Get in touch with Sapphire for consultancy with me!

Dr. Ryan Shah
Cybersecurity & GRC

Data Protection Officer & Senior Security Consultant with expertise spanning academic research, regulatory compliance, and industry consultancy. Specialising in ISO 27001, DORA, NIS 2, and NCSC CAF frameworks.

Dr. Ryan Shah

Bridging Research & Practice

I am a cybersecurity and governance, risk and compliance (GRC) professional with experience spanning academic research, regulatory compliance, and industry consultancy.

I have a proven ability to operate effectively in time-critical environments, combining strong analytical skills with practical delivery across security, privacy, and resilience programmes.

My background includes peer-reviewed cybersecurity research, regulatory and standards-based assurance, and leading client engagements, supported by experience in teaching and communicating complex technical and regulatory concepts to diverse audiences.

PhD
Cybersecurity Research
10+
Years in Security
DPO
Data Protection Officer
MCIIS
Chartered Member

Career Journey

From academic research to industry leadership in cybersecurity and GRC.

Data Protection Officer

2025 – Present

Sapphire | United Kingdom

Appointed DPO providing independent oversight and strategic advice on data protection compliance. Responsible for ensuring adherence to UK and EU data protection legislation including GDPR. Lead privacy governance design, implementation, and monitoring including policies, training, audits, and records of processing. Own breach management and incident response, and lead delivery of DPIAs and DSARs.

Senior Security Consultant

2024 – Present

Sapphire | United Kingdom

Senior consultant within the GRC practice, leading complex client engagements across regulatory compliance, security assurance, and risk management. Product owner for Third-Party Risk Management services. Provide vCISO and vISM services across healthcare, finance, and industrial sectors. Lead successful tender responses across ISO 27001, ISO 27701, ISO 22301, ISO 22237, ISO 42001, and regulatory frameworks including GDPR, DORA, NIS 2, NCSC CAF, and NIST CSF.

Security Consultant

2023 – 2024

Sapphire | United Kingdom

Delivered GRC consultancy as SME in DORA and NIS2 Directive. Led engagements covering ISO 27001, ISO 22301, and ISO 27701 across gap analysis, implementation, internal audit, and certification support. Delivered security awareness training, business continuity planning, and regulatory readiness across transport, logistics, education, healthcare, manufacturing, and finance sectors.

Postdoctoral Researcher

2022 – 2023

Heriot-Watt University | Edinburgh

Research role on the SECRIOUS project investigating how new-code and non-traditional entrants engage with cybersecurity concepts in software engineering. Focused on enabling individuals to understand attacks, defences, and vulnerabilities. Contributed to innovative, human-centred approaches to cybersecurity education working across cybersecurity, games research, and HCI disciplines.

Research & Publications

Peer-reviewed work in robotics security, side-channel attacks, and IoT privacy.

2025

WaveVerif: Acoustic Side-Channel based Verification of Robotic Workflows

Z.Y. Erdogan, S. Nagaraja, C.M. Ahmed, R. Shah

arXiv preprint

2023

Sensor Identification via Acoustic Physically Unclonable Function (PUF)

G. Vaidya, T.V. Prabhakar, N. Gnani, R. Shah, S. Nagaraja

Digital Threats: Research and Practice (DTRAP)

2022

Can You Still See Me?: Reconstructing Robot Operations Over End-to-End Encrypted Channels

R. Shah, C.M. Ahmed, S. Nagaraja

ACM WiSec 2022

2022

Fingerprinting Robot Movements via Acoustic Side Channel

R. Shah, M. Ahmed, S. Nagaraja

arXiv preprint

2022

Reconstructing Robot Operations via Radio-Frequency Side-Channel

R. Shah, M. Ahmed, S. Nagaraja

arXiv preprint

2021

VoIPLoc: Passive VoIP Call Provenance via Acoustic Side-Channels

S. Nagaraja, R. Shah

ACM WiSec 2021 — Abu Dhabi, UAE

2020

A Unified Access Control Model for Calibration Traceability in Safety-Critical IoT

R. Shah, S. Nagaraja

ICISS 2020 — 16th International Conference on Information Systems Security

2019

Clicktok: Click Fraud Detection using Traffic Analysis

S. Nagaraja, R. Shah

ACM WiSec 2019

2019

Secure Calibration for High-Assurance IoT: Traceability for Safety Resilience

R. Shah, M. McIntee, S. Nagaraja, S. Bhandary, P. Arote, J. Kuri

arXiv preprint

2019

Do we have the time for IRM?: Service Denial Attacks and SDN-based Defences

R. Shah, S. Nagaraja

ICDCN 2019 — International Conference on Distributed Computing and Networking

Technical Expertise

Comprehensive skills across compliance, security, and technology.

Regulatory Compliance

NIS / NIS 2 GDPR DORA CCPA EU AI Act EU CRA

Standards & Frameworks

ISO 27001 ISO 27701 ISO 22301 ISO 22237 ISO 42001 NCSC CAF NIST CSF

Security Leadership

vCISO vISM Internal Audit TPRM Threat Modelling

Data Protection

DPO Services DPIA DSARs Breach Response Privacy Governance

Resilience

BCM Incident Response Disaster Recovery BCP Testing

Technical Skills

Python Java React Node.js ML/Analytics SSDLC

Academic Background

PhD, Cybersecurity

University of Strathclyde

2018 – 2022

Thesis: "Security of Robotic Workflows" — Research focused on security of robotic, cyber-physical, and safety-critical systems, with emphasis on calibration security and operational privacy. Explored passive side-channel threats, access control, and blockchain-based approaches using machine learning and signal processing techniques.

BSc Computer Science (1st Class)

Heriot-Watt University

2014 – 2018

Strong focus on software development, networking, and cybersecurity. Final-year project designed and implemented a tool to identify and remediate IoT devices vulnerable to Mirai malware in real time. Advanced coursework in network security, AI, machine learning, and distributed systems.

Professional Credentials

ISO 27001 Lead Auditor

IT Governance • 2026

Tech Risk & Compliance Professional

OneTrust • 2025

PIA & DPIA Automation Expert

OneTrust • 2025

Cybersecurity Professional Certificate

Google • 2024

TPRM Professional

OneTrust • 2024

Full Member (MCIIS)

CIISec • 2025

Associate Fellow (AFHEA)

Higher Education Academy • 2023

Let's Connect

Interested in discussing cybersecurity, GRC, or potential collaborations? Reach out through Sapphire or connect on social media.