Margin of safety
Human Risk Management

Firewalls don't panic.
Policies don't get phished.
People do
Human Risk:
The Real Attack Surface
Most organisations treat culture as a training tick-box, an annual e-learning module and a phishing simulation, filed away and forgotten. Meanwhile the actual attack surface, how people behave under pressure, what they'll click, what they'll ignore, what they'll silently work around, sits unmeasured and unmanaged.
I help organisations treat human behaviour as what it actually is: a measurable, manageable security control. Not a soft add-on to the risk register. The missing line item on it.
About Gary
I'm a senior Security leader with over 10 years' cross sector experience spanning the NHS, higher education, insurance, finance, and legal sectors.
I've built and matured GRC and cyber security functions in highly regulated environments, with particular focus on embedding governance frameworks, risk management, security operations, training and awareness and third-party risk management.
I hold CISM and ISO 27001 Lead Auditor certifications, alongside a coaching and mentoring qualification, and I'm currently building independent thought leadership on human-centred security.

What I offer

Keynotes and workshops on human risk as an attack surface
Practical, evidence-led sessions for boards, security teams and staff audiences. I unpack why traditional risk registers miss the human dimension, and give attendees a way to see behaviour as something they can actually measure and manage, not just lecture people about.

Culture and behaviour-led risk frameworks that integrate with existing GRC structures
I don't ask you to bolt on a separate "culture programme." I build human risk into the frameworks you already run, ISO 27001, your existing risk register, your control environment, so behaviour is tracked and reported alongside every other risk, not off to the side.

Advisory support for building the risk-to-investment case for human-centred security
Culture change doesn't get funded on instinct. I help GRC and security leaders build the business case, linking behavioural risk to measurable outcomes, so investment in human-centred security stands up to the same scrutiny as any other control spend.

Want to know more?
Not sure of your current position?
Want to run an idea or problem by me?
Then get in contact....
....and let's see where your margin of safety is and what can we do to improve it.
“Your risk register is lying to you because it doesn't account for people."
Gary Simpson

