Security advice that stands up to an audit.
Independent external advisor for ISO 27001, NIS2, Blue Team and disaster recovery: clear priorities rather than more tooling.
Frameworks and standards
- ISO/IEC 27001
- NIS2
- NIST CSF
- BSI IT-Grundschutz
- GDPR
- Zero Trust
Services
Independent security advice for mid-sized companies, public bodies and growing IT teams: from strategy and compliance to hands-on Blue Team support.
-
External Security Advisor (vCISO)
Senior security leadership on demand. I take on the CISO role part-time, run your security programme and represent security towards management, customers and auditors, without the cost of a full-time hire.
- Security strategy and multi-year roadmap
- Management and board reporting
- Answers to customer and supplier security questionnaires
-
Security architecture review
Identity, network, cloud and endpoint design assessed against Zero Trust principles, with concrete recommendations for Microsoft 365 and Azure environments.
- Architecture and identity assessment
- Target architecture with quick wins
- Prioritised remediation plan
-
ISO 27001 and ISMS
Build or mature an information security management system that is certifiable and workable in daily operations. Includes gap analysis and audit and compliance readiness.
- Scoping and gap analysis
- Risk assessment, policies and Statement of Applicability
- Internal audit and certification preparation
-
NIS2 readiness
Find out whether NIS2 applies to your organisation and close the gaps in risk management, incident reporting and supply chain security.
- Applicability check
- Measures mapped to NIS2 requirements
- Reporting and evidence processes
-
Blue Team and detection advisory
Review of logging, monitoring and response capability, including MDR and SOC arrangements, so that attacks are detected and contained faster.
- Detection coverage and use-case review
- Incident response plans and playbooks
- Tabletop exercises with your team
-
Disaster recovery and continuity plans
Written disaster recovery and business continuity plans that define recovery priorities, roles and procedures, and that have been tested before you need them.
- Business impact analysis
- Recovery plans and runbooks
- Test and exercise schedule
-
Data protection and GDPR security
Technical and organisational measures (TOMs) that support GDPR compliance and align with your security controls. This is security advisory, not legal advice.
- TOM documentation
- Access, encryption and logging concepts
- Data breach response process
-
Security workshops and training
Hands-on workshops for IT teams and management: incident response, NIS2 and ISO 27001 fundamentals, security awareness and tabletop exercises.
- Tailored to your audience
- Practical exercises instead of slides
- Materials for follow-up
-
Security roadmap and governance
A prioritised, budget-aware plan and reporting that security and business leaders can both follow.
- Risk-ranked initiative list
- Budget and effort estimates
- Quarterly progress reporting
How an engagement works
-
Scope
We agree on objectives, systems in scope and the standards that apply.
-
Assess
Interviews, document review and technical checks establish the facts.
-
Prioritise
Findings are ranked by risk and effort, not by volume.
-
Advise
You receive a written report and roadmap, and a walkthrough with your team.
Background
I advise IT and security leaders on architecture, risk and compliance. My background spans managed detection and response, cloud and identity architecture, and consulting for enterprise customers. I focus on recommendations that can be implemented and defended in front of an auditor.
Frequently asked questions
What is an external cyber security advisor or vCISO?
A vCISO is an experienced security leader who works for you part-time or on a project basis. You get strategy, governance and hands-on guidance without hiring a full-time CISO.
Does NIS2 apply to my company?
It depends on your sector, size and role in the supply chain. An applicability check is usually the first step; it takes a short conversation and a review of your business activities.
How long does ISO 27001 preparation take?
That depends on size, scope and current maturity. A gap analysis shows the realistic timeline; many organisations need several months from kick-off to the certification audit.
Do you write disaster recovery plans?
Yes. Plans are written together with your IT and business owners, based on a business impact analysis, and include a schedule for testing them.