The people who do the work
Credentials you can verify, histories we do not publish
Our people hold qualifications that can be independently checked with the bodies that issue them. What you will not find here is a list of their former employers, clients or engagement dates — and that is a deliberate decision rather than an omission.
Who you would get, and for what. Five specialists, engaged for the work each is genuinely best at.
Henry Cole — security itself: testing, incident work, threat analysis, and technical findings turned into board decisions.
Denny Thompson — Canadian privacy law in practice: what PIPEDA and the provincial statutes require of you now, and whether you can evidence it.
Dr Jane Mayhew — where the law is going: international frameworks, data ethics, and decisions made about people by algorithms.
Marc Tremblay — Québec and Law 25, in French or English, and the point where a security incident becomes a privacy obligation.
Maya Chen — data crossing borders: Canada and Bermuda, group structures, transfers, and privacy decided before procurement rather than after.
Why these pages are short
Detailed staff biographies are raw material for social engineering. Employment history, tenure dates, named clients and the shape of somebody's career are precisely what an attacker assembles into a convincing pretext — a call from a former colleague, an email referencing a project, a request that arrives with just enough true detail attached.
We advise clients to think carefully about what their people publish. It would be difficult to give that advice and then ignore it ourselves.
So we publish what can be independently verified, and describe what each person actually does on an engagement. ISACA and ISC2 maintain public registers you can search yourself, and we would encourage you to. The IAPP verifies its credentials on request rather than through an open directory, so ask us and we will arrange it.
Where a client needs more, we provide detailed backgrounds under NDA as part of the engagement. Several of our clients require this, and it is a normal part of onboarding.
Henry Cole

Henry began in the British Army, where he served nine years as a commissioned officer in the Royal Electrical and Mechanical Engineers, working on secure networks and cryptography. That is an unusual place to learn security, and it leaves a mark: in that environment the consequences of getting key management or network separation wrong are not commercial, and nobody is interested in a finding that arrives as a hundred-page report.
Since then he has worked across most of what the word cybersecurity now covers — offensive testing, defensive operations, incident response, threat analysis, audit and risk. He has spent his career on both sides of the problem, designing attacks and defending against them, which is an uncommon combination and the reason he is difficult to surprise. He knows how an attacker finds the weakness, exploits misplaced trust and moves through an organisation; he also knows what it takes to detect that, contain it and keep the business running while it happens.
That breadth is the point. Most specialists see one part of an incident. Henry has stood in enough of them, from enough angles, to say which part actually matters — and to say it to a board in a sentence rather than a report.
An MSc in cybersecurity and four of the profession's principal certifications, spanning audit, architecture, risk and management — deliberately not a single specialism.
- MSc in cybersecurity
- CISA — Certified Information Systems Auditor
- CISSP — Certified Information Systems Security Professional
- CRISC — Certified in Risk and Information Systems Control
- CISM — Certified Information Security Manager
All four certifications appear in the public registers held by ISACA and ISC2. Verify them there rather than taking our word for it.
Ethical hacking and security testing. Red team and blue team. Incident response and investigation. Threat analysis. Cyber-risk management. Board-level assurance.
- Facilitates tabletop exercises and board sessions, particularly the ones that get uncomfortable
- Reviews technical findings and translates them into what a board actually has to decide
- Supports incident work: what happened, what it means, and what has to be told to whom
- Reviews the technical answers behind assessment and insurance evidence
Based in London and regularly in Toronto. Canadian engagements are delivered under Canadian law with data held in Canada.
Sectors he has worked in. Healthcare. Mining and resources. Financial services. And, at the other end of the scale, direct consultation with small businesses — organisations with no security function at all, where the whole job is explaining what matters to someone who has never had to think about it.
That range is deliberate rather than accidental. The controls do not change much between a hospital, a mine and a bank; what changes entirely is who carries the risk, what the regulator expects, and what an hour of downtime costs. Somebody who has only ever worked in one of those environments tends to assume the whole world runs like it.
Years of work with international organisations and multidisciplinary teams have made him pragmatic and perceptive, and he is at his most useful under pressure — during exercises, live investigations, and the moments when a leader needs a clear answer rather than another technical document. He is an extrovert by nature and a careful listener by experience, and he explains complicated risk without fear, theatre or unnecessary jargon. He takes his espresso Italian and strong, reads the Sunday broadsheets, and volunteers at his local church in London.

