About
Three decades at the intersection of regulation, the boardroom and the lab.
Senior regulator, former board director, and hands-on practitioner. Available from August 2026 for board, advisory and executive engagements globally.
Biography
I began my career in the mid-1980s, studying Computer Science and Engineering at IIT Kanpur and then Management at IIM Calcutta. Those two foundations — one in how systems work, one in how organisations do — have shaped everything since.
My early career was spent across banking and insurance: senior roles in investment banking, Head of Asset Management, Head of Business Risk and Controls, and ultimately Board Director within subsidiaries of the BNP Paribas Group. During those years I sat on boards, managed capital, navigated credit and market risk through difficult cycles including the 2008 global financial crisis, and represented the UK as a National Expert at the European Commission. I came to understand that technology and operational failure are as dangerous to a firm as financial loss — and far harder to see coming.
In 2011 I joined the Bank of England's Prudential Regulation Authority. Fifteen years on, I have specialised in the disciplines that most organisations still treat as compliance obligations rather than business imperatives: operational resilience, cyber risk, IT and outsourcing risk across the insurance sector. I have reviewed the operational resilience of more than 150 firms — life, annuity, motor, managing agents, asset managers and run-off — and led the PRA's work across more than a dozen CBEST and STAR-FS assignments. I have managed the regulatory response to hundreds of incidents and material outsourcing notifications. I represented the UK on EIOPA's Cyber and IT Project Group and on the cyber stream of the EU–US Insurance Project, giving me first-hand insight into how regulators in different jurisdictions approach the same problems.
What distinguishes me from most practitioners in this space is that I do not only advise — I build. Since 2019 I have run a private research laboratory in which I test every recommendation I give before I give it. I coined the term Cryptoagility to describe an organisation's ability to swap out its cryptographic algorithms, and I practise it. I created the world's first public platform for generating NIST FIPS-compliant post-quantum cryptographic key pairs (Kyber.Club), implemented quantum-safe server configurations years ahead of industry timelines, and operate infrastructure that independent evaluations consistently place at the top of any security benchmark.
I will be leaving the PRA in July 2026 after fifteen years of service. From August 2026 I am available for board, advisory, speaking and executive engagements globally. My goal is to bring what I have spent three decades building — the regulator's instinct for risk, the builder's understanding of what is actually possible, the director's experience of how boards make decisions — to organisations that take resilience seriously.
What I believe
-
01
Resilience is a business priority, not a compliance exercise. Firms that treat operational and cyber resilience as a regulatory obligation will always be one step behind. Firms that treat it as a strategic imperative build something that actually works when it matters.
-
02
Prove first; speak later. I do not recommend what I have not tested. Every advisory position I hold on technology risk is grounded in hands-on experimentation in my own laboratory. This is rarer than it should be.
-
03
Don't ignore the quantum threat — and don't panic. The "harvest now, decrypt later" attack is already underway. The 2030–2035 compliance deadlines are too comfortable. But the transition is achievable by 2028 with the right programme — and most of the building blocks already exist.
-
04
AI is useful but not yet intelligent. True intelligence acknowledges what it does not know. Current AI does not. Boards that deploy AI without human oversight and clear accountability frameworks are making a category error — and a risk management failure.
-
05
Credibility is earned at every event, not granted by titles. No matter how senior the role, the obligation to learn, experiment and share continues. I will try to lead the world in what I do — and not expect everyone to follow me.
Recognition and selected engagements
Acknowledged in published Bank of England speeches on operational resilience, including the 2022 PRA Insurance Supervision priorities address and the 2025 CMORG systemic resilience keynote. Advisory Board member, Cyber London Quantum Think Tank. UK representative, EIOPA Cyber & IT Project Group and EU–US Insurance Project (cyber stream).
Selected speaking platforms: ABI · IIAG · IRLA · Cyber Leaders Summit · MFSA Cyber Finance Summit · AFM · Crowe · Deloitte · QA Financial Forum · CCBS · ISORG · Somerford · University of Manchester PhD Research Panel.
What colleagues say
"Santosh is one of those rare people who walk the walk. As an esteemed thought leader in the industry, he is also gracious with his advice and supportive of others on their security and resilience journey."
LinkedIn recommendation — name and title available on request
"Santosh is a well-deserved and respected leader in the fields of operational and cyber risks. His philosophy — 'I will try to lead the world in what I do, and not expecting everyone to follow me' — underscores his humility and influence. He keeps everyone grounded."
LinkedIn recommendation — name and title available on request
Education & credentials
-
Degree
B.Tech, Computer Science & Engineering — Indian Institute of Technology, Kanpur
-
Postgraduate
MBA — Indian Institute of Management, Calcutta (1987–89)
-
Current role
Senior Manager, Risk Specialists team (Cyber & Operational Resilience) — Prudential Regulation Authority, Bank of England (until July 2026)
-
Prior roles
Board Director (BNP Paribas Group subsidiaries) · Head of Asset Management · Head of Business Risk & Controls · Senior Manager, Investment Banking · UK National Expert, European Commission
-
Sectors
Banking · Insurance · Asset Management · Regulation
Available from August 2026 for board, advisory, speaking and executive engagements globally.
See how I can help →