Interim Data Protection Officer
Practical DPO work — DPIAs, LIAs, ROPAs, breach response, vendor schedules, training. Not slide decks.
whitby north yorkshire
It started on a machine like this one. His father’s PET — dual disk drive and a printer — at a time when school meant a room full of BBC Micros. By five he was repairing one for a retired teacher.
Forty years on, the work is the same shape at a different scale: the cryptographic standards protecting sixty million NHS patient records, co-authored; the key architecture behind eight million contactless journeys a day on Transport for London; and still the bench work — fixes landed in OpenBSD, two CVEs credited by Apple in 2026. Standards authors don’t usually still find kernel bugs.
He works in writing, at his own pace, from the town at the bottom of the page.
whitby north yorkshire
The lit windows are the point. Cryptographic systems and smart cards — the NHS national cryptographic standards, co-authored; the key architecture behind TfL contactless. Data protection — DPIAs, LIAs, ROPAs and breach response across clinical trials, retail and law firms. Vulnerability research — macOS, Darwin/XNU and OpenBSD, with fixes credited upstream in OpenBSD −current and three Apple disclosures published in 2026. Also penetration testing and incident response, network and protocol engineering, application security, and compiler and JIT analysis. Forty years of it. Commissioned work runs through TriageForge; the record is here.
Whitby, after dark — AI-rendered to a written brief, and labelled as such.
1986 – 2026
Started on a Commodore PET at five, for a retired teacher who wanted her machine back. Has since written cryptographic standards read by a national health service, designed the key management behind eight million daily journeys, and spent thirteen years’ worth of other people’s latent bugs finding them before somebody worse did. Neurodivergent, plain-spoken about it, and — for the last stretch — working in writing, at his own pace.
Delivered for NHSTransport for LondonPwCDeloitteLondon Stock ExchangeHarrodsBootsSony PlayStationOraclePAREXELHome Office · DWP · DfT
2000 – 2023
Practical DPO work — DPIAs, LIAs, ROPAs, breach response, vendor schedules, training. Not slide decks.
GDPR implementation, security architecture, penetration testing and incident response across financial services, retail and critical national infrastructure.
Designed the cryptographic key-management architecture for London’s contactless payment network — ISO 27001 and PCI DSS compliant, 22,000 readers, 8 million transactions a day.
Co-authored the cryptographic security standards for the NHS national programme: smart-card infrastructure, key-derivation protocols, 60 million patient records.
Designed the online infrastructure for the PlayStation 2 UK launch. The technology was sound.
The thing IBM was putting on the wanted list in 1999.
independent 2026
Two guest→host memory-safety defects in libslirp, the user-mode network stack behind QEMU’s default VM networking. An NC-SI OEM handler reads up to four bytes past the supplied packet and reflects them into the guest’s reply — information disclosure, CWE-125, rated Moderate by Red Hat at CVSS 3.1 4.3. The DHCPv6 and TFTP response builders overflow the reply buffer where if_mtu is configured small — memory corruption, CWE-787, rated Important at CVSS 3.1 7.4.
Found by source audit and confirmed with minimised reproducers under a guard-page allocator. Patches written here and applied upstream by the maintainer; fixed in libslirp 4.9.5. Coordinated through Red Hat Product Security, which records: “Red Hat would like to thank Stuart Thomas for reporting this issue.” Credited, not a paid bounty.
A kernel NFS-server denial of service and an SMB resource-exhaustion flaw, both fixed across macOS Golden Gate 27, Tahoe 26.7 and Sequoia 15.8. A third report is acknowledged under Terminal in the iOS 27 and macOS Golden Gate 27 advisories.
Thirteen years latent. A single crafted request made proxy and backend disagree on the message boundary. Found by a source-review pass against the RFC 9112 framing rules; fixed in −current.
PING-01 (out-of-bounds write in /sbin/ping), SMB-01A (smbd copy-chunk DoS) and MAILDROP-01 (unsigned parameters on icloud.com) — each with vendor references and status notes. Apple fixed the first two on 14 September 2026; MAILDROP-01 remains under review.
A six-phase methodology from 35 years of structured practice — scope, recon, research tracks, red-team, submission, archive. Eleven chapters.
A four-class taxonomy of how AI-assisted disclosures go wrong, a pre-send filter that catches the mechanical two, and two real withdrawals from the author’s own OpenBSD work.
pro bono no fee
An NFC tag in every genuine piece carries an unforgeable AES-128 signature. Tap with any phone — no app required.
authenticwhitbyjet.co.ukA plain-English guide for fishing operators, quayside businesses and maritime families: GPS spoofing, onboard networks, invoice fraud, insurance gaps.
Read the guideCommunity groups, charities and small research teams with a genuine data-protection question. A record of what I know, not a services page.
What I can help with
whitby 1911
Robert Dixon, four-times great-grandfather, worked Whitby jet in the heart of the trade. Standing on the same streets, using cryptography to protect what he helped create felt inevitable.
scarborough c.1940
Bill Steele, grandfather, Marconi-trained radio officer on wartime convoys, then a Cold War listening post at Scarborough, copying Russian Navy Morse. The thread between his radio set and AES-128 is there.To whoever is reading
Being honest upfront saves everyone time. I’m neurodivergent — ADHD, autism, RSD. Over 35 years I’ve had more than 75 jobs. I do my best work on things that genuinely interest me, on my own terms, at my own pace.
This site is a record, not a shop window. It is what I’ve done, what I know, and what interests me. Commissioned data-protection and security work runs through TriageForge. I also share knowledge pro bono when health and energy allow, for community, charity or research purposes.
Written communication only. No phone calls, no video meetings, no real-time chat. Async, at my pace. I may not respond quickly. I may not respond at all. That isn’t rudeness — it’s capacity.
Stuart ThomasWhitby, September 2026
checked against every job
held not claimed
CIPP/ECertified GDPR PractitionerCiSMP · DistinctionGIAC GSECISO 27001 · implementation
Not a Lead Auditor, and I don’t claim to be: ISO 27001 experience is implementation, pre-audit preparation and post-certification management — not leading audits.
Correspondence
Based in Whitby. Genuine pro bono questions from community, charity, research or family contexts are welcome here. For commissioned data-protection or security work, write to TriageForge. If it is urgent, or needs legal advice, I’m not the right person.