Independent Consultant | Cybersecurity Architect & vCISO

Currently fully booked. New engagements onboard from early 2027.Join the 2027 waitlist

Blog

Articles

Technical deep-dives and strategic guidance, written for people who actually make security decisions.
The EU AI Act for Small Companies: What You Actually Have to Do
2026-06-26 EU AI Act

The EU AI Act for Small Companies: What You Actually Have to Do

A plain-English starter on the EU AI Act for SMEs. If your small company uses AI tools rather than builds them, here is what actually applies to you - and what you can stop worrying about.

2026-06-25 Penetration Testing

How to Scope a REST API Penetration Test (and Pay Less for a Better One)

A founder's guide to what your API pentest actually needs from you. Bring two documents and the test gets cheaper, faster, and more useful. Skip them and you pay for guesswork.

What Security Actually Is: A Guide for People Who Never Wanted to Learn It (Part 1)
2026-06-12 Security Basics

What Security Actually Is: A Guide for People Who Never Wanted to Learn It (Part 1)

Information security, cyber security, the CIA triad, CIS Controls and why security people talk like generals - explained for business owners with no IT background.

Your Enterprise Customer Will Not Wait Until Your Security Is Ready
Featured
2026-05-12 SME Security

Your Enterprise Customer Will Not Wait Until Your Security Is Ready

Enterprise customers ask small software vendors for security evidence long before the company has a full security team. A retained security advisor helps close that gap steadily.

Insider Risk for SMEs: You Don’t Have to Be Hacked to Lose Data
Featured
2026-05-12 Insider Risk

Insider Risk for SMEs: You Don’t Have to Be Hacked to Lose Data

Employees, contractors, suppliers, and former staff can expose company data by mistake or misuse. Learn how SMEs can reduce insider risk with better access controls.

Leaving Microsoft 365 for Proton: A Practical Sovereign Stack Test
2026-02-04 Digital Sovereignty

Leaving Microsoft 365 for Proton: A Practical Sovereign Stack Test

Why I am testing Proton as a more sovereign European workspace: what improves, what may hurt, and how SMEs should approach migrations.

Shadow AI: The Risk Is Secrecy, Not AI Itself
2026-01-27 AI Ethics

Shadow AI: The Risk Is Secrecy, Not AI Itself

Employees use AI because it helps them work faster. The security risk starts when policies are unclear and usage goes underground.