Denny Thompson

Denny works at the point where a privacy policy stops being a document and becomes something an organisation actually does. That is a narrower place than it sounds, and it is where most privacy programmes come apart: the notice is published, the policy is approved, and then nobody can say who owns the decision, what evidence was kept, or what the organisation would produce if a regulator asked it to show its working.
His subject is Canadian privacy law and how it lands in practice — PIPEDA, the provincial statutes, Ontario health privacy, and Quebec's Law 25, which moved the whole country's baseline whether or not an organisation operates in Quebec. He works on privacy strategy, regulatory accountability, breach management, privacy impact assessments, information handling, and the governance of automated decision-making.
That last one is not a side interest. Law 25 already requires an organisation to tell someone when a decision about them was made exclusively by automated means, and federal AI transparency rules are being consulted on now. Most organisations cannot yet answer the first question that follows: which of our decisions are automated, and who signed off on that.
A master's degree in the subject itself, and the principal privacy credentials — the Canadian law qualification, the programme-management qualification, and the IAPP's senior designation.
- MSc in International Data Privacy
- CIPP/C — Certified Information Privacy Professional, Canada
- CIPM — Certified Information Privacy Manager
- FIP — Fellow of Information Privacy
All three are issued by the IAPP. FIP is not an exam: it is granted on application to holders of two IAPP credentials who can evidence three years of privacy work and provide three peer references. We will confirm any of them on request.
Privacy governance, accountability and evidence. Board-level privacy. Breach response. Assessment of privacy programmes rather than construction of them.
- Tests whether a privacy programme can produce evidence, not just policies
- Reviews privacy impact assessments and the decisions recorded in them
- Works through breach obligations: what happened, who must be told, and by when
- Reviews the privacy answers behind assessment and insurance evidence
Based in Toronto, living in Whitby. Canadian engagements are delivered under Canadian law with data held in Canada.
What he asks a board. Not whether you have a privacy policy — you do. What personal information you hold, why you hold it, where the risk actually sits, and what you would be able to show if a customer, a regulator or an affected individual asked you a difficult question tomorrow.
Most executive teams can answer the first two. The fourth is the one that decides how a breach notification or an OPC complaint goes, and it is answered months earlier, by whether anyone was keeping a record at the time.
He is calm about all of this, which matters more than it should: privacy conversations tend to arrive attached to something that has already gone wrong. He makes complicated requirements understandable without quietly dropping the detail that turns out to matter, and he is direct about who is responsible for what. His coffee is a black Americano — strong, dependable, no unnecessary complications — and he takes the view that privacy advice should work the same way. Away from the work he hikes Ontario's trails with his family.

