Skip to content

Founder · Security advisor · Product builder

Krish
Pasumarthi.

Data security and AI governance

I help organisations turn security, privacy and AI governance requirements into practical controls and evidence they can rely on.

22+
years in security and assurance
100+
critical banking supplier assessments
UK + NZ
consulting and client delivery
ISO 42001
Lead Auditor qualification

01 / Expertise

Protect the data.
Make governance work.

My work combines architecture assurance, privacy engineering and risk management with experience leading client programmes and building trust software.

01

Data security and privacy

Data protection requirements, DLP policy design, access and sharing controls, privacy risk, and evidence of control effectiveness.

CDPSE · IAM assurance · Security architecture

02

AI governance and assurance

AI use-case risk, accountability, human oversight, supplier due diligence and assurance requirements informed by ISO/IEC 42001.

ISO 42001 · AI risk · Governance

03

Client delivery and GRC

Discovery workshops, control design, implementation priorities, stakeholder alignment, audit coordination and clear residual-risk decisions.

SOC 2 · ISO 27001 · NZISM

Microsoft Purview programme focus

Connect policy intent with technical protection.

I bring policy design, privacy and risk assessment, stakeholder engagement and control validation to Purview Information Protection, DLP and Copilot data-security workstreams. This builds on my established architecture and assurance experience.

02 / International experience

UK consulting roots.
New Zealand delivery.

UNITED KINGDOM

PwC UK

January 2011 – October 2014

Manager, Risk Assurance. UK client engagement, control assessment and assurance reporting.

NEW ZEALAND

Regulated environments

Banking · Transport · Government · Technology

National programme advisory, supplier security, architecture reviews and fractional security leadership.

INDIA

Consulting foundations

PwC · Deloitte · Grant Thornton

IT advisory, risk assurance and cyber consulting, progressing to Associate Director.

Apr 2026 – Present

NZTA / Waka Kotahi

Lead Security Advisor, NTS Programme

Security advisory, system-level risk assessment and residual-risk advice for the National Ticketing Solution programme and public transport integration.

Jul 2025 – Mar 2026

Auckland Transport

Principal Security Advisor

Third-party risk framework, supplier security assessments, control design and risk reporting across transport technology.

Mar 2025 – Jul 2025

Gaming sector client

Senior Cyber Security Architect

Architecture assurance and vendor security advice for high-availability enterprise platforms, aligned with NIST 800-53.

Jun 2022 – Jan 2025

Technology SME

Fractional Security and Compliance Officer

SOC 2 audit coordination, control and evidence readiness, privacy and security policies, and vendor risk assessments.

Mar 2020 – Apr 2023

Large New Zealand bank

Senior Information Security Consultant

More than 100 critical-supplier security assessments, IAM assurance supervision and senior-leadership risk reporting.

Earlier consulting appointments
2019–2020KPMG New Zealand

Associate Director, Risk Consulting Cyber

2017–2019PwC New Zealand

Senior Manager, Risk Assurance

2014–2017Grant Thornton India

Associate Director, IT Advisory and Cyber Security

2011–2014PwC UK

Manager, Risk Assurance

2008–2011PwC India

Senior Consultant, Risk and Regulatory Services

2007–2008Deloitte India

Senior Analyst, Enterprise Risk Services

Some consulting appointments overlap. CybrGen and MyTrustForge are concurrent founder-led activities. Earlier Auckland Transport reviews took place in 2019 and 2024.

03 / Selected assurance work

Specific problems.
Practical security decisions.

Examples are summarised without confidential client architecture or supplier details.

Identity and application security

JWT signing design

Identified that a symmetric JWT signing design lacked a shared-secret distribution approach. The design subsequently changed to asymmetric signing.

Focus: key distribution and trust boundaries.

Authentication controls

MFA and token lifetime

Challenged proposed 24-hour confirmation codes and email-based MFA, recommending shorter token lifetimes and stronger authentication controls.

Focus: practical safeguards against credential misuse.

Supplier and control assurance

Banking supplier risk

Completed more than 100 critical-supplier assessments using CPS 234, NZISM and ISO 27001-aligned criteria, with senior-leadership reporting.

Focus: evidence, treatment priorities and residual risk.

04 / Professional foundation

Security, privacy and AI governance.

ISO/IEC 42001

Lead Auditor

AI management systems

CDPSE

Certified Data Privacy Solutions Engineer

Privacy and data protection

CRISC

Certified in Risk and Information Systems Control

Technology risk and controls

CEH

Certified Ethical Hacker

Security assessment

Post Graduate Diploma in Business Administration
ICFAI Business School, Hyderabad, India

Bachelor of Science
Nagarjuna University, Andhra Pradesh, India

05 / Founder and product perspective

Controls need an operating model.

I founded MyTrustForge to connect framework requirements with reusable controls, risks, ownership and evidence. My product work includes AI readiness and AI-assisted policy generation.

Engagement model for data security and AI governance
Client risk and governance objectivesScope · Ownership · Policy · Risk decisions
TECHNICAL WORKSTREAM

Microsoft Purview

  • Information protection requirements
  • DLP policy and control validation
  • Copilot data protection and auditability
ASSURANCE WORKSTREAM

MyTrustForge

  • Reusable controls and framework mappings
  • Risk ownership and evidence workflows
  • Assessment and remediation tracking
Review control effectivenessEvidence · Exceptions · Improvement priorities

Illustrative delivery approach. Any use alongside Purview would be scoped to complement the client’s existing tools; this does not represent an existing product integration.

Explore MyTrustForge

Client engagements and delivery partnerships

Start with the client’s
data security challenge.

Based in Auckland, with UK and New Zealand delivery experience and an engagement focus across the UK, Australia and New Zealand.