Services

Cybersecurity Advisory & vCISO

Ongoing and once-off cybersecurity services.

Where to start

Most organisations don't call me because they've had a breach. They call because something isn't adding up — the reporting says one thing and the room knows another, or security has become a bottleneck nobody wants to own. Find the line below that sounds most like you.

Where are you stuck?

Not sure which line you're on? That's a normal place to start — the first conversation is usually about working out which problem you actually have.

Services

Virtual CISO (vCISO)

Ongoing fractional security leadership, scaled to what you need: functional oversight — a second set of experienced eyes across strategy, risk and reporting; function leadership — running the security function outright while you grow or recruit; or staff coaching — developing the people you already have so they can do the job themselves.

Board and executive reporting, and risk oversight, come with all three.

Cybersecurity Risk & Maturity Assessment

An honest, evidence-based assessment of where you actually stand — covering reputational risk, compliance risk, and the impact security risk is having on your delivery and your strategy.

It can be scoped the way that's useful to you: to a customer, a system, a data set or a cohort, or run against a framework of your choice (ISO 27001, NIST CSF, Essential Eight, CPS 234). The assessment deliberately covers visibility and capability as well as controls — what you can't currently see, and what you couldn't act on even if you could.

Cybersecurity Incident Response Games

Setting up incident response, or practising it. Game-based exercises that put your real decision-makers inside a realistic incident and make them make the calls, followed by a walkthrough of what the decisions revealed.

Run with the right stakeholders in the room, this is also the fastest way to find out what your risk tolerance genuinely is, rather than what your policy says it is.

Cybersecurity Threat Model Workshops

Game-based threat modelling that gets engineering and security teams solving the same problem together. Engineers walk through their architecture, the room roleplays threat actors, and the group leaves with prioritised risks and actual decisions — not a report that sits unread.

Based on the open-source workshop I developed and have been running for years.

Board & Executive Risk Communication

Translating cyber risk into terms your board and executive team can actually use to make decisions — board papers, briefings, and metrics that tell the truth. Particularly useful for borderline risks, where what you need is genuine alignment on whether to accept or act, not a number everyone quietly disagrees with.

Security Roadmap & Strategy Development

Turning an assessment into a sequenced, fundable plan: what to do, in what order, with which people and what money — and what you're deliberately choosing not to do yet, stated out loud so nobody is surprised later.

Cybersecurity Organisational Design

Designing the security function itself — governance design, skills assessment, and operating model design. Structure, decision rights and ways of working, so the function can carry what you're asking of it. More on the organisational design and risk culture page.

Third-Party & M&A Security Due Diligence

Vendor risk reviews, and security due diligence for acquisitions — on either side of the table.

This goes beyond a questionnaire. A questionnaire tells you what a third party says about itself; the assessment covers the visibility risks you're taking on — what you will and won't be able to see once you depend on them.

Interim Security Leadership

Covering a security or technology leadership gap during a search, restructure, or transition.

This list is a starting point rather than a fixed menu — every engagement starts with a conversation about what you actually need.

Get in touch