MBV

IT and security leadership

Mike Vaughan

I build technology functions that regulators, auditors and the people who use them every day can all live with.

About

My career started in scientific research, then ran through telecoms security and further and higher education to cyber security software. The thread through all of it is the same: technology people can rely on, in organisations where a regulator, an auditor or a customer will notice quickly if it goes wrong.

I like building the function, not just running it. That means owning the risks properly, being clear about who is accountable for what, and keeping controls light enough that people actually follow them. Security and data protection work best when they help an organisation move faster, not slower.

I'm hands-on by habit. At home I run my own small platform: servers, backups, monitoring and an AI assistant I built myself. It keeps me honest about what the advice I give actually costs to follow.

What I do

IT leadership

Building and running IT teams and services across multiple sites, from strategy and suppliers to the service desk.

Information security

ISO 27001, governance, risk and compliance, identity and access, and proper oversight of the suppliers you depend on.

Data protection

Formal DPO accountability: UK GDPR, impact assessments, and being the person who talks to the regulator when it matters.

Digital transformation

Changing how inspected, regulated organisations work, without breaking what already works.

Where I've worked

Scientific research

My first proper job: IT for the global science centre of a major food and drinks group. Labs, research data, and an early lesson that results have to stand up to scrutiny.

Telecoms

Security operations and security engineering for a national telecoms provider with millions of customers. Also where I learnt that customers and regulators judge you on the escalations, not the averages. Ofcom complaints included.

Further and higher education

Multi-site, inspected and accountable. IT, data protection as DPO, and digital transformation under Ofsted's eye.

Cyber security software

Building the IT and security function of a growing, investor-backed security company, through ISO 27001 and the scrutiny of customers who know exactly what good looks like.

Credentials

CISSPCertified Information Systems Security Professional MCIISecChartered Institute of Information Security ISO 27001Lead Implementer DPOData Protection Officer PRINCE2Project management ITILIT service management

Off the clock

Usually building something: the homelab, e-ink dashboards round the house, or whatever is coming off the 3D printer this week.