Tim Bateson
Head of Information Security @Slaughter and May
Signup · Get unlimited contacts
WORK HISTORY
Head of Information Security @Slaughter and May
London, GB
Head of IS and deputy CISO at one of the world’s most iconic law firms (1,500 heads, revenue).− Lead a team of GRC professionals, plus a virtual team of analysts, engineers and project managers.− Steer overall security direction via Information Security, Audit & Risk, and Operating Committees.− Defined the security TOM to move to a 3 lines of defence model, to better align to client expectations.− Define, own and drive the 3-year security roadmap. Develop the business cases for, and then lead, security projects ranging from technical cybersecurity improvements to GRC-focused (e.g. improving third party risk management).− Manage the ~£2m p.a. security budget and ~20 vendors. Reduced expenditure by 25% by consolidating the security tech stack on Microsoft E5. Reinvested the savings in accelerating security programme delivery.− Oversee cybersecurity engineering, e.g. vulnerability management. Greatly reduced the firm’s attack surface by adopting Microsoft Secure Score and Exposure Score as KRIs.− Oversee cybersecurity operations, including defining response plans and handling escalations.− Re-tendered Managed Security Service Provider contract (£1m over 3 years) to obtain better service and value. Moved the firm to a bring-our-own-SIEM model to reduce costs and prevent MSSP lock-in.− Coordinated, and was Acting CISO for, a ransomware-themed crisis exercise with senior leadership.− Run the firm’s Information Security Management System (ISMS).− Maintain the firm’s ISO27001 and Cyber Essentials Plus certifications, which enable £MMs p.a. of revenue.− Satisfy client due diligence enquiries and support pitches, enabling the firm to win and retain business.− Negotiate the security clauses within all the firm’s client and supplier contracts.− Currently working to de-risk Artificial Intelligence adoption, including ISO42001 certification.
EDUCATION
University of York
MEng, Electronic & Communications Engineering
Royal Air Force College Cranwell
Queen's Commission, Royal Air Force Officer Training
Royal Air Force College Cranwell
Engineer Officer Training, Electronic & Communications Engineering
SKILLS
ABOUT TIM BATESON
Versatile cybersecurity, governance, risk and compliance professional and chartered engineering leader. Accomplished at leading teams of up to 100 to success through uncertainty and myriad change. Skilled communicator and influencer who sees the big picture and rapidly achieves the credibility, consensus and buy-in required to deliver complex change in demanding circumstances.Skills- Cybersecurity - including strategy, gap analysis, architecture, roadmap definition, business case development, improvement programme management, security engineering, security operations, incident response and crisis management. CISSP, CISM, etc- Information Assurance - including ISO27001, CIS/SANS \'Top 20\', NCSC CCP/CTAS/CAS-T, HMG SPF, HMG IAMM- Information management (e.g. HMG governance & data architecture (e.g. LDM definition)- Data protection / privacy management and GDPR compliance- Governance, Risk & Compliance (GRC)- particularly as it pertains to technology/information risks- IT audit - universe definition, scoping, planning, execution and reporting- Decisive leadership and development of winning, empowered teams of up to 100- Briefing and influencing at senior level - Board / C-suite / 3* military / Senior Civil Service.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.