Founder & Principal
Stephen Randles
Stephen Randles’s career has had one through-line: being the person who answers for the risk. As a Group Chief Information Security Officer, most recently across a global software business, he has been accountable to boards for security, data and regulatory risk in the rooms where that accountability is tested: board meetings, audit committees, regulator conversations, and transactions under diligence.
The work has spanned regulated software, financial services, healthcare and education, across UK, US and EU territories. He has built and run information security management systems from the ground up, and aligned organisations to the standards that bear on them, ISO 27001, ISO 42001, PCI DSS, SOC 2, NIST and HITRUST among them, never as parallel programmes but as one position that answers to all of them.
His regulatory range rests on what he has operated under, not read about: the UK and EU at working depth (GDPR, NIS2, DORA) and the United States for cross-jurisdiction data and privacy, including HIPAA. The high-stakes moments (an incident, a regulatory finding, a transaction under scrutiny) are the parts of the seat he knows best: where the answer has to be both quick and defensible.
Alvermere exists to put the judgement of that seat within reach of organisations that need it without filling it permanently. Beyond the firm, he serves as a trustee of the Writhlington Trust, a UK health and wellbeing charity.
Credentials
- CISSPCertified Information Systems Security Professional
- ISO 27001Lead Implementer
- GDPRPractitioner
Confidentiality
We describe the calibre of the work, never the clients. That is deliberate: the discretion we extend to them is the discretion you would receive.
If you would value his read on a decision you are weighing, he would welcome the conversation.