Tony Cleal

Managing Director. Principal Cyber and Information Security Advisor

Threat Intelligence, National Security, Resilience and Strategic Lead

Tony is former British Intelligence having worked for the UK National Cyber Security Centre (NCSC), part of GCHQ, and with the Centre for the Protection of National Infrastructure (CPNI) to protect UK critical infrastructure against attacks from nation states, terrorists and criminal groups. Whilst working for the Security Services, Tony also led on two National Protect Law Enforcement operations with the UK National Crime Agency (NCA) to disrupt organised cyber criminal groups operating via the UK.

Prior to this Tony spent 16 years working in IT in the Offshore Financial Service industry, working in the Channel Islands, the Isle of Man, Switzerland, Luxembourg, Liechtenstein, the US, Canada and across the Caribbean. Before moving back to Guernsey from London in 2018, Tony deepened his experience in financial services through his role as Infrastructure Security Manager for M&G Prudential, a UK FTSE100 financial services company with 27,000 staff and $321 billion worth of assets under management.

Tony led the successful cyber security thematic review in Guernsey for the GFSC in 2018/2019. This included on site meetings 40 different firms and conducting interviews with nearly 160 individuals across Board members, IT, Compliance and Risk to assess their cyber security capability and maturity, and to see how their practices aligned against internationally agreed standards. The review culminated in the presentation of findings to all regulated and registered firms, and provided the basis for revised rules based policies around cyber management as a key operational risk to regulated firms.

Given his ability to marry his insights from years in British Intelligence and UK Central Government, the financial services industry and insights from the GFSC thematic review, Tony is uniquely placed to guide firms and private clients on safeguarding their operations and assets, and in evidencing compliance with applicable regulatory requirements.

Professional Qualifications

  • (ISC)2 CISSP - Certified Information Systems Security Professional

  • (ISC)2 SSCP - Security Systems Certified Practitioner

  • ISACA CISA - Certified Information Systems Auditor

  • ISACA CISM - Certified Information Security Manager

  • GIAC GCIH - GIAC Certified Incident Handler