Farhan Qureshi

Independent Director Candidate · HyderabadCyber resilience · Cloud · Incident response

FarhanQureshi

Former CTO and later CISO of a Hyderabad IT-services company. I help boards treat cyber and technology risk the way they already treat credit and liquidity: as a number with an owner and a limit.

  • In technology23 years
  • Last rolesCTO, then CISO
  • IICA DatabankRegistered

Most boards have approved a cyber budget. Few have decided how many hours the company can afford to be dark. That number is the real policy.

Farhan Qureshi · on what a board should settle before an incident

01 The story

An engineer who learned to answer to a risk committee

My first job was building the switch that moves money between ATMs and banks. Everything since has been a version of the same question: what happens to the business when this system stops?

I started in Hyderabad in 2003, writing switching and reconciliation software for card and ATM networks at a small payments product company. In 2006 I moved to Bengaluru as a network architect for a multinational telecom equipment maker and designed core networks for Indian mobile operators through the national 3G roll-out. That work taught me how large systems fail: rarely all at once, and usually at the joins.

In 2011 I came home to run infrastructure and disaster recovery at the Hyderabad delivery centre of a global IT consulting firm, for client programmes in banking and insurance. I designed the first recovery drills the centre ran with clients in the room. Few things test a plan as honestly as an audience that pays for it.

In 2018 a mid-sized IT-services company appointed me Chief Technology Officer. I wrote the three-year cloud programme its board approved, closed two owned data centres and put technology spend in front of the CFO every month. In 2022 the board asked me to move across and build the security function as CISO, and for the next four years I presented the technology and cyber risk register to its risk management committee every quarter.

Those meetings changed how I think about boards. Directors asked sharp questions when the material allowed them to, and polite ones when it did not. I am now seeking a first independent directorship with a listed or large unlisted company where technology, data and third-party risk are material to the business, so that I can ask those questions from the other side of the table.

Twenty-three years, drawn to scale2003 to 2026

  1. 2003Payment switches
  2. 2006Mobile core networks
  3. 2011Infrastructure and disaster recovery
  4. 2018Chief Technology Officer
  5. 2022Chief Information Security Officer

02 Defining moments

Three moments that taught me what a board needs to hear

A migration, a briefing and an incident. Each changed the way I explain technology risk to the people who have to govern it.

Migration · 2019 to 2021

Two data centres, switched off

The board approved a three-year cloud programme on a condition I had written into the business case myself: an exit plan for every major contract before signature. We closed both owned data centres and moved the delivery platforms to public cloud. The monthly review I set up with the CFO found the two places where savings had been assumed and never earned.

Board briefing · First quarter as CISO

The register that stopped listing controls

My first risk register for the risk management committee ran to forty controls and told directors very little. I rewrote it around three questions for each risk: what we would lose, how fast, and what recovery would cost. At the next meeting the committee asked management for a recovery tolerance, and agreed one within two quarters.

Incident · A client-facing subsidiary

Three in the morning, on the bridge

A ransomware intrusion took down systems at a client-facing subsidiary. I ran the response: isolate, preserve evidence, tell clients before they heard it elsewhere, restore. Services were back inside the recovery window the committee had agreed. The full post-incident review, including what we got wrong, went to the board the following month.

03 What I bring to a board

Three things a board can hold me to

  1. 01

    Cyber risk stated in hours and rupees, so the board can set a limit on it.

    Evidence

    Four years presenting the technology and cyber risk register to a board risk management committee, rebuilt so the committee could agree a recovery tolerance and hold management to it.

  2. 02

    A second, sceptical reading of every technology business case.

    Evidence

    Wrote and delivered the cloud business case a board approved. I know where savings get assumed, and I ask for the exit plan and the vendor concentration before a contract is signed.

  3. 03

    A calm, specific plan for the first twenty-four hours of an incident.

    Evidence

    Ran the response to a ransomware intrusion, ran recovery drills with clients present from 2011, and prepared breach handling for the Digital Personal Data Protection Act, 2023. I can help a board decide in advance who speaks to customers, regulators and the market, and when.

04 Board readiness

Where I would serve, and the facts behind it

An Independent Director Candidate seeking a first appointment. Committee fit is stated as Primary and Supporting, each with the experience that supports it.

Primary committees

Risk Management Committee

SEBI LODR Reg 21

Four years presenting the cyber and technology risk register to a board risk management committee, including a full post-incident review.

IT Strategy / Cyber Committee

Where a company has constituted one

Authored the three-year technology roadmap a board approved, and tracked it against budget and risk appetite through delivery.

Supporting committee

Audit Committee

Companies Act 2013 s.177 · SEBI LODR Reg 18

Worked each year with internal and statutory auditors on IT general controls, access reviews and third-party assurance reports.

IICA Independent Directors Databank
RegisteredRegistered in the databank maintained by the Indian Institute of Corporate Affairs.
Director Identification Number
To be obtained on appointmentNo DIN held today.
Independence
Meets s.149(6) criteriaNo pecuniary relationship with prospective companies, their promoters or group. Declaration to be given on appointment.
Current directorships
NoneFirst-time candidate, with capacity for up to three boards.

Education and credentials

  • B.Tech, Computer Science and Engineering2003
  • CISSPISC2
  • Registered in the IICA Independent Directors Databank
  • English, Hindi, Urdu, Telugu

05 Contact

For nomination committees, chairs and search firms

If your board is weighing technology or cyber experience for a vacancy or a committee, I would be glad to talk. I reply to every enquiry within two working days.

Email
office@farhanqureshi.in
Based in
Hyderabad, Telangana · available for board meetings across India
Replies within two working days

This is a sample site, so messages aren't sent. On your own site this reaches your inbox.