Dr Jane Mayhew

Jane's question is the one boards rarely get asked: not whether a use of data is lawful, but whether it is fair, explainable, and worth the trust it depends on. She is an academic — a professor and researcher in international data protection law — and she is on this team because a growing share of what we are asked to assess has no settled rulebook yet.
Her doctorate is in law, from the London School of Economics and Political Science, with research on international data protection, digital rights and responsible data advocacy. Her work is on how legislation, technology and organisational accountability actually interact, and what that means for the people whose information is being used — who are, as she points out, absent from almost every meeting where decisions about their data get made.
Her particular interest is decisions made about people by data and algorithms, and the gap that opens when technical capability moves faster than the oversight of it. That gap is not theoretical: it is where our AI governance work sits, and Jane is the reason we are willing to take positions on questions the regulators have not finished answering.
An academic specialism rather than a certification portfolio — the depth is in the doctorate and the teaching, not in a list of exams.
- PhD in Law — London School of Economics and Political Science
- Research in international data protection, digital rights and data advocacy
- Professor of international data protection law
- Researcher and educator; adviser to organisations on data ethics
- Member of the Society of Legal Scholars and the Socio-Legal Studies Association
LSE degrees can be verified through the university's own records service, by anyone, without going through us. Her academic post is named on request. The two society memberships are subscriptions rather than examined qualifications, and we list them as memberships for that reason.
International frameworks, cross-border transfers, data-subject rights, regulatory accountability, and the ethics of emerging technology.
- Assesses whether an automated decision can actually be explained to the person it affects
- Works on cross-border transfer arrangements and the reasoning recorded behind them
- Reviews AI governance frameworks against principles, not just against current statute
- Runs board sessions on where minimum compliance leaves real exposure
Brings the international comparison: what other jurisdictions already require, and where Canadian expectations are likely to land.
Why two privacy specialists, and what the difference is. Denny works on what Canadian law requires of you now and whether you can evidence it. Jane works on where the law is going, what the principles underneath it demand, and the questions that arise when a decision is made about somebody by a system rather than a person.
Most organisations need the first. Any organisation deploying AI into decisions that affect customers, patients or employees needs both, because the compliance answer and the defensible answer are not yet the same answer.
She is an unusually good explainer — she makes complicated legal questions accessible without quietly sanding off the parts that make them difficult, which is the failure mode of most plain-language legal advice. She will push a board past "is this permitted" to "is this something we would be comfortable explaining publicly", and she is patient about it. Her coffee is a latte: thoughtful, balanced, and best over a long conversation.

Marc Tremblay

Marc works where cyber and privacy collide, which is where most organisations discover they have organised themselves badly. A ransomware incident, a compromised supplier or a misconfigured AI system is almost never only a technical problem. Within hours it becomes a set of decisions about notification, evidence retention, what to tell customers, and what to say to the Commission d'accès à l'information du Québec — and those decisions are usually taken by people who have never had to take them before.
He has been on the other side of that. Having held senior information-security and CISO roles, he knows the difference between advising an organisation about its risk and being the person personally accountable when it materialises. That distinction changes what advice is worth giving.
His specialism is Québec. Law 25 is the most demanding privacy regime in the country, and Marc works in French and English on organisations that live under it — so the advice is built for their legal and cultural environment rather than translated from somewhere else after the fact.
An unusually wide credential set spanning security leadership, privacy, risk and AI governance — which is what working across both disciplines requires.
- MSc in cybersecurity
- CIPP/C and CIPM — privacy, Canadian law and programme management
- CISSP, CISM, CRISC — security, security leadership and risk
- AIGP — Artificial Intelligence Governance Professional
CISSP is verifiable with ISC2, CISM and CRISC with ISACA, both by public register. The IAPP credentials — CIPP/C, CIPM and AIGP — are confirmed on request.
Québec engagements in French or English. Law 25. The point where a security incident becomes a privacy obligation.
- Assesses Law 25 readiness: privacy impact assessments, governance policies, the confidentiality-incident register
- Reviews cross-border information assessments and the reasoning recorded behind them
- Tests whether automated-decision obligations have actually been identified, not just acknowledged
- Reviews third-party and supplier assurance
Engagements, workshops and deliverables in French where the client prefers it.
What he is good at, specifically. Translating a live and confusing situation into decisions somebody can actually take: what happened, who may be affected, what has to happen next, and what evidence the organisation needs to keep while it does. He does this equally comfortably with a technical team, a privacy officer and a board, which is rarer than it sounds.
Note the boundary, because it applies to him as much as anyone here: Marc assesses whether Law 25 obligations have been met and can be evidenced. He does not then build the programme he has just assessed.
He is unhurried in a way that is useful when everyone else is not. While the rest of the team argues about espresso strength, Marc drinks Earl Grey — fragrant, composed, and given time to brew properly. He takes the view that governance works the same way: start with reliable ingredients, allow time for judgement, and never mistake rushing for being decisive.

