Turning a business need or a specific risk into controls, architecture and tools that actually work, with independent judgement and without being tied to a vendor.
Some security decisions don't fit into an audit and can't wait for a master plan: choosing a tool this quarter, defining how a system going live in May gets protected, or checking whether what was built two years ago still makes sense.
This is the engagement for that. Specific technical work, with risk judgement behind it and the scope agreed before starting, on whatever ground it takes —not only the part already covered by Microsoft security or information protection.
Three vendors, three demos and no way to tell which one solves your problem. What is missing is someone to translate the sales pitch into what you will actually use.
Something new is being built —a system, an integration, a migration— and someone needs to define how it gets protected before it is running, not after.
There are controls that have been running for years without review. Nobody knows whether they still cover what they covered, or whether they get in the way more than they help.
Work with an agreed scope, which doesn't depend on a master plan existing behind it or on signing up for a retained service.
Defining how something gets protected, and leaving it working.
Deciding on your own criteria rather than on the vendor's pitch.
The translation that tends to be missing between what worries the business and what has to be built.
Four phases, with scope and days agreed before starting and no need for a prior plan to exist.
What needs solving, what risk sits behind it and what the constraints are: budget, deadlines, team and whatever is already in place.
The solution on paper: controls, architecture or tool requirements, with the discarded alternatives and the reason for each.
Rollout in phases, with your team involved from the start so it doesn't end up a black box only the person who built it can touch.
Verification that it does what was expected, operating documentation, and handover to whoever will maintain it from then on.
What was built, and the reasoning behind each decision for whoever inherits it in two years.
Scope of the serviceThe engagement runs up to the design, the implementation and the documented handover; day-to-day operation of what was built stays with your team or your supplier. I don't run penetration tests or continuous monitoring, and I don't resell product: if the comparison concludes that the best option is the one you already have, that is the recommendation you will get.
The plan decides what gets done and in what order, over several financial years. This is executing one specific piece, and it doesn't need a plan to exist first: plenty of engagements arrive because something has to be solved this quarter. If it turns out the underlying problem is a lack of order, I will say so, and what you probably need is the other one.
No. That is where my deepest specialisation is, which is why it has its own page, but this service exists precisely for what falls outside it: architecture, controls and tools from any vendor. If the engagement lands squarely on Entra or Purview, it fits better in the other one.
Yes, and it is a fairly short engagement. The real requirements get defined, the alternatives compared, and you get the comparison with a reasoned recommendation. What you do with it afterwards is your call: you can implement it with anyone, including your current supplier.
Yes, and it is usually the most efficient route. Often the engagement consists precisely of bringing security judgement to what someone else is already doing: reviewing a proposal, adjusting a design, or translating what the business asks for into technical requirements. I don't come in to replace anyone unless you ask me to.
It varies a lot by type. A configuration review or a tool comparison is measured in days; designing and implementing a new control, in weeks. Scope and days are agreed before starting rather than as we go, so you know the cost from the outset.
Tell me what is on the table and what constraints you are working with. One conversation is enough to see whether it is a bounded engagement of a few days or whether there is a bigger decision behind it worth ordering first.
I reply personally within 24 working hours · No commitment