Available for cyber due diligence & transaction advisory mandates

Cybersecurity due diligence
that prices the risk,
not just flags it.

Independent cyber and digital trust diligence for private equity, investment committees and risk advisory firms — pre-acquisition red flags, confirmatory diligence, post-close remediation and exit readiness, across IT, OT, IoT and AI environments.

Pre & Post-Acquisition Diligence  ·  Technology Risk  ·  AI Governance  ·  Board Advisory
UK CISO of the Year 2020
UK Cyber Security Hall of Fame
0 material breaches across 16 CISO tenures
Global C|CISO of the Year, Finalist
Michael J. Loginov
Michael J. Loginov
Managing Partner · Cyber Due Diligence & Transaction Advisory
British citizen · Based in Asia
Track Record

Thirty years. Seventy countries.
Zero material breaches.

0
Cyber maturity & risk assessments delivered
0
Board & audit committee presentations
0
Material breaches across all tenures
30+Years executive leadership
70+Countries of operation
16Global, Group & Interim CISO appointments
18Major transformation programmes
US$1bn+Cybersecurity budget oversight
5Major cyber recovery programmes
US$1.2bn+Strategic transformation advisory
88Senior consultants led as UK Managing Director, DNV (Det Norske Veritas)
200Direct reports at peak
2,000Extended programme teams
Profile

Board-level judgement,
operator credibility.

Michael (“Mike”) Loginov advises private equity sponsors, investment committees and risk advisory firms on cybersecurity due diligence, technology risk and AI governance across the transaction lifecycle.

He brings more than thirty years of international executive leadership to that work. Across approximately sixteen Global, Group and Interim CISO appointments and eighteen major enterprise transformation programmes, he has delivered more than one hundred Board and Audit Committee briefings in over seventy countries — spanning IT, OT, IoT and AI cybersecurity risk, from securing the smart and cognitive city to industrial manufacturing and critical national infrastructure.

His experience combines executive leadership within multinational organisations with consulting expertise gained through Hewlett-Packard, Grant Thornton and Control Risks. He has advised organisations whose combined annual revenues are measured in the trillions of dollars, overseen budgets exceeding US$1 billion and conducted more than 150 executive cyber maturity, governance and strategic risk assessments, from SMEs to international conglomerates and national governments.

He has operated inside sponsor-backed environments on both sides of the table: Executive Director, Cybersecurity at Systal Technology Solutions, an Inflexion Private Equity-backed platform, and Group CISO at NEOM, backed by Saudi Arabia’s Public Investment Fund. Earlier, as UK Managing Director of DNV (Det Norske Veritas), the Norwegian certification and assurance body — the equivalent of Lloyd’s in its field — with revenues measured in billions of euros, he led a practice of 88 senior consultants conducting maturity assessments and issuing ISO 27001 certifications; he founded and ran the Ascot Barclay Group for fifteen years before its sale via management buyout, and has served as a technology company CEO.

That operating history is the point: it is what allows a finding to be expressed as a cost, a timeline and a decision, rather than a risk rating. He currently serves as Non-Executive Chairman and investor in a Thai functional food business, maintaining an active board seat alongside his advisory practice.

Transaction Focus

Cyber and digital trust diligence for investment committees and private equity sponsors, pre- and post-acquisition.

Sponsor-Backed Experience

Executive roles inside Inflexion Private Equity and Public Investment Fund-backed businesses. Understands the sponsor’s clock and the value-creation plan.

P&L Leadership

UK Managing Director of DNV (Det Norske Veritas) leading 88 senior consultants issuing ISO 27001 certifications; founder and CEO of Ascot Barclay Group, sold via MBO after fifteen years.

Board-Level Perspective

Over one hundred Board and Audit Committee briefings across organisations in more than seventy countries.

Operator Credibility

From sovereign-scale programmes to industrial crisis recovery, with zero material breaches across all tenures.

Recognition

UK CISO of the Year 2020 · UK Cyber Security Hall of Fame · Nominated Global C|CISO of the Year (Finalist) · Author, CISO: Defenders of the Cyber Realm, Cyber Book of the Year.

Working with Investors

Four points in the deal
where cyber decides value.

Engagements are structured around the pace of the transaction and sized to the mandate — from a five-day red flag screen to a full post-close remediation programme. Delivered on-site or remotely across Asia, Europe and the Middle East.

Pre-LOI

Red Flag Screening

Rapid outside-in read on a target before terms are set.

  • Breach and incident history
  • Regulatory and data exposure
  • Early deal-breaker identification
Diligence

Confirmatory Diligence

Findings quantified in terms an investment committee can price.

  • Governance and control maturity
  • Technical debt and remediation cost
  • OT / IoT / AI risk exposure
Post-Close

First 100 Days

Turning diligence findings into a de-risked asset.

  • Priority remediation sequencing
  • Governance and PMI integration
  • Interim CISO or M&A oversight
Exit

Exit Readiness

A cyber narrative that survives buyer-side scrutiny.

