accurate and timely client reports, providing data-driven insights for decision-making. Responsibilities include analyzing reports, tracking recommendations, and supporting clients through the vCIO function. Continuous improvements enhance efficiency, identify trends, and enable proactive planning. vCIO & Strategic Planning Quarterly business assessments and client alignments ensure a structured IT review. Managing Quarterly Business Reviews (QBRs) bridges IT strategy gaps. A 12–36 month roadmap aligns IT with business goals while integrating compliance frameworks such as CIS, NIST, and GDPR. The department also oversees risk assessments, maturity models, and the full vCIO lifecycle for long-term IT success. Policy & Process Management (PPM) Developing and maintaining IT policies, the department ensures compliance with security and industry regulations. A structured roadmap defines training schedules, policy reviews, and compliance tracking. Policies align with client security postures, risk registers, and business goals, with policy-driven projects supporting industry standards. Security Awareness Training (SAT) Annual SAT campaigns enhance compliance and cybersecurity awareness through scheduled training, phishing simulations, and security initiatives. Training completion is monitored, and an audit-ready SAT report is maintained, with automated certificates issued for compliance.
• Manage, monitor, and report on the Security Operation centre (SOC) • Manage, monitor, and report on the Network Operation centre (NOC) • Assess risk and conduct root cause analysis to recommend, implement and/or design new features and functionalities to support compliance initiatives. • Manage implementation of any new compliance requirements for existing or new needs. • Manage all evidence collection activities relating to compliance. • Coordinate with all business units and the enterprise to obtain and validate evidence required for compliance and assessments. • Incrementally improve the evidence collection process and streamline evidence collection procedures. • Regularly communicate PCI DSS, PCI PIN and POPI requirements and the status of PCI DSS, PCI PIN and POPI compliance to relating business units and Exco. • Communicate regularly with assessors and adjust the compliance program as needed. • Coordinates with company and vendor SMEs to ensure adherence to program requirements. • Manage relationship of compliance needs in conjunction with needs of the other cyber departments. • Challenge and validates assessment decisions from both internal business units as well as external partners/vendors • Build and manage an ongoing Cybersecurity awareness training program to cater for various business units compliance requirements .
Banking Sector – African Resonance is a Tech / Logistics service and DashPay a Tech / Banking service. African Resonance is a market leader in South Africa’s national payment system through its privately owned terminal network Resonet. The Company promotes access to the Resonet network to companies and institutions to enable them to distribute their products and services via this terminal network. Examples include loyalty, retail management, pre‐paid, government social grant distribution products and the like.... I provide shared services for two companies African Resonance and DashPay which falls under one group: Capital Appreciation. Physical security • Develop, implement and adjust policies to ensure the physical safety of all visitors, employees, or customers to the organization's facilities; • Safeguarding of property and assets owned by the organization (i.e. equipment, stock, building, storage); • Oversees the administration and operation of the organization's security equipment- Alarm system, CCTV, Access control; • Monitoring of all above mentioned systems such as access control, access rights and time zones, arming and dis-arming of alarm system, alarm activations and armed responses; • Simulate security breaches to test the infrastructure, policies and procedures and provide remedies for any shortfalls; • Oversee the selection, testing, deployment and maintenance of security hardware and software products as well as outsourced arrangements; • Takes appropriate actions to ensure staff are properly trained on security and security systems as well as compliance requirements and equipped to manage potential issues or breaches. IT Security • Monitor and oversee usage relating to company systems by staff and third parties such as Internet usage, servers, application and infrastructures; • Leads and directs major investigations and responses to critical events that impact the organisation;