Strategy, technical capability and training, so an organisation knows where it stands, what to deal with first and how to keep moving.
A company that has just received its first security questionnaire from a client is not in the same place as one with a management system certified three years ago and an appetite for getting more out of the licences it already pays for. The first needs order. The second needs depth.
Rolling out controls is only one part. The hard bit is deciding which ones, in what order and on what criteria. That's where my work starts, and it's why it almost always starts with an assessment rather than a tool.
The three things I look at before proposing anything:
What the organisation does, what it depends on to get through an ordinary Monday, and who demands what of it: clients, parent company, sector and applicable regulation.
What can go wrong, how likely it is and what it takes down with it. Risk sets the order of the list; the budget decides how far down it you get.
Some capabilities only work if the ones before them are already standing. Skipping that order is the quickest way to spend a security budget badly.
Know where you stand before deciding where to go.
An audit doesn't have to end in a certificate. Most of the time it serves something more immediate: putting in writing which controls exist, which ones actually work, which ones only exist as an intention, and what is missing —ordered by impact and by effort.
I work with the frameworks the sector already uses, and also with tailored reviews when none of them quite fits what the organisation needs to look at. The result turns into conclusions the board can use and concrete actions IT can prioritise and carry out.
“We know we have to improve. Now we need to know how.”
This is where most organisations get stuck: there's an assessment, there's half a budget approved and there's a list of pending items nobody puts in order.
What's missing isn't technology. It's the judgement to set the order, turn it into a plan and keep it moving.
I cover it with three kinds of engagement: executing one specific piece, setting the direction, or outsourcing the leadership.
Bringing the strategy down to the ground: what gets implemented, with what, and in what order.
The document that turns an intention into a calendar with a budget attached.
Outsourced cybersecurity leadership, full or partial, with an agreed level of dedication.
Protect information where it is actually used.
Most organisations have more security under contract than they use. Many Microsoft Entra and Microsoft Purview capabilities may already be included in licences that are paid for every month and configured halfway —usually because nobody has decided first which information matters and who should be able to reach it.
My work here has two halves: getting into service what is already paid for, and designing the model that holds it up, from identity through to how information moves.
Who is who and how far they get. It's the control every other one rests on.
What information exists, how it is labelled and what protection travels with it.
A DLP strategy doesn't start in the admin console. It starts by answering a handful of uncomfortable questions, and in many organisations that part hasn't been done:
Once those decisions are made, Microsoft Purview stops being the starting point and becomes what it should be: the technology that executes a strategy defined beforehand. Doing it the other way round ends in a pile of rules nobody dares switch to block mode.
See the service →Awareness is measured in behaviour, not in attendees.
One session a year, on its own, is unlikely to build a culture. What changes the outcome is repetition, content that speaks to the actual work of each role, and a measurement before and after to know whether anything moved.
Hence the distinction I keep on every project: running training is an action with a date on it; building a security culture is a continuous programme in which training is one piece among several.
The frame that holds up everything else: objectives, calendar, owners and measurement.
Different content depending on who it's for: finance doesn't need the same session as IT.
Social engineering and phishing with a learning objective, not an internal ranking.
AI is already inside. What is missing is deciding how it is used.
In most companies AI arrives without a project: with a Copilot licence, a new CRM feature or someone's personal account. Meanwhile, the AI Act assigns obligations according to each organisation's role and the use it makes of each system.
I approach AI from cybersecurity. First, an applicability review system by system; with that in hand, the governance and technical controls you need.
What the AI Act requires of you, system by system, and how it fits with what you already comply with.
Rules, owners and a process for deciding before AI turns up on its own.
The risks specific to AI, built into the usual security analysis.
Order matters more than speed. Each step leaves a concrete result that makes the next decision a better one.
What the organisation does, what it depends on, which assets it holds and what its clients and its sector are asking of it.
Risk, maturity, controls and capabilities: what is in place, what works and what is missing.
What deserves attention first, at what effort, and with what argument it holds up in front of the board.
Turning the decisions into projects with an owner, a deadline and a result that can be checked.
Measuring what was put in place, reviewing it and adjusting when the business or what's demanded of it changes.
Three capabilities. One way of understanding cybersecurity.
Every organisation starts from a different point and hardly any of them have it written down. Tell me what worries you, what you're being asked for and what you have to work with. That conversation produces a first list of priorities, whether we end up working together or not.
I reply personally within 24 working hours · No commitment