Services

I offer a range of services — on a project, fractional, subscription, or on-demand basis. Read more below.

Good to know

When should you engage me?

Organizations often engage me in one or more of the following situations:

  • You want to establish or professionalize an information security program.
  • You need to demonstrably comply with laws and regulations or security standards and are looking for structure and a pragmatic approach.
  • You lack overview and cohesion: many measures and tools, but no cohesive security architecture.
  • You are facing significant design or product choices around new systems or solutions and wish to incorporate security properly from the start.
  • You want an experienced security partner without immediately setting up a full-time position.
  • You are looking for someone who can help organize security, and also engage technically with technicians at the table.
Roles

Services on a project basis

Many organizations are already doing all sorts of things around security, but lack a program that hangs together logically. That makes it hard to substantiate choices, steer on risk, and demonstrably meet the requirements of clients, regulators, and laws and regulations.

I help bring structure to this and turn it into one coherent whole. Among other things, I support with:

  • formulating frameworks, policy, and principles that fit your organization;
    • shaping a solid program
  • sharpening roles, responsibilities, and reporting lines;
    • so it is clear who does what
  • setting up consultation, decision-making, and follow-up around security.
    • so it is not a paper tiger, but a working whole

Even with good measures and tooling, a lot falls apart if it is unclear who is responsible for what and how things are steered. Governance is about ownership, decisions, and accountability.

I help make that clear and workable, fitting how your organization is already set up. In doing so, I look at, among other things:

  • the roles and responsibilities of CISO, IT, risk, business, suppliers, and internal audit;
  • the consultation structure and decision-making: who joins where, with what mandate;
  • reporting and accountability: which information is on the table at which level, and in what form;
  • the alignment with existing IT, risk, and compliance governance.

In practice, many misunderstandings arise from different definitions and expectations. An important part of my work is creating clarity about concepts and frameworks, so that everyone works from the same starting point.

Security measures and tooling often grow organically: something is added, something is removed, projects make their own choices. Without a clear architecture, you quickly end up with a collection of disconnected solutions. I help bring structure to this and ensure that new choices are directly in line with the bigger picture.

In concrete terms, this means, for example:

  • translating goals, risks, and policy into security architecture principles that give direction to choices;
  • creating an overview of measures and tooling: what do we do where, what is missing, what is duplicated;
  • drafting or reviewing functional designs (FD) and high level designs (HLD) from a security perspective;
  • assessing decision documents and product selections: does this solution fit the architecture, the available resources, and the future vision.

I do not implement products myself, but work closely with engineers and architects. This way, we ensure that designs are both secure and practically feasible.

Not every issue calls for a large program. Sometimes there is one concrete theme you want to think through carefully and then steer on closely. In those situations, I often work in short cycles and in a focused way.

Examples of these kinds of issues are:

  • a new platform or application that needs to be set up securely and manageably;
  • a business process that needs to be set up securely, auditably, and demonstrably compliant;
  • an existing environment that needs to be critically reviewed: what still works, what no longer does;
  • the wish to move the organizational culture more towards a Zero Trust mindset, without being unnecessarily rigorous.

I then help with:

  • analyzing and structuring the issue;
  • working out a pragmatic proposal or design;
  • if desired, guiding the implementation, together with your own teams and suppliers.
The ultimate First Principle in Cybersecurity: "The probability of a materialised cyber attack within a finite amount of time."
— Rick Howard
Roles

Subscription & Flexible Role

Not every organization requires — or has the budget for — a full-time CISO or security architect. At the same time, there is a need for someone who provides direction, assists in making decisions, ensures coherence is maintained, and/or serves as a point of contact for management and IT. For this, I offer several subscription and flexible options.

In a fractional role, I am part of your organization for an agreed portion of the time, without a full position having to be created.

Think of:

  • a fixed day per week, a few days per month, or deployment in blocks around important initiatives;
  • safeguarding coherence in the InfoSec program and the architecture;
  • acting as the point of contact for management, IT, and suppliers, and where necessary towards auditors or regulators.

This way, you bring the experience of a senior security professional in-house, on a scale that fits your organization.

Not every issue is a project. Sometimes what is mainly needed is someone to think along:

  • Sparring about choices, risks, and solution directions.
  • A second opinion on plans, proposals, or quotes.
  • Joining a number of important meetings or decision moments.

This can be on the basis of a punch card or a simple subscription, depending on the need.

What now?

Do you recognize one or more of the situations above, but are not sure where to start? Please feel free to contact us. In a brief conversation, we will map out together:

  • where you currently stand;
  • what the main pain points or risks are;
  • and which form of collaboration best suits you (project, flexible role, or a subscription).
Get in touch