Where I help
A policy is not a security control unless the organisation can operate it. I work from the real environment outward: what needs protecting, who has access, where the evidence lives and what happens when something fails.
My security work is grounded in operations. I focus on controls that can actually be maintained: access, endpoint and network security, vulnerabilities, evidence, recovery and data protection.
Discuss a project ↗A policy is not a security control unless the organisation can operate it. I work from the real environment outward: what needs protecting, who has access, where the evidence lives and what happens when something fails.
Scope depends on the problem. These are areas I can own directly.
Send me the problem, the current setup and what you need to be different. I will tell you where I can genuinely help.