I tell you what your security risk actually is.
Most security reporting is written for engineers and handed to directors. I write the other way round: the conclusion first, in plain language, with the evidence behind it for anyone who wants to check.
Where I help
Strategic security planning
I work out where the risk actually sits against what the business is trying to do, and what to fix in what order.
- Risk assessment and management
- Security roadmap development
- Policy development and review
Compliance and governance
I tell you plainly what your obligations require and where you do not currently meet them. I run internal audits myself. For an external audit I prepare you for it or sit alongside it, and if you do not have an auditor I will introduce one I trust — including, where it fits, InfoSec Collective, which I co-founded and have an interest in.
- Regulatory compliance, including the Privacy Act and GDPR
- Privacy impact assessment
- Internal audit
- External audit preparation and support
- Security governance frameworks
Incident response
I help you build a plan you have actually tested, and afterwards I tell you what the evidence can and cannot show.
- Incident response planning and testing
- Post-incident analysis
Artificial intelligence
I check whether the technical controls around an AI system are real, and whether it is being built and used responsibly.
- Technical controls for AI systems
- Responsible development and use
Third-party and acquisition risk
I tell you what you are taking on when someone else’s security becomes your problem — whether you are depending on it or buying it.
- Vendor and partner risk assessment
- Security due diligence for mergers and acquisitions
How the work arrives
A report
A board paper
Something you keep and use
Time in the room
Restraint is the point
Security vendors sell with padlocks, glowing threat maps and manufactured urgency. I present findings in black and white because the substance carries itself. If a finding needs decoration to persuade you, I have not written it well enough.