Technical cybersecurity consulting

Turning a business need or a specific risk into controls, architecture and tools that actually work, with independent judgement and without being tied to a vendor.

When it makes sense

When it is already clear what needs solving

Some security decisions don't fit into an audit and can't wait for a master plan: choosing a tool this quarter, defining how a system going live in May gets protected, or checking whether what was built two years ago still makes sense.

This is the engagement for that. Specific technical work, with risk judgement behind it and the scope agreed before starting, on whatever ground it takes —not only the part already covered by Microsoft security or information protection.

You have to choose and nobody is comparing

Three vendors, three demos and no way to tell which one solves your problem. What is missing is someone to translate the sales pitch into what you will actually use.

A project needs security judgement

Something new is being built —a system, an integration, a migration— and someone needs to define how it gets protected before it is running, not after.

It was built and nobody has looked at it since

There are controls that have been running for years without review. Nobody knows whether they still cover what they covered, or whether they get in the way more than they help.

What's included

The kind of engagement that fits here

Work with an agreed scope, which doesn't depend on a master plan existing behind it or on signing up for a retained service.

Controls and architecture

Defining how something gets protected, and leaving it working.

  • Design and implementation of technical controls
  • Design of security architecture and capabilities
  • Review of configurations and technical models
  • Improvement of the security capabilities already in place

Tool selection

Deciding on your own criteria rather than on the vendor's pitch.

  • Defining the real requirements before looking at any product
  • Reasoned comparison between alternatives
  • Proofs of concept and validation
  • Implementation of the chosen tool

From risk to solution

The translation that tends to be missing between what worries the business and what has to be built.

  • Translating a business or risk need into a technical solution
  • Technical support for improvement and transformation initiatives
  • On-the-ground implementation of the defined security strategy
  • Support for your team while the implementation lasts
How I work

How an engagement is set up

Four phases, with scope and days agreed before starting and no need for a prior plan to exist.

  1. Framing

    What needs solving, what risk sits behind it and what the constraints are: budget, deadlines, team and whatever is already in place.

  2. Design

    The solution on paper: controls, architecture or tool requirements, with the discarded alternatives and the reason for each.

  3. Implementation

    Rollout in phases, with your team involved from the start so it doesn't end up a black box only the person who built it can touch.

  4. Handover

    Verification that it does what was expected, operating documentation, and handover to whoever will maintain it from then on.

What you get

What stays when the engagement closes

What was built, and the reasoning behind each decision for whoever inherits it in two years.

  • Documented technical design
  • Decision criteria and discarded alternatives
  • Configuration implemented and verified
  • Tool comparison, where there is a selection
  • Operating documentation for your team
  • Recommendations on what to revisit later

Scope of the serviceThe engagement runs up to the design, the implementation and the documented handover; day-to-day operation of what was built stays with your team or your supplier. I don't run penetration tests or continuous monitoring, and I don't resell product: if the comparison concludes that the best option is the one you already have, that is the recommendation you will get.

Frequently asked questions

What people usually ask before engaging

How is this different from a master plan?

The plan decides what gets done and in what order, over several financial years. This is executing one specific piece, and it doesn't need a plan to exist first: plenty of engagements arrive because something has to be solved this quarter. If it turns out the underlying problem is a lack of order, I will say so, and what you probably need is the other one.

Do you only work on Microsoft?

No. That is where my deepest specialisation is, which is why it has its own page, but this service exists precisely for what falls outside it: architecture, controls and tools from any vendor. If the engagement lands squarely on Entra or Purview, it fits better in the other one.

Can you help us choose a tool without implementing it?

Yes, and it is a fairly short engagement. The real requirements get defined, the alternatives compared, and you get the comparison with a reasoned recommendation. What you do with it afterwards is your call: you can implement it with anyone, including your current supplier.

Will you work with our current supplier?

Yes, and it is usually the most efficient route. Often the engagement consists precisely of bringing security judgement to what someone else is already doing: reviewing a proposal, adjusting a design, or translating what the business asks for into technical requirements. I don't come in to replace anyone unless you ask me to.

How long does an engagement like this take?

It varies a lot by type. A configuration review or a tool comparison is measured in days; designing and implementing a new control, in weeks. Scope and days are agreed before starting rather than as we go, so you know the cost from the outset.

Where to go next

Let's talk

Have something specific to build, review or choose?

Tell me what is on the table and what constraints you are working with. One conversation is enough to see whether it is a bounded engagement of a few days or whether there is a bigger decision behind it worth ordering first.

I reply personally within 24 working hours · No commitment