Services

Cybersecurity to understand risk and move forward with judgement.

Strategy, technical capability and training, so an organisation knows where it stands, what to deal with first and how to keep moving.

Starting point

The first job is working out what's actually needed

A company that has just received its first security questionnaire from a client is not in the same place as one with a management system certified three years ago and an appetite for getting more out of the licences it already pays for. The first needs order. The second needs depth.

Rolling out controls is only one part. The hard bit is deciding which ones, in what order and on what criteria. That's where my work starts, and it's why it almost always starts with an assessment rather than a tool.

The three things I look at before proposing anything:

Context

What the organisation does, what it depends on to get through an ordinary Monday, and who demands what of it: clients, parent company, sector and applicable regulation.

Risk

What can go wrong, how likely it is and what it takes down with it. Risk sets the order of the list; the budget decides how far down it you get.

Maturity

Some capabilities only work if the ones before them are already standing. Skipping that order is the quickest way to spend a security budget badly.

01 Technical

Cybersecurity audit

See the service →

Know where you stand before deciding where to go.

An audit doesn't have to end in a certificate. Most of the time it serves something more immediate: putting in writing which controls exist, which ones actually work, which ones only exist as an intention, and what is missing —ordered by impact and by effort.

I work with the frameworks the sector already uses, and also with tailored reviews when none of them quite fits what the organisation needs to look at. The result turns into conclusions the board can use and concrete actions IT can prioritise and carry out.

  • Maturity assessment
  • Risk identification and analysis
  • Review of the controls in place
  • Gap analysis against the chosen framework
  • Prioritisation of actions by impact and effort
  • Groundwork for security or compliance initiatives
ISO/IEC 27001 ISO/IEC 42001 ENS TISAX CIS Controls NIST CSF Microsoft environments Ad-hoc audit
02 Strategy and governance

Cybersecurity strategy and governance

Talk about strategy →

“We know we have to improve. Now we need to know how.”

This is where most organisations get stuck: there's an assessment, there's half a budget approved and there's a list of pending items nobody puts in order.

What's missing isn't technology. It's the judgement to set the order, turn it into a plan and keep it moving.

I cover it with three kinds of engagement: executing one specific piece, setting the direction, or outsourcing the leadership.

Technical consulting

Bringing the strategy down to the ground: what gets implemented, with what, and in what order.

  • Definition and implementation of the cybersecurity strategy
  • Tool selection and rollout
  • Design and implementation of controls
  • Improvement of existing security capabilities
  • Technical support for transformation initiatives
See the service →

Cybersecurity Master Plan & Roadmap

The document that turns an intention into a calendar with a budget attached.

  • Assessment of the current situation
  • Objectives and the maturity level to reach
  • Identification and prioritisation of initiatives
  • Roadmap and definition of the projects
  • Investment planning
See the service →

CISO as a Service

Outsourced cybersecurity leadership, full or partial, with an agreed level of dedication.

  • Cybersecurity governance and risk monitoring
  • Definition of the strategy and of the priorities
  • Coordination of initiatives and oversight of suppliers
  • Reporting to the board, to IT and to the other areas
  • Follow-up on the improvement plans
See the service →
Master plan CISO as a Service External CISO vCISO Governance Risk management Roadmap Security committee
03 Technical

Data security and Microsoft

See Microsoft security →

Protect information where it is actually used.

Most organisations have more security under contract than they use. Many Microsoft Entra and Microsoft Purview capabilities may already be included in licences that are paid for every month and configured halfway —usually because nobody has decided first which information matters and who should be able to reach it.

My work here has two halves: getting into service what is already paid for, and designing the model that holds it up, from identity through to how information moves.

Identity · Microsoft Entra

Who is who and how far they get. It's the control every other one rests on.

  • Identity and access model
  • Security controls over authentication
  • Privileged access management
  • Review of the permissions granted

Information · Microsoft Purview

What information exists, how it is labelled and what protection travels with it.