  • Evidenced security maturity
  • Buyer diligence rehearsal
  • Valuation protection
The Difference

Most diligence tells you what’s missing.
I can tell you what it costs to fix.

Built it, not just reviewed it

Sixteen Global, Group and Interim CISO appointments, including greenfield builds at sovereign scale. Remediation estimates come from having run the programmes, not from a benchmark table.

Commercial, not just technical

Over one hundred Board and Audit Committee briefings. Findings arrive as value at risk, cost to remediate and time to defensible — in language investment committees already use.

Full estate, not just IT

IT, OT, IoT, ICS and AI. Industrial manufacturing, critical national infrastructure, energy, pharma, 5G and the smart and cognitive city — where the un-priced risk usually hides.

Crisis-tested

Five major cyber recovery programmes, including a breach that halted production and threatened insolvency, restored to full capability in six months. I know which findings are genuinely existential.

Independent and discreet

No product to sell, no managed service to upsell, no downstream remediation contract to protect. The recommendation is the deliverable.

Client-facing at partner level

Comfortable in front of a Board, an investment committee or a target’s management team — including the difficult conversation where the finding changes the price.

Selected Transaction Outcomes

Proof, not promises.

Situation

A significant cyber breach halted production and placed the business at risk of insolvency.

Action

Retained through a leading risk consultancy as independent crisis lead; directed containment, Board-level crisis communications and the rebuild of compromised OT and IT infrastructure.

Outcome

Full operational capability restored within six months, with sustainable controls embedded and enterprise value preserved.

Situation

A £150 million private equity-backed platform required enterprise-grade security capability to compete for global clients.

Action

Built a 54-strong cybersecurity function from a blank canvas within six months, spanning IT/OT security, SecOps, CSIRT and Zero Trust services across more than thirty-five countries.

Outcome

Won and delivered Board-level security mandates for Fortune 500 and financial institutions aligned to DORA, directly supporting the platform’s growth thesis.

Situation

A national German banking transformation programme, with an opening contract value exceeding US$1 billion, carried security-critical delivery risk.

Action

Strategic cybersecurity and CISO advisor, shaping the security workstream and executive risk position, working with the client-side CISO to shape the tender and deliverables.

Outcome

Delivered the firm’s largest cybersecurity refresh for a major European bank, protecting programme value and client confidence.

Situation

A sovereign wholesale 5G programme required independent cyber assurance over the selection of its sole network equipment provider.

Action

Advised alongside a large European telco team on the cybersecurity dimension of the vendor selection process, assessing supply chain, national security and operational risk.

Outcome

A defensible, evidence-based vendor decision for critical national telecommunications infrastructure.

Evidence Base (Examples)

Sovereign scale to
crisis recovery.

The environments behind the diligence — each one an estate Mike has operated, secured or recovered rather than only reviewed.

NEOM
KSA
Executive Director & Group CISO
Inaugural Group CISO for one of the world’s largest development programmes, reporting to the Group CEO. Built the cybersecurity authority, governance framework and SOC from greenfield, leading Cognitive City cyber strategy across sixteen sectors spanning IT, OT, IoT and ICS, working with PIF and National Security and Governance teams.
Dept. for Work & Pensions
UK Government
Interim Programme Director · SCS2
Reporting directly to the Secretary of State across one of Europe’s largest digital government environments. Directed programme accountability across departments managing an annual expenditure footprint exceeding £150 billion, including oversight of the Universal Credit launch.
Control Risks
Germany
Interim Executive · Breach Recovery
Executive cyber leadership within one of the world’s leading specialist risk consultancies. Retained as an independent crisis recovery specialist following a significant industrial cyber breach, restoring full operational capability within six months.
Hewlett-Packard
USA / UK
Global Cybersecurity & CISO Advisor
Strategic cybersecurity and CISO advisor across multiple key accounts, including a national German banking transformation programme with an opening contract value exceeding US$1 billion.
Digital Nasional Berhad
Malaysia
Cybersecurity Advisor · National 5G
Advisory role working with a large European telco team, based in Southeast Asia, on the vendor selection process for cybersecuring Malaysia’s wholesale 5G network. DNB selected Ericsson as its sole network equipment provider.
Systal Technology Solutions
Scotland · PE-Backed
Executive Director, Cybersecurity
Executive cybersecurity leadership within a £150 million platform backed by Inflexion Private Equity. Built a 54-strong cybersecurity function from a blank canvas in six months across 35+ countries, and won Board-level security mandates with Fortune 500 and financial services clients aligned to DORA — capability built directly against a sponsor’s value-creation plan.
Det Norske Veritas
UK
UK Managing Director
Managing Director of the UK business of DNV (Det Norske Veritas), the Norwegian certification and assurance body — the equivalent of Lloyd’s in its field — with revenues measured in billions of euros. Led a practice of 88 senior consultants responsible for conducting maturity assessments and issuing ISO 27001 certifications.
Bank of England
UK
CISO Advisory Services
Staff awareness training on cybersecurity and social engineering threats, delivered to Bank staff on behalf of the Bank’s CISO.
Your project
Next
Cyber Due Diligence · Advisory · Interim
Pre-acquisition red flags, confirmatory diligence, post-close remediation or exit readiness — scoped to your deal and your timeline.
Selected Clients & Appointments
Endorsements

Trusted at the top table.

