Advisory
Cybersecurity guidance for leaders who need a straight answer.
Most boards do not need another dashboard. They need someone who can say what the risk actually is, what the controls actually do, and what happens if nothing changes.
Security decisions get made at the governance level by people who are accountable for the outcome but rarely have the technical background to interrogate what they are being told. That gap is where bad spending happens: money goes to whatever was presented most confidently rather than to what reduces the most risk.
My job in an advisory seat is to close that gap. That means translating technical risk into operational and financial consequence, giving leadership an independent read on the work already underway, and being direct when a proposed control does not do what it is claimed to do.
I have worked across corporations, government agencies, and non-profits, and in roles from hands-on engineering through to leadership. That range matters here: it is the difference between describing a risk and knowing what it takes to fix it.
What an engagement looks like
Advisory board seat
Ongoing security input at the governance level: reviewing policy, testing assumptions, and asking the questions the room is not asking.
Executive briefings
A clear read on where the organization actually stands: what the current controls cover, what they do not, and what that means in business terms.
Risk and compliance guidance
Working through the mandates that apply to you, and separating what genuinely reduces risk from what only satisfies an auditor.
Program review
An honest assessment of a security program: maturity, gaps, and a prioritized order of work that fits the budget you actually have.
Bring me into the conversation early.
Advisory work is most useful before a decision is made, not after an incident forces one.