Cybersecurity Expertise for Leaders, Boards & Security Teams
Thirty years of experience in the CISO seat, the boardroom, and building cyber ventures. I work with organizations that need a trusted expert - not a vendor pitching a product.
Virtual CISO (vCISO)
Executive-level security leadership, without the full-time cost.
Many growing companies need a seasoned CISO - but can't justify a full-time C-suite hire. As your vCISO, I embed into your leadership team, own the security roadmap, manage vendors, and ensure you're audit-ready at all times.
Who this is for: CEOs and founders without a dedicated CISO
Learn more- Security strategy & roadmap development
- Board and executive reporting
- Vendor and tool selection
- Incident response planning
- Regulatory compliance readiness
- Security awareness programs
CISO Advisory
Strategic guidance for enterprise security leaders.
Enterprise CISOs face unique pressures - board expectations, regulatory complexity, and an evolving threat landscape. I serve as a trusted advisor to help you make better decisions faster, backed by real-world experience at the highest levels.
Who this is for: Enterprise CISOs seeking a strategic sparring partner
Learn more- Board-level security communication
- Security program maturity assessment
- Budget and resource optimization
- Regulatory navigation (GDPR, NIS2, ISO)
- M&A security due diligence
- Fractional advisory retainers
Compliance & Frameworks
Turn compliance into a competitive advantage.
Compliance is not just a checkbox - it's a signal to your customers and partners that you take security seriously. I guide organizations through the full certification lifecycle, from gap analysis to audit readiness.
Who this is for: Companies pursuing certifications or facing audits
Learn more- GDPR - Data protection and privacy programs
- ISO 27001 - ISMS design and certification
- NIST CSF - Framework implementation
- PCI-DSS - Cardholder data security
- SOC 2 - Trust services readiness
- Gap analysis and remediation roadmaps
Security Assessment & Pen Testing
Find your vulnerabilities before the attackers do.
A security assessment gives you an honest, outside-in view of your risk posture. I combine automated scanning with manual expert analysis to identify gaps that automated tools miss - and deliver a clear remediation plan.
Who this is for: Organizations wanting to understand their true risk exposure
- Network and infrastructure pen testing
- Web application security testing
- Cloud security posture review
- IoT and OT security assessment
- Social engineering and phishing simulation
- Executive risk summary reports
Security by Design
Build products with security and AI embedded from day one.
I help companies define, build, and maintain technology products - any type of product - with security and AI built into the foundation. From strategic scoping to long-term maintenance, my team owns the full lifecycle.
Who this is for: Any company that builds, buys, or operates technology products
Learn more- End-to-end product specification & architecture
- Security model designed before first line of code
- AI capabilities built in - not bolted on
- Custom alternatives to expensive SaaS products
- Automation of slow, manual business processes
- Ongoing development & maintenance by the same team
Explore My Perspective by Topic
Extended perspectives on the areas I work in most - how I see the problem, what organizations get wrong, and what actually works.
AI Security & Governance
Shadow AI, EU AI Act, and what CISOs must get right before AI becomes a liability.
AI Security Governance
EU AI Act compliance, AI system inventory, shadow AI detection, and board accountability frameworks.
Cyber Risk for Boards
What directors need to own - not just approve - as regulatory accountability grows.
Cybersecurity Advisory for Boards
Structured board advisory: NIS2 management accountability, SEC disclosure obligations, and the governance framework directors need to own - not just approve - cyber risk.
Virtual CISO (vCISO)
Executive security leadership on a fractional basis - roadmap, board reporting, compliance ownership, without the full-time hire.
CISO Advisory
Strategic guidance for security leaders - from someone who has been in the seat at one of the world's most targeted organizations.
CTEM & Exposure Management
Why point-in-time audits fail and what continuous exposure management actually looks like.
Compliance & Regulation
GDPR, ISO 27001, NIST, EU AI Act - turning compliance into strategic advantage.
Security by Design
Build products with security and AI embedded from day one - not added as an afterthought.
All Articles
Real-world cyber insights - no vendor fluff. Just experience-driven perspectives.
Two Companies, One Mission
Beyond advisory, I build - enterprise security services through Cybecs and next-gen CTEM through RedRok.
Cybecs
cybecs.com
Enterprise cybersecurity services - from managed security operations to tailored consulting engagements for demanding organizations.
RedRok
redrok.io
AI-powered Continuous Threat Exposure Management (CTEM) platform - giving security teams real-time visibility into their attack surface.
Not Sure Where to Start?
Book a free 30-minute risk review. We'll look at your current posture, identify the biggest gaps, and map out a practical next step - no commitment required.
Book Your Free Risk Review