Cybersecurity Strategy & GRC
Risk-informed strategy, governance, assurance and implementation across enterprise environments.
About Billy Teow
I work at the intersection of cybersecurity strategy, enterprise risk, compliance and human risk. My experience spans four years in advisory environments and four years in-house, so I’ve seen both how security recommendations are made and what it takes to make them work.
What I do
My work sits between security expectations and the reality of how organisations make decisions, manage risk and get things done.
Risk-informed strategy, governance, assurance and implementation across enterprise environments.
Connecting security expectations with behaviour, participation and the realities of how teams work.
A focused area of learning and experimentation, grounded in established security and governance thinking.
How I work
I prefer practical security over theoretical perfection. A control can be technically strong but difficult to use; a process can satisfy a requirement while creating unnecessary friction. Good security means understanding those trade-offs and finding an approach that works for the organisation and the people using it.
Metrics are easy to produce. Making them useful is harder.How I think about security
Make the risk understandable to the person making the decision.
Turn governance into something teams can actually use.
Design for how work happens, not how a policy document imagines it.
Keep ownership with the right decision-maker.
Perspective
Advisory work taught me to frame problems, guide stakeholders and make recommendations practical. In-house work taught me to live with the trade-offs, dependencies and follow-through that come after the recommendation.
I’m now looking to bring that combined perspective into technology and product-led environments where security has to move with the business.
Framing complex problems, guiding stakeholders and translating risk into practical recommendations.
Working through dependencies, trade-offs and the follow-through required to make security work inside an organization.
Applying that combined perspective to product-led and SaaS environments where security, trust and change meet.
I’m CISM-certified, with Microsoft and AWS credentials across cybersecurity architecture, cloud security and security fundamentals. These credentials support my experience; they are not a substitute for it. Links point to issuer records or badge pages, while the Credly profile is the complete credential index.
Beyond work
Cybersecurity is what I do professionally, but it isn’t the only thing I’m interested in.
I enjoy manual brewing and pour-over. One day, when I retire, I’d love to run a small café built around genuinely good coffee and a welcoming place to spend time.
I’m naturally curious about technology and enjoy comparing approaches, experimenting with ideas and learning what makes a system useful.
Sometimes that means a technical project. Sometimes it is a spreadsheet, workflow or automation that solves a very specific problem.
Why this website exists
This website brings together my professional experience, practical security work, things I’m learning and projects I’m building. I don’t expect everything here to fit neatly into one category, and like most personal projects, it will keep changing.

For professional opportunities, industry discussions or collaboration, connect with me on LinkedIn.
Connect on LinkedIn ↗