Co-founder · Operations · Research

Decide what to change. Protect what cannot fail.

Co-founder of ITRES and SG6. More than twenty years connecting business, infrastructure and cybersecurity so technology decisions hold up in real-world operations.

20+years across operations, resilience and cybersecurity
ITRES · SG6co-founder and builder of technology services
25+ public CVEscredited by multiple CNAs throughout my research career
ISO · NISTISO 27001 auditor and trained in the NIST CSF

01 / Approach

Business / Infrastructure / Risk

How I work

Problem first. Architecture second.

I work where continuity, performance, cost, vendors, risk and team capacity tend to collide.

I do not start from a particular tool. I start from how the organisation operates, what it depends on and how long it can afford to be down. Architecture comes next.

From decision to operations

  1. 01Discovery

    Inventory, dependencies, incidents and single points of failure.

  2. 02Priority

    Impact, urgency, cost and the actual capacity to execute.

  3. 03Operations

    Owners, controls, dates and recovery conditions.

Connected domains

CybersecuritySystemsData centreInnovation

A practical rule

Operate.
Measure.
Recover.

A solution is not finished when it is purchased. It is finished when the team knows how to run it, can measure its state and has tested recovery.

03 / Track record

Security / Operations / Research

What I have built

Experience shapes judgement.

Three projects connected by one idea: carry risk all the way into operations, then feed what is learned back into practice.

Public conversations

Research, challenge, share.

Judgement also develops by exposing it to scrutiny: at technology forums, conferences, in the media, and in conversations with business, universities and government.

04 / Contact

Decisions / Research / Conversation

Contact

When the problem combines technology, risk and operations, the first step is to define its boundaries.

Technology decisionsResearch and disclosureSpeaking and media