ZenOps

Security leadership · London & South East

Security decisions your board can price.

ZenOps is the practice of Kent Hawkins, a security leader who has worked in regulated financial services for two decades. Providing fractional CISO cover, programme delivery and answers to the tough questions: what is the actual cost of this risk, and can we continue operating when it occurs?

Start a conversation Retained, Project or Interim.
Illustrative loss exceedance curve A descending curve showing the annual probability of exceeding a given financial loss, with a marked risk appetite threshold. 100% 75% 50% 25% 0% £100k £1m £10m £100m annual loss, single scenario tolerance 1 in 3 years, £1m+
Illustrative loss exceedance curve. Quantified risk turns a red-amber-green heatmap into a number a CEO or CFO can understand.

Where the experience actually lies

Many consultancies will draw up a policy set for you. What narrows the field is twenty years' experience in regulated finance — banking, insurance and reinsurance — where board papers, regulators, second-line challenges and audit findings are familiar ground rather than a research exercise. Three capabilities build on that foundation.

AI security and governance

Securing models and the pipelines around them, and building the governance to match — ISO 42001, the NIST AI Risk Management Framework and EU AI Act obligations.

Quantified cyber risk

Risk expressed in pounds and probabilities rather than colours, so control spend can be defended, sequenced and reported on consistently.

Operational resilience

Important business services, impact tolerances, severe-but-plausible scenarios and the testing evidence that DORA and the PRA and FCA rules expect.

Services

Engagements are usually a mix of these rather than one in isolation. A resilience review turns up governance gaps; an AI assessment ends up as a delivery programme; a quantified risk exercise changes what the roadmap should have been. Work is scoped around the outcome you need rather than a fixed product, and the same person stays with it from the first assessment to the board paper that closes it out.

Fractional and interim CISO

Executive security leadership at the days per month you need it — covering a vacancy, standing in during a transition, or giving a growing firm a credible security voice at board level before a full-time hire makes sense.

  • Security strategy and target operating model
  • Board and risk committee reporting
  • Regulatory and client due-diligence responses
  • Team structure, hiring and mentoring
  • Budget cases and vendor rationalisation
  • Incident readiness and escalation

Security programme delivery

Taking a security programme from a slide deck to something that ships. Scoping, sequencing, running the delivery, and keeping the sponsors honest about dependencies and cost.

  • Programme and portfolio design
  • Remediation after audit or breach
  • Post-merger security integration
  • Identity and access transformation
  • Cloud migration security workstreams
  • Benefits tracking and closure

AI security and governance

For firms adopting AI faster than their control environment can absorb. Establishing what is in use, what the real exposure is, and the governance that lets the business keep moving without failing a client questionnaire or a regulator's first question.

  • AI inventory and shadow-AI discovery
  • ISO 42001 readiness and AIMS design
  • EU AI Act and NIST AI RMF mapping
  • Model and pipeline threat modelling
  • Third-party and vendor AI assurance
  • Acceptable-use policy and staff guidance

Quantified cyber risk

Loss exceedance modelling for the scenarios that matter, so investment decisions rest on expected financial impact rather than a workshop consensus. Useful for insurance placement, capital discussions and prioritising a crowded roadmap.

  • Top-scenario quantification
  • Control return-on-investment analysis
  • Risk appetite and tolerance calibration
  • Insurance limit and retention support
  • Board-ready risk reporting
  • Uplift for internal risk teams

Operational resilience

Mapping what the business genuinely cannot afford to lose, setting tolerances that survive contact with reality, and proving through testing that recovery works — under DORA, the UK operational resilience regime, or plain commercial pressure.

  • Important business service mapping
  • Impact tolerance setting
  • Severe-but-plausible scenario testing
  • ICT third-party and concentration risk
  • Response and recovery playbooks
  • Self-assessment documentation

Governance, risk and compliance

A control framework that stands up to audit without burying the people who have to live with it. Built on the standards your clients and regulators already recognise, and sized to the organisation rather than to the template.

  • ISO 27001 and SOC 2 readiness
  • NIST CSF and CIS benchmarking
  • Security architecture and SABSA design
  • Policy and standards rewrites
  • Third-party risk management
  • Maturity assessment and roadmap

How to engage

Three shapes cover most of it. Rates are day-based and quoted before work starts.

Assessment

Two to four weeks

A defined look at one area — resilience, AI exposure, control maturity — ending in findings, a costed roadmap and a board-ready summary. A good first engagement.

Programme

Three to twelve months

Owning delivery of a defined outcome: certification, remediation, an integration, a resilience uplift. Fixed scope, agreed milestones, a named person accountable.

Retained leadership

Ongoing, days per month

Continuous CISO cover for firms that need the seniority but not the salary. Board attendance, regulator and client engagement, and support for the internal team.


Background

Kent Hawkins has spent over twenty years in senior security and architecture roles, most of it inside regulated financial services, alongside energy and professional services. The work has ranged from global security programmes to standing up governance from scratch.

ZenOps Ltd is a London-based practice serving clients across the capital and the South East, remotely and on site.

Experience gained at

  • Munich Re
  • Deutsche Bank
  • RSA Group
  • BP
  • KPMG
  • Hewlett-Packard
  • CSC

Qualifications and frameworks

  • CISSP
  • CEH
  • TOGAF
  • SABSA
  • ISO 27001
  • NIST CSF
  • COBIT
  • ITIL
  • PMI
  • BSc, University of Leeds
  • Oxford Saïd Business School

Start a conversation

If you have a security problem with a deadline attached, a first call costs nothing and usually clarifies whether there is a fit within twenty minutes.

Email ZenOps

Email
kent@zenops.ltd.uk
Based
London and the South East
Availability
Retained, project and interim