What Does a Programme Coordinator Do in a Cyber Security Transformation? banner image
Blog

What Does a Programme Coordinator Do in a Cyber Security Transformation?

By Holly Hacon 9 October 2026 3 min read
When people picture a cyber security transformation, they often picture the visible work: the policies, the platforms and the dashboards. My role supports that, helping keep multiple workstreams pointing in the same direction under a single programme. It has given me a practical view of how this work actually gets done at Bridewell, and I think it is worth sharing.

Thirteen Workstreams, One Programme 

The shape of the programme tells the story without needing to name the organisation. Multiple workstreams are running at once, including data loss prevention, incident response, identity, supply chain, asset management and secure device management. Each has its own lead, timeline and budget. Each also shares risks, dependencies and deadlines with the others, so the value comes from managing the connections between them, not just the individual workstreams. 

My job is to help make sure none of that falls through the gaps: weekly delivery meetings, risk and issue tracking, milestone reporting, action follow-ups and governance packs. On paper, some of that can look like coordination. In practice, it is the difference between a programme that can clearly evidence what it has delivered and one that relies on people remembering what happened. 

A normal Tuesday can involve following up overdue actions before the delivery meeting, finding out that a workstream lead is waiting on evidence from another team, logging the dependency, and then spending the afternoon building the governance pack for Thursday. None of that is the headline. All of it is what makes the headline stand up. 

Evidence is Everything 

The part I am proudest of is how seriously we take evidence. Nothing is treated as complete just because someone says it is. Every deliverable has acceptance criteria agreed up front, an evidence pack behind it, an assurance check, and a named person who signs it off. It all lands in one register with dates, approvers and links. Following those sign-offs through is a large part of my week, and it is one of the most important parts of the role. 

That discipline pays off in one specific moment. When a sponsor, an auditor or a board asks what has been delivered for the investment, the answer is not a slide full of activity. It is a register they can open, trace to a named approver and map to a measurable control improvement. I have watched that conversation go well purely because the record already existed. 

What I've Learned About How Bridewell Works 

Three things have stood out to me since I joined, and none of them are purely technical: 

  • We embed rather than work alongside. From the outset, Bridewell’s approach was to operate within the client’s existing change and governance routes, rather than create a separate Bridewell tracker that sat outside them. That meant reporting through the client’s own processes, using the routes already in place, and helping strengthen delivery from within rather than managing it from the side. 
  • We build things to be handed back. Every runbook, ownership matrix and training session I help chase down is written so someone on the client side can pick it up after we leave. Designing yourself out of the day-to-day running is a strange thing to aim for, but it is the whole point. 
  • We use what is already there. Before anyone recommends new tooling, we look at whether the client's existing capability can do the job. If it cannot, the decision needs to be clear and evidenced. I have sat in meetings where a more attractive option lost out to something the client already owned and had not fully switched on. 

Why I'd Recommend This Path to Anyone Starting Out 

Coordinating a programme like this has taught me more about cyber delivery in months than any course could have done on its own. You see how the technical, commercial and human sides pull against each other: a control that is simple to configure but hard to get anyone to own, or a deadline that is fixed by regulation but still has to work for delivery teams. You learn that governance is not red tape. It is what makes ambitious work defensible when someone eventually asks. And you get to watch an organisation move from fragmented, manual controls to something measurable and board-ready. 

If you are a project professional wondering whether cyber is for you, the honest answer is that it is not always glamorous. You will spend more time chasing evidence than you will in a war room. But that discipline is the reason the outcomes hold up, and you will know exactly which parts of it you helped hold together. If you are starting out and are interested in this work, please reach out to Bridewell’s talent team. 

Bridewell delivers cyber security consulting, managed detection and response, and data privacy services to critical national infrastructure and organisations that require the highest standards of cyber security. 
Holly H

Holly Hacon

Project & Programme Management Consultant