What I do.
Independent cyber security consulting across architecture, cryptography and offensive testing — each engagement anchored in the real risk to your system, delivered with clear, prioritized, and auditable results.
Security Architecture Reviews
A structured assessment of existing or planned systems for design-level weaknesses, before they become costly in production.
- Threat modeling & trust boundaries
- Design & data-flow analysis
- Prioritized remediation roadmap
Cryptographic Implementation
Correct, auditable implementation of cryptographic methods — from key management to protocol design and review.
- Key management & lifecycle
- Protocol design & validation
- Implementation review
Penetration Test Campaigns
Controlled attack simulation against your systems, with a clear, prioritized catalog of findings and fixes.
- OWASP Top 10 testing
- Vulnerability scans
- Exploitation & reporting
Secure Code Reviews
Manual and tool-assisted review of source code to surface vulnerabilities and insecure patterns early.
- Manual code audit
- Insecure-pattern detection
- Developer-facing guidance
Risk Assessments & ISO 27001
Information security risk assessments aligned with recognized standards, supporting ISO 27001 objectives.
- Asset & risk identification
- Control gap analysis
- Treatment recommendations
Incident Response & Hardening
Incident response planning plus Unix/Linux hardening, and general cyber security consulting where you need it.
- Incident response plans
- Unix / Linux hardening
- General security consulting
How an engagement runs
A transparent process in four steps — from first conversation to verified result.
Analysis
Assessing your system, threat landscape and relevant protection goals.
Evaluation
Review, code analysis or active penetration testing.
Implementation
Prioritized recommendations, with hands-on support on request.
Verification
Re-testing to confirm the identified risks have been closed.