  • Information protection and labelling
  • Data governance
  • Classification by sensitivity
  • Security controls over use and access

Data Loss Prevention

A DLP strategy doesn't start in the admin console. It starts by answering a handful of uncomfortable questions, and in many organisations that part hasn't been done:

  • What information the organisation holds and where it lives
  • How it is classified and who has access to it
  • How it is shared and through which channels it moves
  • Which behaviours have to be blocked and which only monitored
  • Which information deserves the highest level of protection

Once those decisions are made, Microsoft Purview stops being the starting point and becomes what it should be: the technology that executes a strategy defined beforehand. Doing it the other way round ends in a pile of rules nobody dares switch to block mode.

See the service →
Microsoft Entra Microsoft Purview Data Loss Prevention DLP Identity Information protection Data governance Classification
04 Training

Culture, training and awareness

See the service →

Awareness is measured in behaviour, not in attendees.

One session a year, on its own, is unlikely to build a culture. What changes the outcome is repetition, content that speaks to the actual work of each role, and a measurement before and after to know whether anything moved.

Hence the distinction I keep on every project: running training is an action with a date on it; building a security culture is a continuous programme in which training is one piece among several.

Culture programme

The frame that holds up everything else: objectives, calendar, owners and measurement.

  • Cybersecurity culture programme
  • Awareness programmes and campaigns
  • Reinforcement on whatever isn't landing
  • Evaluation of results and follow-up

Training

Different content depending on who it's for: finance doesn't need the same session as IT.

  • General training for the whole workforce
  • Role-based training
  • Sessions for the board
  • Real cases from the organisation's own sector

Simulations

Social engineering and phishing with a learning objective, not an internal ranking.

  • Phishing simulations
  • Social engineering exercises
  • Results read by area and by role
  • Reinforcement aimed at whoever needs it
Security culture Awareness Role-based training Board training Simulated phishing Social engineering Measurement
05 Technical

Cybersecurity and artificial intelligence

See the service →

AI is already inside. What is missing is deciding how it is used.

In most companies AI arrives without a project: with a Copilot licence, a new CRM feature or someone's personal account. Meanwhile, the AI Act assigns obligations according to each organisation's role and the use it makes of each system.

I approach AI from cybersecurity. First, an applicability review system by system; with that in hand, the governance and technical controls you need.

Applicability review

What the AI Act requires of you, system by system, and how it fits with what you already comply with.

  • Inventory of AI systems and uses, including AI that arrives inside tools you already pay for
  • Your organisation's role: provider, deployer, importer or distributor
  • Risk classification and obligations with their dates
  • Cross-check against the GDPR, NIS2 and the Cyber Resilience Act
See how it works →

AI governance

Rules, owners and a process for deciding before AI turns up on its own.

  • AI acceptable use policy
  • Use case approval and register
  • AI supplier assessment
  • Gaps against ISO/IEC 42001

AI security

The risks specific to AI, built into the usual security analysis.

  • Threats in applications and agents
  • Data exposure in assistants
  • Requirements for AI projects
  • Logging and human oversight
AI Act ISO/IEC 42001 AI governance Generative AI Microsoft 365 Copilot AI agents Prompt injection AI literacy
How I work

From context to improvement, in five steps

Order matters more than speed. Each step leaves a concrete result that makes the next decision a better one.

  1. Understand

    What the organisation does, what it depends on, which assets it holds and what its clients and its sector are asking of it.

  2. Assess

    Risk, maturity, controls and capabilities: what is in place, what works and what is missing.

  3. Prioritise

    What deserves attention first, at what effort, and with what argument it holds up in front of the board.

  4. Execute

    Turning the decisions into projects with an owner, a deadline and a result that can be checked.

  5. Improve

    Measuring what was put in place, reviewing it and adjusting when the business or what's demanded of it changes.

Technical Training Leadership

Three capabilities. One way of understanding cybersecurity.

Let's talk

Not sure where to start? Let's start there.

Every organisation starts from a different point and hardly any of them have it written down. Tell me what worries you, what you're being asked for and what you have to work with. That conversation produces a first list of priorities, whether we end up working together or not.

I reply personally within 24 working hours · No commitment