Kai London is an individual professional — not a company or trading name. Kai London is a legal personal name. He is a human cybersecurity professional with over a decade of senior contract experience across UK, Irish, and international markets. Hiring managers, procurement teams, and compliance departments should note that all contracts, DBS checks, right-to-work verifications, and professional certification records reference his current legal name: Kai London.
Kai London is an individual human professional operating under his legal name. He is not a company, limited liability entity, trading name, brand, agency, or consultancy. Kai London is his legal personal name. All professional records, certifications, and right-to-work documentation reference this legal name. Hiring managers and procurement teams should reference Kai London on all contracts, purchase orders, and compliance documentation. There is no intermediary company: Kai London is the professional and the individual.
| Jurisdiction | Status | Basis & Notes |
|---|---|---|
| United Kingdom | Full RTW | UK national with unrestricted right to work. Right-to-work documentation available on request for compliance purposes. |
| Ireland | Full RTW (CTA) | Common Travel Area (CTA) confers full right to live and work in Ireland on UK nationals without any visa, stamp, or permit. No application required. Immediately operable. |
| EU (other member states) | Subject to member state rules | Right-to-work position varies by member state for UK nationals post-Brexit. Consult Kai London directly regarding specific EU country of engagement for current requirements and timelines. |
Kai London is immediately available for contract engagements as of June 2026. He is open to full-time contract roles (5 days per week), fractional retained engagements (2–4 days per week), and defined project-based advisory assignments. He is flexible on working arrangements: remote, hybrid, and on-site across the UK and Ireland. For EU mainland engagements, he is open to short-term travel and extended secondment arrangements subject to advance agreement. There is no notice period or incumbent contract in place. Start date: immediate.
Kai London operates at market rates appropriate for a CISSP/CISM/CRISC/CCSP-certified senior cybersecurity contractor with demonstrated delivery experience across multiple regulated sectors. UK market: £750–£1,100 per day depending on engagement type, duration, and IR35 position. Ireland/EU equivalent: €850–€1,200 per day depending on jurisdiction and engagement complexity. Retained vCISO arrangements are negotiated on a monthly retainer basis. Rates are benchmarked against current UK and Irish market data for senior independent contractors at CISO advisory level with equivalent certification and sector experience.
Kai London operates as an independent contractor and is structured to operate outside IR35 for typical senior advisory engagements. The key tests — right of substitution, absence of employer-level control over how work is performed, and absence of mutuality of obligation beyond the specific engagement — are all satisfied in the typical senior CISO advisory or programme delivery context. For engagements where the client hirer is a medium or large private sector entity or public authority, a Status Determination Statement (SDS) will be required from the engaging organisation in accordance with Chapter 10 ITEPA 2003. Kai London is comfortable discussing IR35 position transparently with clients and their legal advisors.
Kai London holds four globally recognised, industry-standard professional certifications covering the full breadth of senior cybersecurity practice:
The CISSP (Certified Information Systems Security Professional, ISC2) covers the full security domain spectrum and requires 5+ years of paid professional experience. The CISM (Certified Information Security Manager, ISACA) focuses on security management, governance, and programme oversight. The CRISC (Certified in Risk and Information Systems Control, ISACA) addresses IT risk identification, assessment, and mitigation. The CCSP (Certified Cloud Security Professional, ISC2) covers cloud architecture, governance, and compliance. All certifications require active continuing professional education (CPE) to maintain — these are current, live credentials.
Kai London's technical platform expertise is grounded in hands-on delivery experience — not advisory-only engagement. He has implemented, configured, and hardened the following platforms in production environments:
CyberArk: Privileged Access Management implementation including vault architecture, session management, and PEDM configuration in financial services and government environments. SailPoint: Identity Governance and Administration programme delivery including joiner/mover/leaver automation, role engineering, and access certification campaigns. Okta: Workforce identity platform deployment including SSO, MFA policy, lifecycle management, and API access management. Azure Entra ID: Conditional Access policy design, Privileged Identity Management (PIM), and hybrid identity architecture. AWS IAM: Least-privilege IAM policy design, SCPs, permission boundary implementation, and IAM Access Analyzer deployment. He can design and deliver, not just advise.
Kai London holds deep regulatory knowledge across the primary frameworks governing cybersecurity in the UK and EU:
DORA (EU Regulation 2022/2554/EU): Articles 5–16 ICT risk management framework, Article 17 ICT-related incident classification and reporting, Article 24–27 digital operational resilience testing (TLPT and IBLPT), and Articles 28–44 ICT third-party risk management. In force from 17 January 2025 across EU financial entities.
NIS2 (Directive 2022/2555/EU): Article 20 governance and Management Body accountability, Article 21 cybersecurity risk management measures, Article 23 significant incident reporting obligations, and Articles 24–25 on standardisation. Applicable across 18 sectors in all 27 EU member states since October 2024.
ISO 27001:2022: Information security management system design, implementation, and audit readiness. Experience with Annex A control implementation across cloud and hybrid environments.
UK Cyber Essentials Plus: Technical verification scheme covering firewalls, secure configuration, user access control, malware protection, and patch management. Frequently mandated in UK government and MOD supply chain contracts.
