01
Penetration Testing
Internal, external, web, wireless and mobile testing that ends in a fix list, not a scanner dump.
Authorised testing against the systems you actually run — external perimeter, internal network, web and mobile applications, wireless estate and cloud footprint. Findings are reproduced by hand and rated by what an attacker gains, not by a scanner's default severity. Every report ends with a remediation order of work your engineers can start on the same day.
- External and internal network penetration testing
- Web application and API testing (OWASP-aligned)
- Wireless and network hygiene audits
- Mobile application testing, iOS and Android
- IoT and embedded device assessment
- Retest and remediation verification
02
Red Team Operations
Full adversary simulation: black-box, social engineering, physical and wireless, against a live defence.
A penetration test asks whether a system can be broken. A red team engagement asks whether your people, process and detection notice. Objective-led, black-box, run against production with the SOC unaware — phishing and pretexting, wireless and physical entry, lateral movement and exfiltration — measured against MITRE ATT&CK so the outcome is a detection gap map rather than a war story.
- Objective-led adversary simulation
- Black-box and assumed-breach scenarios
- Social engineering and phishing campaigns
- Wireless and physical access testing
- Purple team: detection tuning alongside your SOC
- MITRE ATT&CK coverage mapping
03
Post-Quantum (PQC) Readiness
Cryptographic inventory, Harvest Now Decrypt Later exposure and a migration plan with dates on it.
Encrypted traffic captured today can be stored until a quantum computer can open it — the Harvest Now, Decrypt Later problem. Long-lived secrets are already exposed. I inventory what cryptography you actually use, score which of it fails under HNDL, and set out a migration path to NIST post-quantum standards in the order that reduces real risk first. Eight years of research behind QuantumHandshake™ sits under this work.
- Cryptographic asset discovery and inventory
- Harvest Now, Decrypt Later (HNDL) risk scoring
- Crypto-agility and migration roadmap
- NIST PQC standards alignment (ML-KEM, ML-DSA)
- Certificate, key and TLS estate review
- Board-level briefing on quantum exposure
04
AI and Machine Learning Security
Two directions: machine learning that catches what rules miss, and securing the AI systems themselves.
Detection has outgrown signatures. I build and tune the behavioural and anomaly models that find the activity no rule was written for — network threat analytics, user and entity behaviour, and the data pipelines and visualisation that make a SOC able to act on them. The other direction matters just as much now: AI systems are themselves attack surface, from model manipulation and data poisoning to the identity and authentication layer that decides what an agent is allowed to do. That second problem is what AI-integrated identity in QuantumHandshake™ exists to solve.
- ML-driven anomaly and behavioural detection
- Network threat analytics (NTA) and UEBA tuning
- AI-assisted triage, SOAR and alert reduction
- Adversarial ML and model threat assessment
- AI-integrated identity and agent authorisation design
- Security data pipelines, analytics and visualisation
05
Private Cyber Investigations
Confidential digital forensics and investigation, run so the evidence survives scrutiny.
Discreet investigation into intrusion, insider activity, data theft, fraud and account compromise. Acquisition and analysis follow a defensible chain of custody so findings hold up in disciplinary, civil or criminal proceedings. Certified in computer hacking forensic investigation (CHFI) and forensic analysis (CFA); engagements are run under NDA and reported to you alone.
- Intrusion and breach investigation
- Insider threat and data exfiltration cases
- Host, disk, memory and network forensics
- Evidence acquisition with chain of custody
- Dark-web exposure and credential-leak tracing
- Expert reporting for legal and HR proceedings
06
SOC and SIEM Build
Design, build and staff a security operations centre — or fix the SIEM that is drowning your analysts.
Standing up detection from nothing, or rescuing a SIEM that generates more alerts than anyone can read. Log source strategy, use-case and detection engineering, alert triage and escalation runbooks, analyst rotas and shift handover. Detection content is mapped to MITRE ATT&CK so coverage is a measurable figure rather than an opinion.
- SOC design, build and operating model
- SIEM deployment, migration and tuning
- Log source strategy and coverage assessment
- Detection engineering and use-case development
- MITRE ATT&CK coverage mapping
- Analyst runbooks, triage and escalation process
07
Incident Response and CSIRT Readiness
Containment when it is happening, and the playbooks that stop the next one becoming a crisis.
