C|RAGE Scheme Committee

Allan Cafournet

Allan Cafournet

Allan Cafournet is an Information Systems Security Consultant and Trainer specializing in regulatory compliance, operational resilience, and enterprise risk management. With over seven years of experience in cybersecurity, Allan has led critical projects in ISO 27001, NIS2, DORA, cloud security, incident and crisis management, business continuity (ISO 22301), disaster recovery, and AI governance (ISO 42001).
He has successfully supported organizations in highly regulated industries, including finance, SaaS, and critical infrastructure, ensuring compliance with international standards while strengthening overall security and resilience. His dual expertise in governance and technical domains enables him to bridge strategy with practical implementation.
As the founder of ACQRIT SECURE IT, a Qualiopi-certified training organization, Allan provides accredited training and consulting services worldwide. He is deeply committed to empowering professionals through education on cybersecurity, risk, and resilience frameworks, while also contributing to social inclusion initiatives through accessible training programs.
Driven by a holistic and ethical approach, Allan integrates governance, compliance, and innovation to build trust and enable sustainable digital transformation. His appointment to the EC-Council’s Certified Responsible AI Governance & Ethics Professional (RAGE) Scheme Committee reflects his dedication to shaping responsible AI practices aligned with global standards.

Ashish Chandra

Ashish Chandra

Ashish Chandra is a seasoned cybersecurity and data privacy strategist with over two decades of cross-industry impact spanning BFSI, NBFC, Insurance, eCommerce, Healthcare, and Manufacturing. He specializes in designing and operationalizing enterprise-wide frameworks for Governance, Risk, and Compliance (GRC), integrating global standards such as AIMS, NIST, ISO 27001, GDPR, RBI, and India’s DPDP into actionable policy architectures.
Ashish has led multi-regional cybersecurity programs across the US, EU, and APAC, embedding behavior-driven security practices and multilingual awareness campaigns. His strategic initiatives include deploying cloud security maturity models, conducting 3rd party risk assessments, and aligning data governance with privacy-by-design principles. He has conducted privacy readiness assessments, DPIAs, and vendor contract reviews to ensure robust data protection across digital ecosystems.
A champion of educational outreach, Ashish has built LMS platforms, gamified training modules, and compliance dashboards to drive engagement and measurable improvement. His mentorship spans students, professionals, and public communities, fostering digital resilience and ethical awareness.
With certifications including CCISO, CISSP, CISM, CISA, CRISC, CDPSE, Lead Auditor – ISO 27001, ISO 20000, ISO 13485 and Lead Implementer – ISO 42001 credentials, Ashish combines technical depth with strategic foresight. His leadership style emphasizes collaboration, structured decision-making, and cross-functional alignment—making him a trusted advisor in transforming cybersecurity culture and scaling privacy innovation.
Ashish continues to pioneer modular, AI-integrated solutions that bridge regulatory rigor with operational agility, empowering organizations to thrive in an era of evolving digital risk.

Claudio De Rossi

Claudio De Rossi

Claudio De Rossi is recognized as an innovative leader in organizational resilience, with a strong focus on cybersecurity, data protection, and governance, including AI oversight. As a senior security executive, he is responsible for defining and implementing enterprise-wide security strategies, ensuring alignment with evolving regulatory frameworks such as NIS2. He has a proven track record in developing integrated security governance models and in designing comprehensive structures that combine strategic governance with advanced security operations. His extensive leadership experience covers complex areas such as cyber risk management, data governance, and implementation of innovative solutions to enhance corporate resilience and protection.
His strategic approach is founded on a remarkably diverse academic trajectory. His studies span Management and E-governance alongside deep dives into human behavior and company’s strategic risks. This includes degrees in Work and Organizational Psychology, specialized training in Cyberpsychology, and advanced studies in Cyber Criminology and the Geopolitics of Security.
He holds highly respected cybersecurity certifications such as C|CISO, Certified Ethical Hacker Master (CEH), Casp+/SecurityX, Pentest+, Cysa+. Furthermore, he holds strong governance expertise, underpinned by Project Management certifications (e.g., PRINCE2, Project+) and as a qualified Lead Auditor for ISO 9001, ISO 27001, and ISO 22301 standards. He is also an active advocate for community engagement and digital literacy: he actively contributes to the cybersecurity community as a cyber career mentor and Item Writer for EC-Council certification exams. In addition, he is a founding member of FInD (Ferrara Innovation and Digital), an association dedicated to promoting and disseminating digital culture.

Emem Umoh

Emem Umoh, MSc, CISSP, CDPSE, CCISO, CSA CP, DPC CDPS

Chief Information Security Officer (CISO) & Data Protection Supervisor (DPS), Zenith Bank (Ghana) Ltd

Emem Umoh is a distinguished Information Security and Privacy Professional with over two decades of experience spanning banking, technology, and governance. He currently serves as the Chief Information Security Officer and Data Protection Supervisor at Zenith Bank (Ghana) Limited, where he leads the Bank’s cybersecurity, privacy, and governance programs, aligning them with global standards and regulatory frameworks.
His expertise covers ISO/IEC 27001, 27701, and 42001, PCI DSS, SWIFT CSCF, and NIST frameworks, as well as Ghana’s Cybersecurity Act (Act 1038) and Data Protection Act (Act 843). Under his leadership, Zenith Bank has achieved multiple certifications and strengthened its cyber resilience through initiatives such as the establishment of a Security Operations Centre (SOC) and implementation of an Information Security Management System (ISMS).
Beyond the Bank, Emem is Head of the Security Group of the Institute of ICT Professionals Ghana (IIPGH) and Vice President of the group of CIOs and CISOs of Banks in Ghana, promoting cybersecurity awareness, capacity building, and regulatory compliance across the sector.
He is a PECB Certified Trainer, Implementer, Auditor, and Professional, an MSECB Management Systems Interim Auditor, and a recipient of multiple international recognitions, including the Global CISO 100 Award and the World CIO 200 Legend Award.

