Skip to content

Engagements shaped around the problem, not a package.

Eight areas of work, grouped into three practices. Most engagements combine two or three, and scope follows a conversation about your situation.

Third-party risk and compliance

The core of the practice: vendor-risk programs that route, tier, and document, and audit preparation that closes the gap between written policy and daily practice.

Third-party and vendor risk management

  • Program design
  • Intake & risk tiering
  • Vendor assessments
  • SOC 1 / SOC 2 / ISO 27001 evidence review
  • Remediation tracking
  • Risk registers

The problem

Vendor review either blocks the business for months or waves things through on a questionnaire nobody reads.

The work

I design or rebuild the program end to end — intake that routes, tiering tied to data and access, assessment depth matched to tier — and run the assessments, reading SOC 1, SOC 2, and ISO 27001 reports for scope, exceptions, subservice organizations, and complementary user controls.

The outcome

A tiered portfolio, a register your auditor can follow, remediation with owners and dates, and decisions in days rather than quarters.

Compliance and audit readiness

  • SOC 2
  • ISO 27001
  • HIPAA
  • CJIS
  • GDPR
  • NIST CSF

I prepare organizations for assessment. Certification and compliance determinations rest with your auditor or regulator, and I do not guarantee either.

The problem

A framework arrives with a customer deadline, and the gap between written policy and daily practice surfaces during fieldwork.

The work

Readiness assessment, control mapping across overlapping requirements, policies that match what you actually do, evidence routines, and preparation for the people sitting in the interviews.

The outcome

A prioritized gap list, controls documented in language that survives scrutiny, and evidence assembled before the auditor asks.

Also within this practice

Due diligence and OSINT

  • Sanctions & watchlist screening
  • Adverse-media & litigation research
  • Ownership tracing
  • Public exposure review

The problem

A security questionnaire says nothing about who owns the company, where it operates, or what has been written about it.

The work

Sanctions and watchlist screening, adverse-media and litigation research, ownership tracing, and public exposure review — each finding recorded with its source and date.

The outcome

A sourced diligence memo that separates confirmed fact from unverified claim, suitable for attaching to a risk decision.

AI governance and operational resilience

A defensible position on AI adoption, and continuity and incident work that gets tested with the people who would actually be paged.

AI governance and AI vendor risk

  • AI vendor & feature assessment
  • Governance workflows
  • Human oversight & evidence requirements
  • Internal use guidance

The problem

AI features appear inside tools you already approved, and the standard questionnaire asks nothing about training data, model changes, or human oversight.

The work

Assessment criteria for AI vendors and features, intake that surfaces AI use before deployment, defined oversight points and evidence expectations, and internal use guidance.

The outcome

A defensible position on AI adoption: what is permitted, what needs review, who reviews it, and what record it leaves.

Resilience and incident readiness

  • Tabletop exercises
  • Business continuity planning
  • Disaster recovery planning

The problem

The plan has not been opened since the last audit, and the first real test finds the contact list and recovery order both out of date.

The work

Tabletop exercises written for your environment and vendors, facilitated with the people who would actually be paged, then continuity and recovery documentation built from what they expose.

The outcome

Plans tied to named roles and realistic recovery expectations, plus a record of the gaps found.

Also within this practice

Security awareness

  • Program support
  • Phishing simulation programs
  • Role-based training

The problem

Training that treats a nurse, a developer, and an accounts payable clerk as one audience teaches all three to ignore it.

The work

Role-based content built around the decisions each group faces, phishing simulations designed to teach rather than embarrass, and reporting that distinguishes a click from a report.

The outcome

Training people finish and remember, a reporting culture rather than a hiding one, and the completion evidence your framework requires.

Security workflow engineering

The integrations and internal tools that take the manual work out of GRC, and the routines that turn a flood of findings into a shrinking backlog.

Security software and workflow automation

  • Custom security & GRC tooling
  • GRC ↔ ticketing ↔ notification integrations
  • Structured intake
  • Scheduled follow-up on stalled items

The problem

Most GRC time goes to copying data between systems and chasing approvals. The platforms are licensed; nothing connects them.

The work

I write the integrations and internal tools myself: webhook pipelines between GRC, ticketing, and notification tools; intake forms that create structured records; scheduled follow-up on stalled items. Review steps and approval authority stay intact.

The outcome

Fewer manual handoffs, less status-chasing, and an audit trail that improves rather than degrades.

Also within this practice

Data and shadow IT governance

  • DLP remediation
  • DSPM remediation
  • Shadow IT identification
  • Governance routines

The problem

A DLP or DSPM rollout produces thousands of findings and no plan for who closes them — while departments keep buying tools on a credit card.

The work

Triage by sensitivity and exposure, tuning to cut false positives, discovery of unsanctioned tools, and a route that brings the useful ones into review.

The outcome

A shrinking backlog with a documented rationale, and a sanctioned path faster than going around you.

How an engagement moves

  1. 01Intake
  2. 02Risk tiering
  3. 03Evidence review
  4. 04Documented decision

Frameworks referenced as design and preparation references, never as certifications held: SOC 1 / SOC 2, ISO 27001, ISO/IEC 42001, HIPAA, CJIS, GDPR, NIST CSF, NIST AI RMF, and the NIST Generative AI Profile.

Start with the problem you have now.

Describe the deadline, the backlog, or the process that keeps breaking, and I’ll propose a scope that fits.

Discuss a project