We left the boardroom not because we'd failed at the game, but because we wanted to change the rules.
Ex-Corporate · Ex-Compliance · Exceptional
InfoSec Collective is a group of former CISOs, CTOs and CIOs who've spent decades inside complex businesses. We pair the seniority a board expects with the bluntness a problem deserves. No juniors in trench coats. No box-ticking. No fear-selling.
We bridge security and business, because each of us has lived on both sides of the table. Our clients engage us for our experience — and that's what we deliver. The work that goes out is the work we did, not the work a graduate did under our name.
Seven principles. They're not posters. They're how we choose work, write reports, and walk away from briefs.
01
Clarity Over Complexity
Security should inform, not overwhelm.
02
Substance Over Theatre
We don't perform security. We deliver it.
03
Outcomes Over Activity
Real-world change, not hours billed.
04
Autonomy With Accountability
Trust given early; we expect you to own it.
05
Truth To Power
We speak plainly to boards and bluntly to broken systems.
06
Integrity In Action
We protect reputations, data, and each other.
07
Build Together, Not Top-Down
The best ideas win, regardless of title.
"Most security reports get filed. Ours get acted on. That's the only metric we accept."— Founding member · Ex-CISO