RS
Governance · Risk · Compliance · Data Protection

Dr. Ryan 
Shah

A researcher turned practitioner who reads regulation like a threat model, and builds assurance that holds up under scrutiny.

Dr Ryan Shah
FIG.01 A happy security practitioner
01

Practice

Who I am
and how I work

I sit where academic rigour meets the unglamorous reality of getting an organisation certified, compliant and genuinely more resilient.

I am a cyber security and governance, risk and compliance professional with experience spanning peer-reviewed research, regulatory compliance and industry consultancy. I hold a PhD in information and network security & privacy, and work as both a Lead GRC Consultant and Data Protection Officer.

I work well in time-critical environments, combining analytical depth with practical delivery across security, privacy and resilience programmes. My background includes leading client engagements, building standards-based assurance, and communicating complex technical and regulatory ideas to very different audiences.

The researcher

Ten peer-reviewed papers on side-channels, IoT safety and traffic analysis. I treat evidence as the product.

The practitioner

vCISO, vISM and DPO engagements across health, finance and industry. I turn frameworks into outcomes.

02

Trajectory

From the lab
to the boardroom
2025Present

Data Protection Officer

Sapphire · UK

Appointed DPO providing independent oversight and strategic advice on data protection compliance, ensuring adherence to UK and EU legislation including the GDPR. I lead privacy governance design, implementation and monitoring, covering policies, training, audits and records of processing. I own breach management and incident response, and lead the delivery of DPIAs and DSARs.

UK GDPRDPIADSARBreach responsePrivacy governance
2024Present

Senior Security Consultant

Sapphire · UK

Senior consultant within the GRC practice, leading complex client engagements across regulatory compliance, security assurance and risk management. Product owner for Third-Party Risk Management services, providing vCISO and vISM support across healthcare, finance and industrial sectors. I lead successful tender responses across ISO 27001, 27701, 22301, 22237 and 42001, and regulatory frameworks including the GDPR, DORA, NIS 2, the NCSC CAF and NIST CSF.

vCISOvISMTPRMDORANIS 2
20232024

Security Consultant

Sapphire · UK

Delivered GRC consultancy as subject-matter expert on DORA and the NIS 2 Directive. I led engagements covering ISO 27001, 22301 and 27701 across gap analysis, implementation, internal audit and certification support, plus security awareness training, business continuity planning and regulatory readiness across transport, logistics, education, healthcare, manufacturing and finance.

ISO 27001ISO 22301Internal auditBCM
20222023

Postdoctoral Researcher

Heriot-Watt University · Edinburgh

Research on the SECRIOUS project, investigating how new-code and non-traditional entrants engage with cyber security concepts in software engineering. I focused on helping people understand attacks, defences and vulnerabilities, contributing human-centred approaches to security education across cyber security, games research and HCI.

Secure SDLCHCIEducation
03

Research

Peer-reviewed
and indexed
SIG · A fun side-channel trace
2025

WaveVerif: Acoustic Side-Channel based Verification of Robotic Workflows

Z. Y. Erdogan, S. Nagaraja, C. M. Ahmed, R. Shah · arXiv preprint

Preprint
2023

Sensor Identification via Acoustic Physically Unclonable Function

G. Vaidya, T. V. Prabhakar, N. Gnani, R. Shah, S. Nagaraja · Digital Threats: Research and Practice

Journal
2022

Can You Still See Me? Reconstructing Robot Operations Over End-to-End Encrypted Channels

R. Shah, C. M. Ahmed, S. Nagaraja · ACM WiSec 2022

ACM
2022

Fingerprinting Robot Movements via Acoustic Side-Channel

R. Shah, M. Ahmed, S. Nagaraja · arXiv preprint

Preprint
2022

Reconstructing Robot Operations via Radio-Frequency Side-Channel

R. Shah, M. Ahmed, S. Nagaraja · arXiv preprint

Preprint
2021

VoIPLoc: Passive VoIP Call Provenance via Acoustic Side-Channels

S. Nagaraja, R. Shah · ACM WiSec 2021, Abu Dhabi

ACM
2020

A Unified Access Control Model for Calibration Traceability in Safety-Critical IoT

R. Shah, S. Nagaraja · ICISS 2020, 16th Intl. Conference on Information Systems Security

ICISS
2019

Clicktok: Click Fraud Detection using Traffic Analysis

S. Nagaraja, R. Shah · ACM WiSec 2019

ACM
2019

Secure Calibration for High-Assurance IoT: Traceability for Safety Resilience

R. Shah, M. McIntee, S. Nagaraja, S. Bhandary, P. Arote, J. Kuri · arXiv preprint

Preprint
2019

Do We Have the Time for IRM? Service Denial Attacks and SDN-based Defences

R. Shah, S. Nagaraja · ICDCN 2019, Intl. Conference on Distributed Computing and Networking

ICDCN
04

Capability

What I bring
to an engagement
C/01

Regulatory compliance

NIS / NIS 2UK & EU GDPRDORACCPAEU AI ActEU CRA
C/02

Standards & frameworks

ISO 27001ISO 27701ISO 22301ISO 22237ISO 42001NCSC CAFNIST CSFNIST SP 800-53
C/03

Security leadership

vCISOvISMInternal auditTPRMThreat modelling
C/04

Data protection

DPOvDPODPIADSARBreach responsePrivacy governance
C/05

Resilience

BCMIncident responseDisaster recoveryBCP testing
C/06

Technical foundation

PythonJavaReactNode.jsML / analyticsCI/CDSSDLC
05

Background

Where it
started
20182022

PhD, Cyber Security

University of Strathclyde

Thesis: Security of Robotic Workflows. Research into the security of robotic, cyber-physical and safety-critical systems, with an emphasis on calibration security and operational privacy. I explored passive side-channel threats, access control and blockchain-based approaches, using machine learning and signal processing.

Side-channelsCyber-physicalSignal processing
20142018

BSc Computer Science, First Class

Heriot-Watt University

A strong focus on software development, networking and cyber security. My final-year project designed and built a tool to identify and remediate IoT devices vulnerable to the Mirai malware in real time, with advanced coursework in network security, AI, machine learning and distributed systems.

NetworkingIoT securityDistributed systems
06

Credentials

Certifications
& memberships
M/01

Full Member, MCIIS

CIISec · 2025
M/02

Associate Fellow, AFHEA

Higher Education Academy · 2023
C/01

ISO 27001 Lead Auditor

IT Governance · 2026
C/02

Tech Risk & Compliance Professional

OneTrust · 2025
C/03

PIA & DPIA Automation Expert

OneTrust · 2025
C/04

TPRM Professional

OneTrust · 2024
C/05

Cyber Security Professional Certificate

Google · 2024
C/06

PGCert in Researcher Professional Development

University of Strathclyde · 2022
07

Field Notes

Writing on GRC,
privacy & research