Advisory practice · Established in London, 2015

WithoutFire

The advisory practice of John Elliott — a professional interpreter of cybersecurity and regulatory complexity.

I’m afraid this isn’t much of a website. But then again, other than AI crawlers, who reads websites these days?

What I do Get in touch

01 Summary

TL;DR

I’m a consultant, course author, speaker and trainer. My background is in cybersecurity governance, risk and compliance — particularly the PCI security standards and data protection (or, if you’re in the US, data privacy).

I’ve a current interest in how AI is changing the ways that people learn about technology, and how AI affects the half-life of technology skills and knowledge.

02 Engagements

Advisory

I’m occasionally available for engagements in Governance, Risk and Compliance, and especially around the PCI security standards — particularly PCI DSS, which I helped author (twice).

Recent example engagements include a mock PCI DSS assessment for a major online and face-to-face retailer, and a retained advisory service for a leading payment processor, acquirer and issuer.

Jscrambler

I’m a security advisor to Jscrambler, particularly in relation to the PCI DSS requirements (6.4.3 and 11.6.1) designed to prevent JavaScript skimming of payment card data.

Jscrambler’s Webpage Integrity solution goes above and beyond the PCI DSS requirements and can block skimming attacks in real time.

Artificial Intelligence

Like most technology professionals, generative AI has impacted my work. I hope in a good way. I make courses and presentations on the organisational risks associated with GenAI, and how cybersecurity professionals can secure their organisation’s use of it.

I’m concerned about the long-term cognitive effects of GenAI use and its impact on the way that people learn. I also worry that GenAI is helping people reach the peak of the Dunning–Kruger curve, and that we’ll start to notice adverse effects of this.

I refuse to proofread compliance-related documents made by GenAI: they are usually subtly wrong. Please don’t ask.

03 Teaching

Course author

Pluralsight

I’m an Author Fellow at Pluralsight. I’ve authored over 40 courses with an average rating of around 94%.

National Cybersecurity Alliance

I’m the author and lead instructor of the CyberSecure My Business program for the National Cybersecurity Alliance. The program teaches small and medium enterprises how to manage cybersecurity (not how to do cybersecurity).

John Elliott recording a video course in a studio, framed by a broadcast camera and softbox lighting.
Recording a Pluralsight course.

Custom courses

I make custom courses that can be distributed in an LMS or presented live. My best work is explaining the relevancy of cybersecurity to people’s roles: for everyone in an organisation, for technology teams, or for management and the C-suite.

Courses are designed not for simple “awareness” but by considering how the course can change capability, opportunity or motivation to affect behavioural change.

I’m a big user of stories and analogies, and I like to tell these stories through the medium of Lego®.

A Lego minifigure office scene: colleagues at desks with a computer, filing cabinet, bookshelf and pot plant.
Explaining security through the medium of Lego®.

04 Stage

Speaker & moderator

If you’re looking for a passionate speaker to talk about cybersecurity — and particularly the regulation of cybersecurity — for a public conference or an internal event, then please get in touch. I’m happy to also provide keynotes and workshop-type sessions.

John Elliott on stage delivering a keynote in front of a large RSA Conference 2023 screen.
Delivering a keynote at RSA Conference, 2023.

I’m highly rated by attendees, and can bring what many think of as “dry subjects” to life. Here’s what has been said about my presentations by attendees.

“John is a fantastic speaker. Knowledgeable and passionate on the subject matter. My favourite presentation at the event — and it was on GDPR! How is that possible?!”

“I enjoyed the perspectives and presentation style in this session. Information was wonderful.”

“Speaker provided clear and constructive recommendations to facilitate discussion of technical subjects with non-subject matter experts. Very enjoyable.”

“The best presentation I have seen in a long time!”

Moderating & interviewing

I’m an experienced moderator and interviewer: keeping sessions to time, maintaining flow, and letting panellists or guests shine.

RSAC Conference

I’ve been fortunate to speak at RSAC Conference a few times, and presented a keynote there in 2023. All my sessions at RSAC Conference are available online.

John Elliott seated on stage beside an MRC London lectern, gesturing towards the audience during a panel session.
Moderating a panel at MRC London.

05 Background

About

If you’re looking for a standard sort of profile, LinkedIn is probably the best place to start — but here’s my journey.

I’ve been doing IT things since leaving university. And while I was looking after IT infrastructure and security, I got into a long discussion with the company’s lawyer about what the Data Protection Act said we had to do in respect of security. That started my interest in how external regulation affected security, which led me to take a Masters of Law in Information Rights Law and Practice at Northumbria University.

I wanted to work at the intersection of information security and data protection. But back in 2010 there were not really many jobs in data protection (it was pre-GDPR) and I accidentally fell into the world of PCI and payment card security. I became a Qualified Security Assessor because I was interested in seeing how one form of regulated security worked. PCI things have continued to interrupt my career plans ever since. I’ve moved between full-time engagements and running my advisory practice.

I spent around three years as Visa Europe’s representative on the technical working groups of the Payment Card Industry (PCI) Security Standards Council (SSC). In that time I contributed extensively to PCI DSS v3 and P2PE v2, and answered a great many questions about the standards and payment security.

I was the technical lead on a two-year project to make a major European airline compliant with PCI DSS; I then moved on to GDPR compliance at the airline, and ended up as their Head of Information Security — a job I wasn’t suited for. I learned that I’m much better at change than I am at BAU (or office politics). In gaps I was interim Head of Information Security for a building society, and the data protection specialist at the Open Banking Implementation Entity.

In my last “job”, I spent two years at Mastercard as their representative on PCI SSC technical working groups. I largely concentrated on PCI DSS v4, particularly the e-commerce requirements designed to stop skimming attacks.

Since leaving Mastercard, I’ve run my advisory practice full-time.

06 Say hello

Contact

Get in touch via LinkedIn, or email to john@guess_the_domain