Ibrahim Siyaz

Ibrahim Siyaz

Ibrahim Siyaz is an experienced cybersecurity, data privacy, and risk management professional with over a decade of leadership in the financial services sector. He currently serves as the IT Security Manager at the Bank of Maldives, where he oversees information security governance, risk, and compliance programs in alignment with PCI-DSS v4.0.1, ISO/IEC 27001, and regulatory standards set by the Maldives Monetary Authority.
His expertise spans information security governance, data privacy, AI risk management, penetration testing, and incident response. Siyaz has been instrumental in strengthening the Bank’s security posture through the implementation of enterprise-wide security controls, data protection measures, and continuous compliance frameworks across critical systems and applications.
In addition to his professional responsibilities, he contributes to academia as a lecturer at Cyryx College, where he teaches postgraduate courses in Cybersecurity, Digital Forensics, and Ethical Hacking, fostering the next generation of cybersecurity professionals in the Maldives.
Siyaz holds globally recognized certifications, including CISM, CRISC, CISA, CGEIT, and CCISO, reflecting his commitment to advancing organizational resilience, governance, and ethical technology practices. His professional interests include AI governance, data privacy, model risk management, and responsible technology adoption within regulated industries.
As a member of EC-Council’s Certified Responsible AI Governance & Ethics Professional (RAGE) Scheme Committee, Siyaz contributes his expertise to promote responsible innovation, transparency, and accountability in the governance of emerging AI technologies.

Roger-Millar

Roger Millar

With over two decades of experience in information technology and cybersecurity leadership, Roger is a trusted advisor and executive, guiding organisations across Australia and internationally through complex technology transformations.
His leadership tenure spans industry sectors including employment services, hospitality, travel and tourism, health, education, and large-scale infrastructure. His pragmatic approach blends technical expertise with a business-minded focus on risk management, compliance, and value creation.
A certified CISO, he is committed to ongoing professional development and thought leadership. An advocate for globally recognised cybersecurity standards, he leverages his extensive experience to assist organisations in navigating evolving regulatory landscapes and emerging threat environments.
He is passionate about mentoring future cyber leaders and is a member of the EC-Council Cybersecurity Career Mentor programme.

Juan Camilo Botonero Rodriguez

Juan Camilo Botonero Rodriguez

Trilingual Systems and Telecommunications Engineer, with extensive experience in designing and implementing comprehensive cybersecurity strategies. My career includes notable roles such as Lecturer, Cybersecurity Specialist, Academic Director, Information Security Officer, Security Consultant, University Professor, IT Manager, and IT Coordinator in various companies. I have led key projects to protect systems and data against cyber threats. I stand out for my ability to coordinate incident response teams (CSIRT) and establish alliances with the industry to drive security innovation. Additionally, I hold internationally recognized certifications such as – C|CISO, CEH, CISA, CISM, CompTIA Security+, ECIH, ISO 27001, ISO 27032, AND SC-900 MICROSOFT, which support my in-depth knowledge and skills in this ever-evolving field.

Tunde Dada

Tunde Dada

Tunde Dada is the Executive Group CIO at inq.Digital Corp. responsible for all IT/OT implementations across the group. He is an astute and visionary technology executive and also a thought leader in the Information Technology and Security space globally. He has extensive industry experience in deploying IT and OT systems across various countries in Africa. He is a member of the British Continuity Institute, the Information Systems and Security Association, the AI Association and others across the world. Tunde is a certified CCISO and ITBMC who has about 26 years of information technology experience out of which over 20 years has been used focusing on Cybersecurity and risk management. He is currently the Chairperson, British Continuity Institute West Africa Chapter and the Agora Nexus CyberSecurity Initiative. Tunde Dada is a board member of various industry executive board including Agora Nexus and CyberEdboard. As a Cybersecurity visionary he is a recognized CISO / VCISO that offers Cybersecurity services across Africa and beyond and is passionate about AI and next generation technology use in Cybersecurity. He is a thought leader in Information Security and a contributor to the Cybersecurity body of knowledge.

The specific duties and responsibilities of the SC members include:

  • Approve key policies governing the operation of EC-Council Certification Division.
  • Assuring consistency of decision making as well as the criteria used therein.
  • Serve on appeals and complaints task groups as appointed by the SC Chair.
  • Promote and provide guidance to promote EC-Council certifications.
  • Provide guidance regarding international initiatives supporting EC-Council certifications.
  • Provide guidance to support educational initiatives related to EC-Council certifications.
  • Determine areas of research required to improve EC-Council certifications.
  • Serve on task forces / subcommittees as appointed by the SC Chair.

Note: Next SC scheduled meeting: December 2025.

Disclaimer: None of the EC-Council | Scheme Committee members are part of the management team of the International Council of E-Commerce Consultants (EC-Council) and as such, they should not be construed to be part of the Board of Directors of EC-Council.