Home About Work Blog Contact
Open to conversations

GRC · Cybersecurity · AI Safety Governance

Sai
Rakshith.

Certified Information Systems Security Professional (CISSP) — ISC2
Trusted AI Safety Expert (TAISE) — Cloud Security Alliance
Certified in Cybersecurity (CC) — ISC2
MSc Strategic Risk Management — Robert Gordon University, Aberdeen
See My Work →
Sai Rakshith Gurijala
DORA Compliance ISO 27001:2022 ISO 22301 BCM ISO 42001 AI FCA / PRA OpRes NIST CSF 2.0 EU AI Act NIS2 / CS&R Operational Resilience Business Continuity Incident Response Third-Party Risk AI Safety Governance Risk Advisory DORA Compliance ISO 27001:2022 ISO 22301 BCM ISO 42001 AI FCA / PRA OpRes NIST CSF 2.0 EU AI Act NIS2 / CS&R Operational Resilience Business Continuity Incident Response Third-Party Risk AI Safety Governance Risk Advisory
Built through
HCL Technologies Analyst → Senior Analyst · Oct 2020–Sep 2021 · SIEM monitoring, 200+ weekly alerts triaged
· ISO 27001/NIST CSF/COBIT policy development
· Vulnerability assessments across 3 enterprise clients
· 35% reduction in mean response time
· Invesco Cyber Incident Response Analyst · Sep 2021–Nov 2022 · End-to-end incident investigation, PCI DSS scope
· NIST 800-61 framework across 3 regional SOC teams
· 40% reduction in false positive alert volume
· Trained 15 junior analysts on triage procedures
· Google Senior BCM Associate · Nov 2022–Aug 2023 · BIA across 12 critical service lines at scale
· ISO 22301-aligned IT-DR, 99.95% recovery success
· BCM governance: plan staleness 40% → under 10%
· Quarterly resilience metrics to senior leadership
· DivIHN Inc. BCM Consultant → Solutions Consultant · Oct 2024–Present · BIAs for 4 enterprise clients, 60+ business functions
· C-suite advisory on ISO 22301 maturity
· GRC consulting: ISO 27001, NIST CSF, SOC 2
· DORA and NIS2 alignment for financial services clients
Expertise

The Problems I Solve

01
📋
Governance & Compliance

Built ISO 27001 policy suites for enterprise clients, aligned BCM programmes to DORA and NIS2, and delivered prioritised remediation roadmaps directly to C-suite. Governance that gets approved and actually implemented.

DORA ISO 27001 FCA/PRA NIS2 COBIT
02
🔄
Resilience & Recovery

Led business impact analyses across 12 critical service lines at Google, achieving 99.95% recovery success rates. Reduced BCM plan staleness from 40% to under 10%. Recovery programmes that work when it matters most.

ISO 22301 NIST CSF BCM IT-DR BIA
03
🔬
AI Safety Governance

Researched AI governance for agentic AI systems at postgraduate level. Certified Trusted AI Safety Expert (TAISE). Building the oversight structures organisations need before regulators demand them.

ISO 42001 EU AI Act Model Risk TAISE
Work

Frameworks Built for Problems That Matter

Each one addresses a real gap.
Each one is open source.

DORA
VIEW PROJECT → ↓ Download Framework
01
In Development
DORA & FCA Compliance Framework

43% of UK financial services firms missed DORA's January 2025 deadline. This framework maps both regimes article-by-article — so organisations can close the gap without running two separate compliance programmes.

DORA FCA PS21/3 PRA SS1/21 ISO 22301
AI
VIEW PROJECT → ↓ Download Framework
02
In Development
AI Governance Framework

75% of UK financial services firms use AI. Only 37% have standardised policies. This management system gives organisations the structure to deploy AI responsibly — and prove it to regulators.

ISO 42001 EU AI Act FCA/PRA
ISMS
VIEW PROJECT → ↓ Download Kit
03
In Development
ISO 27001:2022 Implementation Kit

ISO 27001 is the most cited framework in UK GRC job descriptions. This kit covers all 93 controls, a complete Statement of Applicability, and 10 ready-to-use policies — everything needed for first-time certification.

ISO 27001 ISO 27005 NIST CSF
TPRM
VIEW PROJECT → ↓ Download Programme
04
In Development
Third-Party ICT Risk Programme

90% of UK security teams experienced supply chain incidents in 2025. This programme builds the vendor tiering, DORA Register of Information, and exit strategy methodology that organisations actually need.

DORA Ch.5 PRA SS2/21 ISO 27001
OpRes
VIEW PROJECT → ↓ Download Assessment
05
In Development
Operational Resilience Self-Assessment

The FCA/PRA compliance deadline passed March 2025. PS7/26 adds more obligations from March 2027. This self-assessment covers IBS identification, impact tolerances, and scenario testing — the whole framework.

FCA PS21/3 PRA SS1/21 ISO 22301
View all on GitHub →
About
"Security work taught me one thing above everything else: the technical answer is rarely the hard part."

I started my career watching security alerts scroll past on a SIEM screen at HCL Technologies. I ended up leading business continuity programmes at Google.

In between, I worked incident response at Invesco — investigating and containing security incidents across global investment management systems — and spent a year in Aberdeen deliberately studying the strategic side of risk.

Every role reinforced the same truth: the hard part isn't the technical answer. It's helping the right people understand the risk, trust the plan, and make the call.

That's what I do now at DivIHN Inc.

Oct 2020 11 months
Analyst → Senior Analyst
HCL Technologies
Sep 2021 1 yr 2 mos
Cyber Incident Response Analyst
Invesco
Nov 2022 9 months
Senior BCM Associate
Google
Sep 2023 1 year
MSc Strategic Risk Management
Robert Gordon University, Aberdeen
Oct 2024 9 months
BCM Consultant
DivIHN Inc.
Jul 2025 Present
Solutions Consultant
DivIHN Inc.
Perspectives

Trusted by People Who Know

"

Add your first LinkedIn recommendation here. A quote from a manager or colleague at Google, Invesco, or DivIHN carries real weight.

?
Colleague Name
Role · Organisation
"

Your second LinkedIn recommendation. Copy them directly from your LinkedIn recommendations section.

?
Colleague Name
Role · Organisation
"

Your third recommendation — a peer from your MSc, a DivIHN client, or a professional contact all work well.

?
Colleague Name
Role · Organisation

→ Copy directly from your LinkedIn recommendations

Contact

Got a risk problem?
Let's talk.

I work with organisations navigating complex governance, resilience, and AI safety challenges. If that sounds like yours — reach out directly or schedule a call.

Schedule a Call →
```