← Work

Advisory

Cybersecurity guidance for leaders who need a straight answer.

Most boards do not need another dashboard. They need someone who can say what the risk actually is, what the controls actually do, and what happens if nothing changes.

Security decisions get made at the governance level by people who are accountable for the outcome but rarely have the technical background to interrogate what they are being told. That gap is where bad spending happens: money goes to whatever was presented most confidently rather than to what reduces the most risk.

My job in an advisory seat is to close that gap. That means translating technical risk into operational and financial consequence, giving leadership an independent read on the work already underway, and being direct when a proposed control does not do what it is claimed to do.

I have worked across corporations, government agencies, and non-profits, and in roles from hands-on engineering through to leadership. That range matters here: it is the difference between describing a risk and knowing what it takes to fix it.

What an engagement looks like

Bring me into the conversation early.

Advisory work is most useful before a decision is made, not after an incident forces one.

Schedule a call