Maya Chen

Maya's subject is what happens to personal information when it crosses a border — which entity is actually responsible for it, what is moving, which safeguards travel with it, and what evidence exists that anybody decided this on purpose. It is the question most organisations answer by accident, usually in a procurement decision nobody thought was a privacy decision.
She works across Canadian privacy law and Bermuda's Personal Information Protection Act, which came fully into force on 1 January 2025 and is now enforced by Bermuda's Office of the Privacy Commissioner. That combination is less exotic than it looks: Bermuda is a global insurance and reinsurance centre with deep Canadian corporate ties, and a great many organisations now sit on both sides of that line without having mapped what it means.
Her working principle is that privacy has to be considered during procurement, system design, vendor selection and AI deployment — not bolted on after a product is already live, when the only remaining options are expensive. She holds a master's degree in international privacy and data governance, and an unusually broad credential set covering Canadian law, European data protection, programme management and technical implementation.
Both sides of the discipline: the legal qualifications in two jurisdictions, and the engineering credential for people who have to build it.
- MSc in International Privacy and Data Governance
- CIPP/C and CIPP/E — Canadian and European privacy law
- CIPM and FIP — programme management, and the IAPP's senior designation
- CDPSE — Certified Data Privacy Solutions Engineer
CDPSE is verifiable with ISACA by public register. The IAPP credentials are confirmed on request.
Cross-border data governance. Canada and Bermuda. Privacy that survives contact with procurement.
- Establishes which entity is responsible for what, across jurisdictions and group structures
- Reviews records of processing, information-sharing agreements and transfer arrangements
- Assesses privacy management programmes against what can actually be evidenced
- Reviews whether privacy was considered before a system, vendor or AI tool was chosen
Helps leaders separate what is legally required from what is good practice, and from what needs specialist local advice.
She is composed and precise, and she is unusually good at holding a conversation that contains lawyers, engineers and a board at the same time without any of them losing the thread. Her coffee is a flat white — smooth, precise, and quietly stronger than it first appears — and she says privacy governance should work the same way: island insight, Canadian perspective, and no unnecessary borders around a good idea.

The rule that applies to our people too
Nobody assesses an organisation they have advised
Our independence rule is not a firm-level policy that individuals work around. If one of our people has designed your controls, written your policies or advised you on a fix, that person does not then assess you — and neither does anyone else here on that engagement. We will tell you when that applies before you book, not afterwards.
It costs us work. That is what makes the findings worth anything.
How we are set up
Canada Cyber-Safe is a small practice that engages specialists for the work they are genuinely best at, rather than carrying a bench and finding it something to do. That is a deliberate choice: it keeps the practice independent of any vendor, and it means the person in the room is there because the engagement needs them.
You will be told who is working on your engagement before it starts, and what they are certified in. If you want more detail than this page carries, ask — we will provide it under NDA.
We are always interested in the right people
Joining the practice
The bench, not a vacancy
We do not carry a bench and find it work. We engage specialists for the things they are genuinely best at, which means the practice grows one person at a time and only when there is something worth doing. If that is how you prefer to work — bounded engagements, in your specialism, with your name on the finding — we would like to know you exist before we need you.
We are most often looking for people in security assessment and incident work, Canadian and Quebec privacy, cross-border data governance, and AI governance. If your specialism is not on that list and you think we are missing something, say so — that is a more interesting message than a covering letter.
What happens to your CV. It goes to one monitored address and is read by a named person. We keep it for twelve months and then delete it, unless you ask us to keep it for longer or to delete it sooner — either request is honoured on the day we receive it.
We do not circulate it outside the practice, we do not add you to a mailing list, and we do not pass it to anyone else. You are giving us personal information about yourself in confidence, and the standard we apply to it is the one we would assess a client against.
A CV and a paragraph on what you would want to work on. No forms, and no application portal.
There is no charge for the first conversation and no obligation at the end of it.