Find the gaps. Close them for good.
Most small businesses don't need a security executive, and they don't need another binder of recommendations. They need the gaps found and closed before a phishing email or a reused password turns into a very expensive week. I find where you're actually exposed and I fix it: controls put in place and proven working, the routine parts automated, and your people trained on the rest.
Practical security, built and implemented
I work across the whole security stack: assessing where you stand, implementing the controls that matter, and making them stick with automation, guides, and training. Vendor-neutral, and focused on outcomes you can see, not a binder that sits on a shelf.
Assessments & gap analysis
A clear-eyed review of where you actually stand against NIST CSF and CIS Controls. I surface the real gaps, rank them by risk, and give you a prioritized, budget-aware plan to close them, written in plain English you can hand to your insurer, your bank, or your biggest customer.
Control implementation & automation
The part most consultants leave to you. I stand up and configure the controls that matter, from MFA and logging to backups and endpoint and email defenses, automated wherever it can be so protection runs without adding to your team's workload.
Security architecture reviews
Building something in-house or weighing a third-party solution? I review or design the architecture with you, vendor-neutral, so you invest in what fits and integrate it securely instead of bolting on risk.
Identity & access management
Who can reach what, and how it's protected. Single sign-on, multi-factor, least-privilege access, and clean joiner, mover, and leaver processes so the right people get in and no one else does.
Vulnerability & application security
I set up scanning that finds the weak points in your systems before attackers do. If your team builds software, I add automated checks that review your code for security flaws before they ship (the industry calls this SAST). Either way, you get a short list of what matters, in order, and help fixing it.
Policies, governance & vendor risk
Practical policies people actually follow, sensible governance sized to your business, and a real handle on the vendors and third parties who touch your data.
Systems like these, already built
Client names stay confidential, but the work is real. Two examples of security systems Michael designed and shipped inside global financial institutions, the same disciplines this page offers you.
Segregation-of-duties scanner for a large organization
Every employee transfer was automatically screened for high-risk access combinations, like an operations employee moving to a trading desk, or a technology worker with elevated system access moving into operations, so permissions were reviewed before they became a finding.
Enterprise Salesforce integration security review
A full integration risk review for one of the world's largest financial enterprises: API endpoints, data classification, entitlements, revocation, encryption, and architecture, working directly with the vendor until every risk was documented and formally dispositioned.
Engagements that fit the problem
The assessment is the right starting point for almost every business: it tells you exactly what you need before you spend anything on fixes. Implementation and advisory build on what it finds. And when an engagement calls for extra capacity, I draw on a trusted network of local cybersecurity professionals, while staying accountable for every deliverable myself.
Assessment & roadmap
Defined scope, defined outcome
- Security posture assessment
- Gap analysis vs NIST CSF & CIS Controls
- Prioritized, budget-aware roadmap
- Clear findings in plain English
- Zero disruption: I look, I don't touch, until you approve the plan
Hands-on implementation
I do the work, not just the write-up
- Everything in Assessment
- Stand up and configure the controls
- Identity & access management
- Scanning for weak points, in your systems and your code
- Automation, guides, and team training
Ongoing advisory
A security expert on call
- On-call guidance for security decisions
- Architecture and vendor reviews
- Periodic posture check-ins
- Cyber-insurance application support
Not sure which engagement fits? Ask in a free consultation.
Inspect our armor
This very page ships hardened. The panel below fetches this page's own response headers in your browser, right now, and translates them. Nothing is hardcoded: if a header stopped shipping, its row would vanish.
Or ask a referee we don't control:
Every link points their scanner at this site. We don't get to edit the result.
Not sure where your security actually stands?
Start with an assessment. In a couple of weeks you'll have a clear picture of where you're exposed, what to fix first, and a plan to close the gaps. No jargon, no scare tactics. And if a cyber insurance renewal or a customer security questionnaire sent you here, bring it: those forms are exactly what an assessment is built to answer.
Prefer to talk to a person first? Call us