CISO • Board & executive leadership • Transformation • Resilience

Security leadership for growth, resilience and change.

I lead security across the full maturity curve: establishing functions after carve-outs, stabilising complex environments and strengthening established programmes in PE-backed, listed and digital businesses.

I translate cyber risk into clear decisions, accountable delivery and measurable outcomes. My approach combines pragmatic controls, transparent reporting and visible progress across resilience, cloud, identity, third-party risk, AI governance and secure transformation.

Board & executive leadershipSecurity transformationDigital platformsAI governanceResilience & third-party risk
Mantas Marcinkevicius executive portrait
Career evidence

Executive track record across scale, outcomes and sectors

Current role

CISO

Global digital data platform

Group-level assurance

60+

Businesses across a federated listed group

Enterprise assurance

30,000

Assets across group control and tooling coverage

Annual savings

£200k

Supplier and tooling consolidation

Critical vulnerability exposure

80%

Reduction through accountable remediation

Career experience

  • Lloyd’s List IntelligenceDigital data platform
  • Hyde GroupMulti-entity organisation
  • Associated British FoodsListed global group
  • Thomas Cook GroupTravel and digital commerce
  • RNIBTechnical foundations
Leadership range

Leadership across the full maturity curve

Different organisations require different interventions. My approach is to understand what already works, address material weaknesses and build the operating model needed for the next stage of growth.

01

Establish and scale

Established and matured a dedicated security function following divestment, covering strategy, governance, assurance, resilience, cloud, identity, suppliers and 24/7 security operations.

02

Stabilise and transform

Inherited a challenging brownfield environment and rebuilt governance, supplier delivery, security operations, control maturity and executive confidence.

03

Strengthen established programmes

Contributed within large listed-company environments across group assurance, travel, digital commerce, retail, food, manufacturing, operational environments and OT assurance.

04

Lead through influence

Delivered through direct teams, internal technology leaders, engineering, legal, procurement, business owners, specialist consultancies and managed security providers.

Board and executive leadership

Clarity on the risks that require executive attention.

Formal Board papers and presentations, direct Chairman engagement, executive and private-equity governance, and senior crisis and resilience exercises.

I build executive confidence through a transparent reporting cadence: clean dashboards, a small number of material cyber pain points, clear ownership and visible progress. The objective is to tell the cybersecurity story clearly enough that executives can make timely decisions on risk, investment and resilience.

First 90 days

How I enter an established mandate

Preserve what works, expose what matters and create a credible route to the next stage of maturity without introducing unnecessary disruption.

0–30

Understand and align

  • Meet the Board, executives, security team and critical business owners
  • Confirm critical services, digital revenue dependencies and material risks
  • Assess the operating model, capability, culture and third-party dependencies
  • Establish where confidence is justified and where evidence is weak

31–60

Prioritise and mobilise

  • Agree the highest-value risk and resilience priorities
  • Clarify ownership, decision rights and delivery cadence
  • Align identity, cloud, supplier, AI and resilience activity
  • Resolve immediate accountability or control gaps

61–90

Evidence and scale

  • Test recovery and executive incident decision-making
  • Establish concise Board and executive reporting
  • Present a two-quarter roadmap with trade-offs and investment options
  • Strengthen metrics, accountability and sustainable delivery
Executive value

Outcomes over optics

Board-ready security leadership

Translate cyber risk into decisions, ownership, investment priorities and measurable delivery. Use clean dashboards to show material risk movement, focus executive attention and prompt timely action.

Resilience for digital and operational businesses

Identity-led controls, pragmatic cloud guardrails, third-party assurance and recovery capability designed around critical services and genuine operating constraints.

AI governance and secure innovation

Enable responsible AI adoption through clear ownership, data controls, access boundaries, human approval and auditable decision-making.

Speaking and recognition

External perspective, grounded in delivery

Top 100 CISO, Computing 2024IT Leaders 100, 2025Infosecurity EuropeCISO 360Visions CISO Summit

Contact

For organisations navigating growth, transformation or heightened scrutiny

Executive cyber leadership, strategic advisory and speaking conversations focused on measurable outcomes, resilient operating models and sustainable change.