David Lacey

Former Director of Information Security, IT Governance & Risk at Royal Mail/Post Office Group, Member of Advisory Board at Citicourt & Co & Author of 'Managing the Human Factor in Information Security'

  • Managing Director of David Lacey Consulting Limited
  • Consultant and Member of Advisory Board to Allied Contech LLC
  • Honorary Fellow of The University of Nottingham
  • Member of the Infosecurity Europe Hall of Fame
  • Won the Open Group Award for Outstanding Contribution to Information Security

Discover David Lacey’s biography of published work below.

David Lacey Book - Managing the Human Factor in Information Security: How to win over staff and influence business managers
Managing the Human Factor in Information Security
David Lacey Book - Managing Security in Outsourced and Off-shored Environments: How to Safeguard Intellectual Assets in a Virtual Business World
Managing Security in Outsourced and Off-shored Environments
David Lacey Book - Business Continuity Management for Small and Medium Sized Enterprises. How to Survive a Major Disaster or Failure
Business Continuity Planning for Small and Medium Enterprises

David Lacey is one of the UK’s most influential authorities on cybersecurity, risk management and strategic crisis management, with a career spanning more than four decades at the forefront of information security. Widely recognised as one of the original architects of British Standard BS7799, the pioneering security framework that later became the globally adopted ISO 27000 series, David has played a pivotal role in establishing many of the best practices that underpin modern cybersecurity programmes. Throughout his career, he has built and led information security functions for major organisations including the Foreign & Commonwealth Office, Royal Dutch Shell and Royal Mail Group, while advising governments, multinational corporations and critical infrastructure providers. As Managing Director of David Lacey Consulting Limited, he continues to help organisations navigate complex cyber threats, governance challenges and operational risks. A highly regarded cybersecurity speaker, David combines deep technical expertise with boardroom-level strategic insight, making him a compelling choice for leadership summits, cybersecurity conferences, governance forums and risk management events worldwide.

David began his career in government, leading business systems analysis teams within the Home Office before moving to the Metropolitan Police, where he was responsible for criminal intelligence systems. He later joined the Foreign & Commonwealth Office as Head of Computer Security and Head of the Secure Systems Branch, developing secure applications and information security frameworks. These early roles gave him a unique understanding of security, intelligence and organisational risk, which continues to underpin his highly practical and strategic keynote presentations. He went on to hold senior leadership positions at Royal Dutch Shell and Royal Mail Group, designing and implementing cybersecurity architectures on a global scale. At Shell, he oversaw security programmes across more than 200 sites in 130 countries. At Royal Mail, he directed information security, governance, risk and compliance functions during a major £1.5 billion outsourcing programme. During this period, he helped develop BS7799 and delivered the world’s first and largest accredited certifications for both Shell and Royal Mail.

A respected author, researcher and industry thought leader, David has made a significant contribution to the cybersecurity profession through both his published work and wider influence on security best practice. He is the author of five books, including ‘Managing the Human Factor in Information Security’, which explored the critical role of people in organisational security, alongside ‘Managing Security in Outsourced and Off-shored Environments’, ‘Business Continuity Planning for Small and Medium Enterprises’, ‘Advanced Persistent Threats: How to Manage the Risks to Your Business’ and ‘A Practical Guide to the Payment Card Industry Data Security Standard’. His expertise and impact have been recognised through numerous industry accolades, including the SC Magazine Europe Award for Best Security Team, induction into the Infosecurity Europe Hall of Fame, the Open Group Award for Outstanding Contribution to Information Security and recognition as one of the Global Top 100 Most Powerful Voices in Security. These achievements reflect David’s longstanding influence on the development of the cybersecurity profession worldwide.

Alongside his consultancy work, David continues to play an active role in shaping the future of cybersecurity through advisory, academic and professional leadership positions. He serves on the advisory boards of several technology and security organisations, including Privus, Allied Contech and Citicourt & Co, while also providing strategic guidance on emerging technologies, digital resilience and cyber risk management. A Visiting Senior Research Fellow at the University of Portsmouth’s Institute of Criminal Justice Studies, David remains closely connected to the latest research and evolving threat landscape. As a Fellow and Chartered IT Professional of the British Computer Society, a Fellow of the Chartered Institute of Information Security Professionals and a Founding Director of the Chartered Institute of Information Security Professionals, he is recognised as one of the profession’s most authoritative voices. Event organisers value David for his rare ability to combine decades of hands-on leadership experience with forward-looking insight, delivering engaging presentations that help senior leaders understand complex cybersecurity challenges, strengthen governance and make informed strategic decisions.

To enquire about David Lacey for your event or corporate function, simply contact us via agent@cyber-security-speakers.com or call a booking agent on 0203 0070 318.