Live incident command through triage, containment, eradication and recovery — plus the preparation that decides how the bad day goes. Playbooks, tabletop exercises and a tested escalation path, written on the principle that governs emergency medicine and applies exactly to incident response: do no harm. Most of the damage in an incident is done by the response, not the intruder.
- Incident command and live containment
- Ransomware response and recovery
- CSIRT design, playbooks and first-aid guides
- Tabletop exercises and crisis simulation
- Post-incident review and root cause analysis
- Regulatory and breach notification support
08
Threat Intelligence and Dark-Web Monitoring
What the criminal market already knows about your organisation, and what to do about it.
Monitoring of dark-web markets, paste sites, breach corpora and criminal forums for your domains, executives, credentials and supplier chain. Intelligence is delivered labelled by evidence and confidence, not as a raw feed — so it drives a decision rather than another dashboard nobody reads.
- Dark-web and deep-web monitoring
- Credential and breach-corpus exposure
- Executive and brand impersonation tracking
- Supply-chain and third-party exposure
- Threat actor profiling and campaign tracking
- Evidence-labelled intelligence reporting
09
Attack Surface and OSINT Reconnaissance
Everything the outside world can see about you, assembled before an attacker assembles it.
Passive reconnaissance across DNS, certificates, registries, breach data, social platforms and reputation feeds — the external view of your estate, including the assets nobody remembers owning. This is the discipline AiiDIS™ was built from: 237 modules across 12 disciplines, started in 2017 as my own field tool and hardened on live engagements ever since.
- External attack surface discovery
- Shadow IT and forgotten asset identification
- DNS, certificate and registry footprinting
- Passive reconnaissance — no packets to your target
- Executive and employee OSINT exposure
- Continuous monitoring and change alerting
10
Security Architecture Review
A design assessment that finds the flaw before it is built into production.
Review of network, cloud and application architecture against the way real attacks move — segmentation and trust boundaries, identity and privilege, key management, logging and egress control. Cheaper by an order of magnitude at design stage than after the estate is running on it.
- Network and cloud architecture review
- Segmentation and trust boundary analysis
- Identity, access and privilege model review
- Zero-trust design and roadmap
- Key management and cryptographic design
- Secure-by-design advisory for new builds
11
DDoS Resilience Engineering
Mitigation architecture and load testing for services that cannot be allowed to fall over.
Volumetric, protocol and application-layer denial of service — designing the mitigation, then proving it under authorised load. Covers redundant DNS strategy, upstream scrubbing, rate limiting and origin concealment, with the traffic analysis to tell an attack from a bad deployment.
- DDoS mitigation architecture and review
- Authorised load and resilience testing
- Redundant DNS and failover strategy
- Rate limiting and traffic shaping design
- Upstream scrubbing and provider selection
- Attack traffic analysis and forensics
12
Compliance and Audit
PCI-DSS, ISO 27001 and GDPR taken from gap analysis to signed-off evidence.
Audit preparation and delivery from initial gap analysis through remediation to final evidence pack. The point is not the certificate — it is that the controls behind it actually work, which is where an assessor with an offensive background is worth more than one with a checklist.
- PCI-DSS assessment and remediation
- ISO 27001 gap analysis and readiness
- GDPR audit, DPIA and data mapping
- Control design and evidence preparation
- Third-party and supplier security assessment
- Policy, standard and procedure authoring
13
vCISO and Security Leadership
Board-level security leadership without carrying a full-time CISO on the payroll.
Fractional CISO engagement — security strategy, risk register, budget and roadmap, board and audit committee reporting, team building and vendor selection. Twenty years of running it, including SOC leadership and national-level advisory on electronic revenue policy, cryptography and digital sovereignty.
- Fractional and interim CISO engagements
- Security strategy, roadmap and budget
- Board and audit committee reporting
- Risk register design and risk treatment
- Security team hiring and capability building
- Vendor and technology selection
14
Security Awareness, Training and Speaking
Training built from real engagements, and keynotes that do not read from the vendor script.
Staff awareness programmes, technical upskilling for engineering and SOC teams, and conference keynotes on the shifting threat landscape. Material comes out of live engagements — including the phishing campaigns and lab builds on this site — rather than a generic slide pack.
- Staff security awareness programmes
- Simulated phishing campaigns and measurement
- Technical training for engineering and SOC teams
- Executive and board briefings
- Conference keynotes and panel appearances
- University guest lectures