David Lacey is one of the UK’s most influential authorities on cybersecurity, risk management and strategic crisis management, with a career spanning more than four decades at the forefront of information security. Widely recognised as one of the original architects of British Standard BS7799, the pioneering security framework that later became the globally adopted ISO 27000 series, David has played a pivotal role in establishing many of the best practices that underpin modern cybersecurity programmes. Throughout his career, he has built and led information security functions for major organisations including the Foreign & Commonwealth Office, Royal Dutch Shell and Royal Mail Group, while advising governments, multinational corporations and critical infrastructure providers. As Managing Director of David Lacey Consulting Limited, he continues to help organisations navigate complex cyber threats, governance challenges and operational risks. A highly regarded cybersecurity speaker, David combines deep technical expertise with boardroom-level strategic insight, making him a compelling choice for leadership summits, cybersecurity conferences, governance forums and risk management events worldwide.
David began his career in government, leading business systems analysis teams within the Home Office before moving to the Metropolitan Police, where he was responsible for criminal intelligence systems. He later joined the Foreign & Commonwealth Office as Head of Computer Security and Head of the Secure Systems Branch, developing secure applications and information security frameworks. These early roles gave him a unique understanding of security, intelligence and organisational risk, which continues to underpin his highly practical and strategic keynote presentations. He went on to hold senior leadership positions at Royal Dutch Shell and Royal Mail Group, designing and implementing cybersecurity architectures on a global scale. At Shell, he oversaw security programmes across more than 200 sites in 130 countries. At Royal Mail, he directed information security, governance, risk and compliance functions during a major £1.5 billion outsourcing programme. During this period, he helped develop BS7799 and delivered the world’s first and largest accredited certifications for both Shell and Royal Mail.
A respected author, researcher and industry thought leader, David has made a significant contribution to the cybersecurity profession through both his published work and wider influence on security best practice. He is the author of five books, including ‘Managing the Human Factor in Information Security’, which explored the critical role of people in organisational security, alongside ‘Managing Security in Outsourced and Off-shored Environments’, ‘Business Continuity Planning for Small and Medium Enterprises’, ‘Advanced Persistent Threats: How to Manage the Risks to Your Business’ and ‘A Practical Guide to the Payment Card Industry Data Security Standard’. His expertise and impact have been recognised through numerous industry accolades, including the SC Magazine Europe Award for Best Security Team, induction into the Infosecurity Europe Hall of Fame, the Open Group Award for Outstanding Contribution to Information Security and recognition as one of the Global Top 100 Most Powerful Voices in Security. These achievements reflect David’s longstanding influence on the development of the cybersecurity profession worldwide.
Alongside his consultancy work, David continues to play an active role in shaping the future of cybersecurity through advisory, academic and professional leadership positions. He serves on the advisory boards of several technology and security organisations, including Privus, Allied Contech and Citicourt & Co, while also providing strategic guidance on emerging technologies, digital resilience and cyber risk management. A Visiting Senior Research Fellow at the University of Portsmouth’s Institute of Criminal Justice Studies, David remains closely connected to the latest research and evolving threat landscape. As a Fellow and Chartered IT Professional of the British Computer Society, a Fellow of the Chartered Institute of Information Security Professionals and a Founding Director of the Chartered Institute of Information Security Professionals, he is recognised as one of the profession’s most authoritative voices. Event organisers value David for his rare ability to combine decades of hands-on leadership experience with forward-looking insight, delivering engaging presentations that help senior leaders understand complex cybersecurity challenges, strengthen governance and make informed strategic decisions.
The Cyber Security Speakers Agency is the UK’s top speakers’ bureau specialising in digital data protection experts – named as the No.1 cyber security speakers agency in 2025!
We supply cyber security speakers for in-person and virtual corporate conferences across the globe. With our roster including former hackers, Chief Information Security Officers and more, we ensure audiences of all industries receive tailored advice on cyber security.