Steve Rumbold

Steve Rumbold

Managing Director

Steve Rumbold is a Managing Director in the Enterprise Security Risk Management practice, based in London. Steve leverages over 25 years of expertise in security risk management, governance and assurance, with experience spanning both the UK and global markets.

Before joining Kroll, Steve served as Head of Cyber Risk at National Grid, where he led global cyber security risk management for critical infrastructure in the UK and U.S. He managed cyber risk services for Operational Technology and IT across UK electricity and gas networks, U.S. power generation and renewables, ensuring regulatory compliance and maintaining risk within acceptable levels. Before that, Steve worked across physical and cyber security for EDF Energy. He established an independent security assurance function for the £24 billion Hinkley Point C project and provided expert security advice for other nuclear projects, leveraging standards like IEC62443 and ISO27001.

Steve has also advised on UK Government policy for civil nuclear security, contributing to the first Civil Nuclear Cyber Security Strategy. He created an integrated security framework for new nuclear builds in the UK, approved by the UK civil nuclear regulator.

Before his energy sector roles, Steve was Head of Risk Management at National Car Parks, overseeing financial risk, compliance and security assurance. He is also a former British army officer with global operational experience, including roles with the French Foreign Legion and the Afghan Ministry of Interior and served as Information Security Lead for a sensitive MOD directorate.

Steve holds several prestigious certifications and has also completed various government-run security courses at the Centre for the Protection of National Infrastructure (now the National Protective Security Authority, NPSA) and the UK’s Defence Academy.

Steve holds a M.Sc. (Dist.) in international security and global governance from the University of London and a M.A. (Hons.) in modern languages from the University of St Andrews. He is also a Global Industrial Cyber Security Professional (GICSP), a Certified Information Systems Security Professional (CISSP), a Certified Information Security Manager (CISM), ISO 27001 Lead Auditor and holds a Project Management Qualification (PMQ) from the Association of Project Management.



Enterprise Security Risk Management

Kroll’s Enterprise Security Risk Management practice provides expert guidance and advisory services to our global clientele as they navigate the most challenging and emerging security and threat-related issues.

Security and Risk Management Consulting

Kroll’s team excels at proactive security consulting and expert advisory solutions, aligning our comprehensive offerings with your enterprise’s risk appetite. We offer personnel, expertise, advisory and bandwidth when our clients are challenged in ways that stress their comfort or internal capabilities.