Hands-on assistance
Request assistance
Two decades in the field: incident command, SOC leadership, cloud security architecture, and the unglamorous work of making frameworks stick. If your problem is on this list, I can probably help. If it is not, I will say so and point you to someone who can.
- Security programs & frameworks. NIST CSF 2.0 and CIS Controls alignment, one unified control set instead of four parallel compliance programs.
- Ransomware readiness. Structured assessment of your backup, identity, and response posture before an attacker grades it for you.
- Cloud security architecture. AWS, Azure, and GCP reviews, zero trust design, identity and privileged access. Pragmatic about what lean teams can actually operate.
- Detection & SOC operations. Detection engineering and alert tuning that cuts noise instead of adding to it. I still write the queries myself.
- AI security & governance. Risk-tiering AI use cases and putting real controls around LLM applications, not just a policy PDF.
- Email authentication. SPF, DKIM, and DMARC to enforcement without breaking your mail flow.
- Speaking & media. Podcasts, panels, and webinars on plain-English security, AI governance, and building in public.