The State of Cybersecurity

Hands-on assistance

Request assistance

Two decades in the field: incident command, SOC leadership, cloud security architecture, and the unglamorous work of making frameworks stick. If your problem is on this list, I can probably help. If it is not, I will say so and point you to someone who can.

  • Security programs & frameworks. NIST CSF 2.0 and CIS Controls alignment, one unified control set instead of four parallel compliance programs.
  • Ransomware readiness. Structured assessment of your backup, identity, and response posture before an attacker grades it for you.
  • Cloud security architecture. AWS, Azure, and GCP reviews, zero trust design, identity and privileged access. Pragmatic about what lean teams can actually operate.
  • Detection & SOC operations. Detection engineering and alert tuning that cuts noise instead of adding to it. I still write the queries myself.
  • AI security & governance. Risk-tiering AI use cases and putting real controls around LLM applications, not just a policy PDF.
  • Email authentication. SPF, DKIM, and DMARC to enforcement without breaking your mail flow.
  • Speaking & media. Podcasts, panels, and webinars on plain-English security, AI governance, and building in public.

Tell me what is going on

Goes straight to my inbox. No retainer talk until we both think it is a fit. Privacy.