I am open to a small number of light-touch advisory relationships with growing SaaS and technology businesses.
My focus is helping founders, executives and boards understand which security, resilience and trust issues matter now, which can wait, and what should be addressed before enterprise customers, auditors, investors or acquirers begin asking difficult questions.
Who I can help
- Founder-led SaaS companies moving into enterprise sales
- Businesses approaching formal assurance or regulatory expectations
- Leadership teams building or reshaping their first security function
- Companies preparing for investment or acquisition diligence
- Boards seeking pragmatic security and resilience challenge
- First-time Heads of Security or CISOs needing an experienced sounding board
Typical advisory questions
- Will our current security position survive enterprise due diligence?
- Are we spending on the risks that actually matter?
- What should the board expect from a security function at our stage?
- Is our customer-assurance approach enabling sales or consuming it?
- Are our resilience and data-lifecycle controls real or merely documented?
- What will an investor or acquirer find?
- Do we need another tool, another hire or clearer ownership?
- What should management do now, and what can reasonably wait?
- Is the security programme proportionate to our commercial maturity?
- Where are we relying on paperwork instead of operating controls?
How an engagement might work
Engagements might involve a monthly founder or executive discussion, periodic challenge of a security roadmap or board risk pack, support to a security leader, or a focused review ahead of enterprise or transaction scrutiny.
I am not looking to provide outsourced operational security delivery. My value is in judgement, prioritisation, challenge and practical direction.
Areas of focus
- SaaS security strategy
- Board-level risk and governance
- Customer assurance and trust
- Resilience and business continuity
- Compliance strategy
- Data lifecycle and deletion risk
- Incident and vulnerability leadership
- Due-diligence readiness
- Security operating models
- Commercially proportionate security decisions
Start a conversation
For a confidential introductory conversation, connect with me on LinkedIn.