Independent advice for boards, executives and general counsel

I tell you what your security risk actually is.

Most security reporting is written for engineers and handed to directors. I write the other way round: the conclusion first, in plain language, with the evidence behind it for anyone who wants to check.

What I do

Where I help

Strategic security planning

I work out where the risk actually sits against what the business is trying to do, and what to fix in what order.

  • Risk assessment and management
  • Security roadmap development
  • Policy development and review

Compliance and governance

I tell you plainly what your obligations require and where you do not currently meet them. I run internal audits myself. For an external audit I prepare you for it or sit alongside it, and if you do not have an auditor I will introduce one I trust — including, where it fits, InfoSec Collective, which I co-founded and have an interest in.

  • Regulatory compliance, including the Privacy Act and GDPR
  • Privacy impact assessment
  • Internal audit
  • External audit preparation and support
  • Security governance frameworks

Incident response

I help you build a plan you have actually tested, and afterwards I tell you what the evidence can and cannot show.

  • Incident response planning and testing
  • Post-incident analysis

Artificial intelligence

I check whether the technical controls around an AI system are real, and whether it is being built and used responsibly.

  • Technical controls for AI systems
  • Responsible development and use

Third-party and acquisition risk

I tell you what you are taking on when someone else’s security becomes your problem — whether you are depending on it or buying it.

  • Vendor and partner risk assessment
  • Security due diligence for mergers and acquisitions
Deliverables

How the work arrives

A report

Findings, the evidence behind them, and what I would fix first. The same structure whether it is an advisory assessment, an internal audit, a post-incident review, a privacy impact assessment or due diligence on an acquisition.

A board paper

One page of conclusion, four pages of substance. Written for the pack, not for the presentation.

Something you keep and use

A policy set, a governance framework, a security roadmap or an incident response plan. Written to be operated by your people after I have gone, not to sit in a drawer until the next audit.

Time in the room

A briefing to the risk or audit committee, a tested incident exercise, or sitting alongside your external audit. Questions answered as they come, no deck, and a short paper afterwards.
Approach

Restraint is the point

Security vendors sell with padlocks, glowing threat maps and manufactured urgency. I present findings in black and white because the substance carries itself. If a finding needs decoration to persuade you, I have not written it well enough.