Security advice that stands up to an audit.

Independent external advisor for ISO 27001, NIS2, Blue Team and disaster recovery: clear priorities rather than more tooling.

Email me View services

Frameworks and standards

  • ISO/IEC 27001
  • NIS2
  • NIST CSF
  • BSI IT-Grundschutz
  • GDPR
  • Zero Trust

Services

Independent security advice for mid-sized companies, public bodies and growing IT teams: from strategy and compliance to hands-on Blue Team support.

  • External Security Advisor (vCISO)

    Senior security leadership on demand. I take on the CISO role part-time, run your security programme and represent security towards management, customers and auditors, without the cost of a full-time hire.

    • Security strategy and multi-year roadmap
    • Management and board reporting
    • Answers to customer and supplier security questionnaires
  • Security architecture review

    Identity, network, cloud and endpoint design assessed against Zero Trust principles, with concrete recommendations for Microsoft 365 and Azure environments.

    • Architecture and identity assessment
    • Target architecture with quick wins
    • Prioritised remediation plan
  • ISO 27001 and ISMS

    Build or mature an information security management system that is certifiable and workable in daily operations. Includes gap analysis and audit and compliance readiness.

    • Scoping and gap analysis
    • Risk assessment, policies and Statement of Applicability
    • Internal audit and certification preparation
  • NIS2 readiness

    Find out whether NIS2 applies to your organisation and close the gaps in risk management, incident reporting and supply chain security.

    • Applicability check
    • Measures mapped to NIS2 requirements
    • Reporting and evidence processes
  • Blue Team and detection advisory

    Review of logging, monitoring and response capability, including MDR and SOC arrangements, so that attacks are detected and contained faster.

    • Detection coverage and use-case review
    • Incident response plans and playbooks
    • Tabletop exercises with your team
  • Disaster recovery and continuity plans

    Written disaster recovery and business continuity plans that define recovery priorities, roles and procedures, and that have been tested before you need them.

    • Business impact analysis
    • Recovery plans and runbooks
    • Test and exercise schedule
  • Data protection and GDPR security

    Technical and organisational measures (TOMs) that support GDPR compliance and align with your security controls. This is security advisory, not legal advice.

    • TOM documentation
    • Access, encryption and logging concepts
    • Data breach response process
  • Security workshops and training

    Hands-on workshops for IT teams and management: incident response, NIS2 and ISO 27001 fundamentals, security awareness and tabletop exercises.

    • Tailored to your audience
    • Practical exercises instead of slides
    • Materials for follow-up
  • Security roadmap and governance

    A prioritised, budget-aware plan and reporting that security and business leaders can both follow.

    • Risk-ranked initiative list
    • Budget and effort estimates
    • Quarterly progress reporting

How an engagement works

  1. Scope

    We agree on objectives, systems in scope and the standards that apply.

  2. Assess

    Interviews, document review and technical checks establish the facts.

  3. Prioritise

    Findings are ranked by risk and effort, not by volume.

  4. Advise

    You receive a written report and roadmap, and a walkthrough with your team.

Background

I advise IT and security leaders on architecture, risk and compliance. My background spans managed detection and response, cloud and identity architecture, and consulting for enterprise customers. I focus on recommendations that can be implemented and defended in front of an auditor.

Frequently asked questions

What is an external cyber security advisor or vCISO?

A vCISO is an experienced security leader who works for you part-time or on a project basis. You get strategy, governance and hands-on guidance without hiring a full-time CISO.

Does NIS2 apply to my company?

It depends on your sector, size and role in the supply chain. An applicability check is usually the first step; it takes a short conversation and a review of your business activities.

How long does ISO 27001 preparation take?

That depends on size, scope and current maturity. A gap analysis shows the realistic timeline; many organisations need several months from kick-off to the certification audit.

Do you write disaster recovery plans?

Yes. Plans are written together with your IT and business owners, based on a business impact analysis, and include a schedule for testing them.

Start with an email

Describe your situation in a few sentences: the organisation, the standard or audit you are working toward, and the timeline. I will reply with next steps.