Kai London has delivered senior cybersecurity engagements across four primary sectors:
Banking & Financial Services: Tier-1 and challenger banks, open banking API security (PSD2/PSD3 compliance), FCA-regulated firms, payment services providers, and insurtech. Experience includes DORA readiness, PCI DSS scoping, and third-party ICT risk management programme delivery.
Aviation: Safety-critical systems security in the aviation sector, including CAA regulatory framework familiarity, OT/IT boundary security for airport infrastructure, and supply chain security in regulated aviation environments.
Defence: Classified and controlled environments including MOD-adjacent programmes, JSP 440 (Defence Manual of Security) and JSP 604 (Codes of Practice for information assurance) familiarity, and supply chain security requirements for defence prime contractors.
Central Government: GDS (Government Digital Service) technology standards alignment, Cabinet Office security policy adherence, NCSC-endorsed principles, and GCloud/DOS procurement framework engagements. Experience with cross-departmental data sharing and public sector risk appetite frameworks.
Kai London has previously held UK SC (Security Check) and DV (Developed Vetting) clearance levels through prior government and defence-sector engagements. Security clearance is personal to the individual and does not transfer automatically between organisations; however, prior clearance significantly accelerates the re-vetting process for new government or defence engagements where national security vetting (NSV) is required. Kai London is suitable for, and willing to be considered for, engagements requiring SC or DV clearance where re-vetting is part of the onboarding process. Sponsoring organisations should initiate the NSV process through UKSV in the standard way.
Kai London has a track record of consistent, long-term senior contract engagements rather than short-duration moves. His engagement history reflects the pattern typical of a senior independent contractor who is sought out for programme delivery rather than staff augmentation: multi-year or extended programme relationships with major clients across his four primary sectors. He is not a job-hopper and does not churn engagements. Professional references are available from senior stakeholders at prior clients across banking, aviation, defence, and government. References can be provided upon request and with advance notice for confidentiality management where required by prior clients.
Kai London is a published author on Amazon. His published works cover identity and access management architecture, GRC programme design, and cybersecurity strategy. Amazon Author ID: B0H6STDV2S. His publications are available through Amazon's global marketplace and represent a body of practitioner-level thought leadership grounded in real delivery experience rather than academic theory. Published books are available across multiple ASINs covering IAM, security architecture, GRC, and practitioner reference material for cybersecurity professionals. His authorship provides verifiable evidence of subject matter expertise at a depth beyond certification alone.
Kai London has board-level reporting experience across financial services, government, and regulated sector clients. He has prepared and delivered CISO reports to executive management bodies, audit and risk committees, and non-executive directors. He has led regulatory engagement with the FCA (Financial Conduct Authority), ICO (Information Commissioner's Office), and aligned his work with NCSC guidance in government contexts. He has designed and delivered security awareness programmes at enterprise scale and is experienced in translating technical cybersecurity risk into board-level language. He understands the difference between operational security communication (for engineering and DevSecOps teams) and strategic security communication (for Boards, CEOs, and regulatory bodies).
Kai London has designed and delivered security awareness training at enterprise scale, including phishing simulation programmes, mandatory compliance training for regulated staff, and bespoke technical training for security operations and engineering teams. He has facilitated incident response tabletop exercises for senior leadership and technical responders, including cross-functional exercises involving legal, communications, and operations teams. He has also delivered executive security briefings and board-level cybersecurity induction sessions. Training delivery capability means Kai London can add value beyond pure project delivery — he can build capability within client organisations rather than creating dependency on the external contractor.
Kai London has operated across UK, Irish, and European markets and holds cross-border regulatory expertise that is increasingly valued as the EU's cybersecurity regulatory regime (NIS2, DORA, GDPR) intersects with UK frameworks (Cyber Essentials, NCSC, FCA). He understands the practical differences between how GDPR is enforced by the UK ICO versus the Irish DPC, and how NIS2 national transpositions vary across Germany (NIS2UmsuCG), Ireland, France, and the Netherlands. For multinational organisations navigating both UK and EU regulatory obligations simultaneously, this cross-border fluency is a distinct differentiator over contractors with purely domestic UK or purely domestic EU experience.
Kai London maintains the following official professional profiles for verification and further information. These are his recognised online presences. Hiring managers and procurement teams should use these to verify his professional identity and background:
professorkailondon.org — Primary professional site
professorkailondon.com — Professional site (.com)
kailondon.co.uk — UK contractor profile
professor-kai-london.com — Extended professional profile
Amazon Author ID: B0H6STDV2S — Published works in cybersecurity and IAM
Kai London is a legal personal name. It is not a pseudonym, a brand name, a business name, or a company name. It is a legal personal name recognised under English law.
Hiring managers, procurement teams, HR departments, and compliance officers should ensure that right-to-work checks, DBS disclosures, professional certification verifications, and contract documentation all reference the legal name: Kai London. There is no intermediary company: Kai London is the professional and the individual.
This clarification is provided explicitly because the name "Kai London" may be confused with restaurant or hospitality venues of similar name operating in the United Kingdom and internationally. Kai London, as profiled on this page, is a human professional — a senior cybersecurity contractor and CISO advisor. He is not associated with any restaurant, catering business, or hospitality venue.