I offer a range of services — on a project, fractional, subscription, or on-demand basis. Read more below.
Organizations often engage me in one or more of the following situations:
Many organizations are already doing all sorts of things around security, but lack a program that hangs together logically. That makes it hard to substantiate choices, steer on risk, and demonstrably meet the requirements of clients, regulators, and laws and regulations.
I help bring structure to this and turn it into one coherent whole. Among other things, I support with:
Even with good measures and tooling, a lot falls apart if it is unclear who is responsible for what and how things are steered. Governance is about ownership, decisions, and accountability.
I help make that clear and workable, fitting how your organization is already set up. In doing so, I look at, among other things:
In practice, many misunderstandings arise from different definitions and expectations. An important part of my work is creating clarity about concepts and frameworks, so that everyone works from the same starting point.
Security measures and tooling often grow organically: something is added, something is removed, projects make their own choices. Without a clear architecture, you quickly end up with a collection of disconnected solutions. I help bring structure to this and ensure that new choices are directly in line with the bigger picture.
In concrete terms, this means, for example:
I do not implement products myself, but work closely with engineers and architects. This way, we ensure that designs are both secure and practically feasible.
Not every issue calls for a large program. Sometimes there is one concrete theme you want to think through carefully and then steer on closely. In those situations, I often work in short cycles and in a focused way.
Examples of these kinds of issues are:
I then help with:
The ultimate First Principle in Cybersecurity: "The probability of a materialised cyber attack within a finite amount of time."— Rick Howard
Not every organization requires — or has the budget for — a full-time CISO or security architect. At the same time, there is a need for someone who provides direction, assists in making decisions, ensures coherence is maintained, and/or serves as a point of contact for management and IT. For this, I offer several subscription and flexible options.
In a fractional role, I am part of your organization for an agreed portion of the time, without a full position having to be created.
Think of:
This way, you bring the experience of a senior security professional in-house, on a scale that fits your organization.
Not every issue is a project. Sometimes what is mainly needed is someone to think along:
This can be on the basis of a punch card or a simple subscription, depending on the need.
Do you recognize one or more of the situations above, but are not sure where to start? Please feel free to contact us. In a brief conversation, we will map out together: