Twenty years of breaking into networks, leading security operations and building the cryptography that has to outlast them. Engagements run UK-wide and remote, under NDA.
If your technology supplier walked out tomorrow, could you carry on? Ten checks, one number.
An independent audit of whether you actually control the product somebody else builds for you — repository and cloud ownership, who holds the top-level credentials, whether intellectual property assigns on creation or on final payment, whether a new team could deploy without asking, and what your contract says about the day you leave. Sold to no vendor and paid by no vendor: no commission, no referral fee, no reseller margin, ever. Ten working days, fixed fee, and a free ten-question self-assessment that scores in your own browser.
Free ten-question self-assessment, scored in your browser
Repository, cloud account and domain ownership verification
Credential register: every production system and who holds the keys
Contract review: IP assignment trigger and exit terms
Build and deploy reproducibility without supplier involvement
Internal, external, web, wireless and mobile testing that ends in a fix list, not a scanner dump.
Authorised testing against the systems you actually run — external perimeter, internal network, web and mobile applications, wireless estate and cloud footprint. Findings are reproduced by hand and rated by what an attacker gains, not by a scanner's default severity. Every report ends with a remediation order of work your engineers can start on the same day.
External and internal network penetration testing
Web application and API testing (OWASP-aligned)
Wireless and network hygiene audits
Mobile application testing, iOS and Android
IoT and embedded device assessment
Retest and remediation verification
03
Red Team Operations
Full adversary simulation: black-box, social engineering, physical and wireless, against a live defence.
A penetration test asks whether a system can be broken. A red team engagement asks whether your people, process and detection notice. Objective-led, black-box, run against production with the SOC unaware — phishing and pretexting, wireless and physical entry, lateral movement and exfiltration — measured against MITRE ATT&CK so the outcome is a detection gap map rather than a war story.
Objective-led adversary simulation
Black-box and assumed-breach scenarios
Social engineering and phishing campaigns
Wireless and physical access testing
Purple team: detection tuning alongside your SOC
MITRE ATT&CK coverage mapping
04
Post-Quantum (PQC) Readiness
Cryptographic inventory, Harvest Now Decrypt Later exposure and a migration plan with dates on it.
Encrypted traffic captured today can be stored until a quantum computer can open it — the Harvest Now, Decrypt Later problem. Long-lived secrets are already exposed. I inventory what cryptography you actually use, score which of it fails under HNDL, and set out a migration path to NIST post-quantum standards in the order that reduces real risk first. Eight years of research behind QuantumHandshake™ sits under this work.
Cryptographic asset discovery and inventory
Harvest Now, Decrypt Later (HNDL) risk scoring
Crypto-agility and migration roadmap
NIST PQC standards alignment (ML-KEM, ML-DSA)
Certificate, key and TLS estate review
Board-level briefing on quantum exposure
05
AI and Machine Learning Security
Two directions: machine learning that catches what rules miss, and securing the AI systems themselves.
Detection has outgrown signatures. I build and tune the behavioural and anomaly models that find the activity no rule was written for — network threat analytics, user and entity behaviour, and the data pipelines and visualisation that make a SOC able to act on them. The other direction matters just as much now: AI systems are themselves attack surface, from model manipulation and data poisoning to the identity and authentication layer that decides what an agent is allowed to do. That second problem is what AI-integrated identity in QuantumHandshake™ exists to solve.
ML-driven anomaly and behavioural detection
Network threat analytics (NTA) and UEBA tuning
AI-assisted triage, SOAR and alert reduction
Adversarial ML and model threat assessment
AI-integrated identity and agent authorisation design
Security data pipelines, analytics and visualisation
06
Private Cyber Investigations
Confidential digital forensics and investigation, run so the evidence survives scrutiny.
Discreet investigation into intrusion, insider activity, data theft, fraud and account compromise. Acquisition and analysis follow a defensible chain of custody so findings hold up in disciplinary, civil or criminal proceedings. Certified in computer hacking forensic investigation (CHFI) and forensic analysis (CFA); engagements are run under NDA and reported to you alone.
Intrusion and breach investigation
Insider threat and data exfiltration cases
Host, disk, memory and network forensics
Evidence acquisition with chain of custody
Dark-web exposure and credential-leak tracing
Expert reporting for legal and HR proceedings
07
SOC and SIEM Build
Design, build and staff a security operations centre — or fix the SIEM that is drowning your analysts.
Standing up detection from nothing, or rescuing a SIEM that generates more alerts than anyone can read. Log source strategy, use-case and detection engineering, alert triage and escalation runbooks, analyst rotas and shift handover. Detection content is mapped to MITRE ATT&CK so coverage is a measurable figure rather than an opinion.
SOC design, build and operating model
SIEM deployment, migration and tuning
Log source strategy and coverage assessment
Detection engineering and use-case development
MITRE ATT&CK coverage mapping
Analyst runbooks, triage and escalation process
08
Incident Response and CSIRT Readiness
Containment when it is happening, and the playbooks that stop the next one becoming a crisis.
Live incident command through triage, containment, eradication and recovery — plus the preparation that decides how the bad day goes. Playbooks, tabletop exercises and a tested escalation path, written on the principle that governs emergency medicine and applies exactly to incident response: do no harm. Most of the damage in an incident is done by the response, not the intruder.
Incident command and live containment
Ransomware response and recovery
CSIRT design, playbooks and first-aid guides
Tabletop exercises and crisis simulation
Post-incident review and root cause analysis
Regulatory and breach notification support
09
Threat Intelligence and Dark-Web Monitoring
What the criminal market already knows about your organisation, and what to do about it.
Monitoring of dark-web markets, paste sites, breach corpora and criminal forums for your domains, executives, credentials and supplier chain. Intelligence is delivered labelled by evidence and confidence, not as a raw feed — so it drives a decision rather than another dashboard nobody reads.
Dark-web and deep-web monitoring
Credential and breach-corpus exposure
Executive and brand impersonation tracking
Supply-chain and third-party exposure
Threat actor profiling and campaign tracking
Evidence-labelled intelligence reporting
10
Attack Surface and OSINT Reconnaissance
Everything the outside world can see about you, assembled before an attacker assembles it.
Passive reconnaissance across DNS, certificates, registries, breach data, social platforms and reputation feeds — the external view of your estate, including the assets nobody remembers owning. This is the discipline AiiDIS™ was built from: 237 modules across 12 disciplines, started in 2017 as my own field tool and hardened on live engagements ever since.
External attack surface discovery
Shadow IT and forgotten asset identification
DNS, certificate and registry footprinting
Passive reconnaissance — no packets to your target
Executive and employee OSINT exposure
Continuous monitoring and change alerting
11
Security Architecture Review
A design assessment that finds the flaw before it is built into production.
Review of network, cloud and application architecture against the way real attacks move — segmentation and trust boundaries, identity and privilege, key management, logging and egress control. Cheaper by an order of magnitude at design stage than after the estate is running on it.
Network and cloud architecture review
Segmentation and trust boundary analysis
Identity, access and privilege model review
Zero-trust design and roadmap
Key management and cryptographic design
Secure-by-design advisory for new builds
12
DDoS Resilience Engineering
Mitigation architecture and load testing for services that cannot be allowed to fall over.
Volumetric, protocol and application-layer denial of service — designing the mitigation, then proving it under authorised load. Covers redundant DNS strategy, upstream scrubbing, rate limiting and origin concealment, with the traffic analysis to tell an attack from a bad deployment.
DDoS mitigation architecture and review
Authorised load and resilience testing
Redundant DNS and failover strategy
Rate limiting and traffic shaping design
Upstream scrubbing and provider selection
Attack traffic analysis and forensics
13
Compliance and Audit
PCI-DSS, ISO 27001 and GDPR taken from gap analysis to signed-off evidence.
Audit preparation and delivery from initial gap analysis through remediation to final evidence pack. The point is not the certificate — it is that the controls behind it actually work, which is where an assessor with an offensive background is worth more than one with a checklist.
PCI-DSS assessment and remediation
ISO 27001 gap analysis and readiness
GDPR audit, DPIA and data mapping
Control design and evidence preparation
Third-party and supplier security assessment
Policy, standard and procedure authoring
14
vCISO and Security Leadership
Board-level security leadership without carrying a full-time CISO on the payroll.
Fractional CISO engagement — security strategy, risk register, budget and roadmap, board and audit committee reporting, team building and vendor selection. Twenty years of running it, including SOC leadership and national-level advisory on electronic revenue policy, cryptography and digital sovereignty.
Fractional and interim CISO engagements
Security strategy, roadmap and budget
Board and audit committee reporting
Risk register design and risk treatment
Security team hiring and capability building
Vendor and technology selection
15
Security Awareness, Training and Speaking
Training built from real engagements, and keynotes that do not read from the vendor script.
Staff awareness programmes, technical upskilling for engineering and SOC teams, and conference keynotes on the shifting threat landscape. Material comes out of live engagements — including the phishing campaigns and lab builds on this site — rather than a generic slide pack.
Staff security awareness programmes
Simulated phishing campaigns and measurement
Technical training for engineering and SOC teams
Executive and board briefings
Conference keynotes and panel appearances
University guest lectures
02
Not sure which of these you need?
Most engagements start as one of the above and turn out to be two. Describe
what you are worried about and I will tell you which it is — including
when the answer is that you do not need me yet.