Dr. Priya Sharma
ISO 27001 Lead Auditor

16 years in governance, risk, and compliance. Has guided organizations through complex regulatory requirements and established security frameworks aligned with ISO 27001, GDPR, and NIS2.
Dr. Priya Sharma is GICCT’s Lead Instructor for Governance, Risk, and Compliance, bringing deep expertise in information-security management and data protection law. She advises organisations across Greece and the wider European Union on building defensible compliance programmes, and she brings that current, real-world practice directly into the classroom.
Background and career
Dr. Sharma built her career at the meeting point of security, management, and law, recognising early that technical controls alone cannot make an organisation secure or compliant. She developed expertise in the frameworks and regulations that govern how organisations must protect information, and in the practical work of implementing them — the gap analyses, risk assessments, and management systems that turn principles into practice.
She has guided numerous organisations from an initial state of disorganised, ad-hoc security through to successful certification, and she serves as an external Data Protection Officer for clients in regulated sectors. This ongoing practice keeps her teaching grounded in the realities organisations actually face, rather than the idealised version found in textbooks. She understands compliance not as paperwork but as a practical system of controls that must genuinely function.
Areas of expertise
Dr. Sharma’s expertise covers ISO 27001 implementation, the GDPR and the Greek implementing legislation, and the emerging NIS2 framework that now reaches a broad range of organisations. She has particular depth in the role of the Data Protection Officer and in the practical work of translating regulatory requirements into the concrete policies, procedures, and controls an organisation can actually adopt.
She also understands the connections between these overlapping regimes — how an ISO 27001 management system supports GDPR compliance, how both relate to NIS2 obligations — and she helps students see compliance as a coherent whole rather than a collection of separate burdens. This integrated perspective is increasingly valuable as the regulatory landscape grows more complex.
Teaching philosophy
Dr. Sharma makes complex regulatory material concrete and actionable, working from real documentation, risk registers, and case studies rather than abstract theory. Her students leave able to lead an implementation, not merely describe one. She believes that practitioners who understand the intent behind a requirement can apply it intelligently, while those who merely follow a checklist will founder the moment reality departs from the template.
She is skilled at making a subject that many find dry genuinely engaging, connecting every requirement to the real risks it addresses and the real consequences of getting it wrong. Her goal is graduates who can walk into an organisation and meaningfully improve its compliance posture from day one.
A practitioner’s perspective
Because Dr. Sharma still advises organisations through real compliance challenges, her teaching reflects what actually happens when frameworks meet reality — the judgement calls, the resource constraints, and the organisational politics that textbooks omit. She shares this practical wisdom freely, giving students a realistic picture of what compliance work genuinely involves.
She watches the regulatory landscape closely, particularly the expanding reach of NIS2 and the growing personal accountability it places on organisational leadership. She helps students understand that compliance has become a board-level concern, and that professionals who can bridge the technical and regulatory worlds are increasingly sought after.
Her students value that she brings the perspective of someone who genuinely practises what she teaches, advising real organisations through real compliance challenges even as she educates the next generation. That dual role keeps her teaching grounded, current, and unmistakably connected to the world her students are preparing to enter.
At GICCT
At the institute, Dr. Sharma leads the ISO 27001 Lead Implementer and GDPR & Data Protection programs. She is a strong advocate for the view that good governance is what makes security sustainable over time. For professionals looking to move into the management and compliance side of security — one of the field’s clearest routes to senior roles — her courses provide a rigorous and genuinely practical foundation.