“Presenting awareness of and interest in cybersecurity is a priority for the Bank, and your presentation really helped bring together some difficult to communicate concepts about the threat. The tips on recognising social engineering were especially applicable to staff here. The pitch, content and tempo were spot on — not an easy thing to get right.”
William Brandon · Chief Information Security Officer, Bank of England
“Balanced technical authority with the commercial instincts of an entrepreneurial dealmaker. Boards trust him because he tells them what matters and what it costs.”
Karl DiMascio · Co-Founder, CAGI (thecagi.com)
“At sovereign scale, with everything at stake, Mike built from nothing a cybersecurity capability that gave leadership and investors genuine confidence.”
Joseph Bradley · Former CEO, Tonomus, a NEOM Company
“One of the very few security leaders who can hold the attention of a Board and the respect of an engineering team in the same meeting.”
Professor Richard Benham · Founder, The National MBA in Cybersecurity
“I worked with Mike when he was the Company Secretary and Director for the ISSA. Great guy, very dependable and organised. Has a quiet steel about him, gets things done, and with a host of contacts. Recommend.”
Roger Ellis · CEO, The Great British Business Alliance
Credentials

Certified, and
independently recognised.

Professional Certifications
C|CISOCertified Chief Information Security Officer
CISMCertified Information Security Manager
C|DPOCertified Data Protection Officer
ITILService management
Education & Service
Harvard UniversityCybersecurity Leadership Programme
Institute of DirectorsChartered Director Programme
Royal Air ForceCertified Avionics & Secure Communications Engineer
Security ClearancePreviously held UK SC and Metropolitan Police MPVV clearances across multiple roles; both now lapsed
Recognition
UK CISO of the Year, 2020UK Cyber Security Hall of Fame Inductee
Global C|CISO of the YearNominated, Finalist
Cyber Book of the YearThe National Cyber Awards
Advisory Specialisms

Where I add value.

Cybersecurity Due Diligence Pre & Post-Acquisition Risk OT / IoT / AI & IT Cyber Risk Post-Breach Recovery CEO / CIO / CISO / CAIO Advisory & Interim AI Governance Board Advisory Private Equity Smart & Cognitive City Security Compliance Standards & Frameworks Executive Cyber Maturity Operational Resilience Post-Merger Integration Enterprise Risk
AI Governance in Practice
CAGI — Cybersecurity & AI Governance Initiative

AI risk, assessed with the same discipline investors expect of financial and legal diligence.

As Co-Founder and Executive Director of the Cybersecurity & AI Governance Initiative (CAGI), a global not-for-profit membership body, Mike convenes Board-level and practitioner audiences on emerging cyber and AI risk, anchoring advisory work to recognised frameworks.

EU AI Act Readiness ISO/IEC 42001 NIST AI RMF thecagi.com
Insights

Published thinking.

Short papers written for deal teams and investment committees. Available on request ahead of publication.

+9
Photo Gallery
Moments
Thirteen photographs — keynotes, summits and industry recognition, alongside figures from national security, intelligence and the internet’s founding.
Publication
CISO: Defenders of the Cyber Realm — book by Mike Loginov

CISO: Defenders of
the Cyber Realm

Dirty Deeds, Hackers & Heroes

The award-winning book that opens up the world of the Chief Information Security Officer — the unseen individuals keeping the lights on, the banks open and food on the shelves. With a foreword by Vint Cerf, widely regarded as a father of the internet.

Cyber Book of the Year The National Cyber Awards Foreword by Vint Cerf
Engagement Model

Structured to fit
the mandate.

Flexible commercial terms, engaged directly or through advisory, risk and consulting firms.

Basis
  • Fractional
  • Interim
  • Advisory / Non-Executive
Commercials
  • Retained
  • Day rate
  • Fixed-scope assignment
Commitment
  • Full time
  • Part time
  • Scaled to the deal
Location
  • Fully remote
  • On site as appropriate
  • Asia · Europe · Middle East
“Cybersecurity is no longer simply a technology issue. Coupled to AI, it is a determinant of enterprise value, investment confidence and organisational resilience.”
Contact

Let’s talk about your
next transaction.

Available for cybersecurity due diligence, technology risk and AI governance mandates worldwide — engaged directly or through advisory and risk consulting firms.

MICHAEL J. LOGINOV — CYBER DUE DILIGENCE & DIGITAL TRUST
BRITISH CITIZEN · BASED IN THAILAND · Covers ASIA · EUROPE · MIDDLE EAST