Cyber security,
made useful
for people.

I'm Haidar Rashid. I share practical perspectives on cyber risk, resilience and leadership, shaped by over a decade across central UK government, enterprise and community organisations.

Strategic Advisor

Assurance Profile

Expertise

Security assurance, cyber risk management and cyber security risk strategy.

Background

10+ years across UK government and industry — leading cyber security assurance and risk engagements.

Community outreach

Co-founder of CyBeds CIC & Trustee at a local Citizens Advice.

01 — Areas of expertise

Where experience
becomes useful.

Security Assurance

End-to-end assurance for government and enterprise systems — risk assessments, control reviews and accreditation evidence that stands up to scrutiny, from discovery through to executive reporting.

Governance & Compliance Strategy

Regulatory requirements translated into roadmaps your boards can approve and your teams can deliver.

Executive Assurance Reporting

Risk posture and governance maturity reported in language executives act on — no 200-page PDFs nobody reads.

Central Government Advisory

Security management plans, policy alignment and stakeholder liaison for central UK government programmes.

Resilience & Incident Readiness

Incident response readiness and community resilience planning — informed by national-level work with a UK government department.

Assurance Capability Building

Mentoring and frameworks that leave your own people stronger — I've built and led assurance teams across the public and private sector.

02 — Case studies

What the work
looks like in practice.

Client names and identifying details are withheld. Each example is drawn from real engagements and described at a level that respects confidentiality.

Central UK government

Assurance for a high-value government contract

Challenge
A major government engagement needed a security management approach that satisfied the customer's assurance requirements without stalling delivery.
Approach
I built the Security Management Plan from the ground up, mapped obligations to owners and milestones, and ran the risk register as a live delivery tool rather than a document.
Outcome
Security requirements were met on the customer's timeline, with risk exposure reported to the executive board in a single, readable view.

Enterprise · Consultancy

Compliance roadmap a board could actually approve

Challenge
An enterprise client had a long list of audit findings and no agreed order of work — every function considered its own gap the priority.
Approach
I assessed the findings against real risk and effort, grouped them into phases, and presented a costed roadmap in plain language to the leadership team.
Outcome
The roadmap was approved first time, gave delivery teams a clear sequence, and turned a static findings list into tracked progress.

National resilience · UK government department

Strengthening community cyber resilience

Challenge
Smaller organisations and community groups were exposed to threats they had neither the budget nor the language to engage with.
Approach
I worked across stakeholder groups to assess sector vulnerabilities, improve incident awareness and shape resilience guidance that non-specialists could act on.
Outcome
Practical resilience material reaching organisations that commercial security advice rarely gets to.

Capability building

Building an assurance function that outlasts the consultant

Challenge
A client depended on external consultants for every assurance decision, which was slow and expensive.
Approach
I standardised the assurance approach into reusable templates and review gates, then mentored the in-house team through real assessments.
Outcome
The client's own team now runs routine assurance, with external support reserved for genuinely complex work.
Haidar Rashid, cyber security consultant

Haidar RashidMCIIS · PriCSP

03 — About

From government programmes to the boardroom.

I've spent over ten years in information and cyber security across central UK government and enterprise — including Big 4 consulting on government engagements, and leading cyber assurance delivery in large consultancies.

My current role — Principal Security Consultant — includes a cyber security secondment with a UK government department, contributing to national resilience. That experience reinforced my belief that people are at the heart of cyber security — the best assurance only lands when it connects with the humans behind the decisions. So everything I deliver is specific, prioritised and written for people.

Outside client work I co-founded CyBeds CIC to open up cyber careers in Bedfordshire and serve as a Trustee at a local Citizens Advice, leading on cyber security. I previously served as an elected education governor for a local education trust.

04 — Community

Giving cyber back
to the community.

Co-founder

CyBeds CIC

I co-founded CyBeds, a Community Interest Company breaking down the barriers to cyber careers in Bedfordshire — for students, career changers, experienced practitioners, charities and small businesses alike. The goal is simple: create opportunities, build capability and strengthen cyber resilience across our communities.

  • Cyber Social

    Connecting people, building networks and creating a supportive community.

  • Cyber Pathways

    Helping individuals start and progress their cyber security careers.

  • Cyber Green

    Promoting sustainability and responsible practice across cyber and technology.

  • Cyber Clinics

    Practical guidance for individuals, charities and small organisations.

  • Cyber Guardians

    Community awareness, education and resilience initiatives.

Visit cybeds.org.uk

Trustee

Citizens Advice

As a Trustee I lead on cyber security — helping a local charity give free, independent advice to the community while keeping its own technology and data safe and its services open to everyone.

Visit Citizens Advice

Education governance

I previously served as an elected education governor for a multi-academy education trust, with responsibility for its secondary academies — plus school engagement through Inspiring the Future.

05 — Experience

A decade across
government & enterprise.

Current roles

  1. Employer undisclosed

    Undisclosed

    Principal Security Consultant

    Leading cyber security assurance and risk engagements across complex central UK government programmes — owning outcomes from discovery through to executive reporting.

  2. HM Government logo

    HM Government

    Cyber Security Community Resilience Secondee

    Contributing to national cyber resilience through stakeholder coordination, incident awareness and assessment of sector vulnerabilities.

Previous roles

  1. HM Government logo

    HM Government

    Cyber Security — Junior to Mid-Senior

    Progressed through information and cyber security roles, leading governance, risk and assurance work across central government environments.

  2. DXC Technology logo

    DXC Technology

    Information Assurance Consultant

    Led assurance delivery for enterprise and public-sector clients, presented compliance roadmaps to executive boards and mentored consultants.

  3. EY logo

    EY

    UK Government Security Manager

    Managed assurance for high-value government contracts, developed Security Management Plans and reported risk exposure to executive boards.

06 — Speaking & conversations

Let’s make cyber
easier to talk about.

I’m always open to a useful conversation — whether you’re planning a cyber event, exploring a difficult issue or simply want to compare notes with another practitioner.

Find a time on Calendly

Speaking invitations

Panels, podcasts, roundtables and events exploring cyber risk, resilience, governance and careers.

Cyber catch-ups

Informal conversations with practitioners, community leaders and people finding their route into cyber.

Community conversations

Ideas and collaborations that can strengthen cyber awareness, inclusion and resilience where it matters.

07 — Contact

Continue the conversation.

Follow what I’m sharing, invite me to contribute, or send a note if there’s a cyber security issue worth unpacking together.