Practice areas

Six areas of work.
One defensible outcome.

Engagements are scoped from a conversation, not a catalogue. Most combine two or three of these, because the problems do.

01  ·  AI Risk Management

Know what you are running before someone else tells you.

The first job is always inventory. Which systems use AI, whose data they touch, what decisions they influence, and which of them a customer or regulator would call high risk. Very few have that full list when we start, and the ones who think they do are usually missing some vendor-embedded features.

From there it is risk and impact assessment against a real methodology, not a spreadsheet of adjectives. We use ISO/IEC 42001 as the spine and cross-map to the EU AI Act and NIST AI RMF, so one body of evidence answers several audiences.

  • AI system inventory and classification, including shadow and vendor-embedded AI
  • AI risk and impact assessment methodology your team can run without me
  • Model, agent, and RAG-pipeline threat modeling and risk review: data leakage, prompt injection, tool access, autonomy limits
  • Third-party AI due diligence and contract language that survives vendor pushback and makes sure you know exactly what party is on the hook for which risks.

02  ·  ISO/IEC 42001 Leadership

An AI management system your auditor recognizes and your engineers will actually use.

42001 is the first certifiable standard for managing AI, and it is becoming the shorthand answer to the question your customers keep asking. As a certified Lead Implementer, we run the build the way we build high performing security programs: with the people who have to live inside it.

If your organization already holds ISO 9001 or 27001, a good chunk of the machinery is reusable and the timeline shortens.

01

Readiness Assessment

Scored gap analysis against all of Annex A, AI system inventory and risk register, draft Statement of Applicability, and a roadmap you can take to a budget conversation.

Fixed fee or retainer-based, scoped up front
3–6 weeks
02

Implementation

Policy and scope, risk and impact methodology, Annex A control build-out, control-owner enablement, internal audit, and management review. I stay through the certification audit.

Fixed fee or retainer-based, scoped up front
3–9 months
03

Managed AIMS Retainer

Quarterly reviews, annual internal audit and management review, surveillance-audit prep, and new AI systems brought into scope as they ship.

Fixed fee or retainer-based, scoped up front
12-month term

03  ·  Cybersecurity

The core practice, now with a much larger attack surface.

Twenty-five years of this, most of it accountable for the outcome rather than advising on it. Program assessment, architecture review, and the unglamorous work of deciding what to fix first when everything is on fire.

The newer part is what agentic systems did to the perimeter. An agent with tool access and a credential may be useful, or may pose what we call a Lethal Trifecta of risk. APIs are how it reaches everything else, and our background in API Security comes in very handy in tracing this all out.

  • Security program assessment against NIST CSF, ISO 27001, or your regulator's expectations
  • API and application security: discovery, posture, and the runtime story
  • Agentic AI security: identity, tool permissions, blast radius, human-in-the-loop design
  • Post-quantum readiness and crypto inventory for organizations with long-lived data

04  ·  vCISO / CAISO / CIO

Executive leadership on a fraction of a headcount.

Some companies need the seat filled between hires. Some have a capable team that needs somebody who has already made the expensive mistakes. Either way you get a practitioner in the chair, not a junior consultant with a template and a partner who shows up for the QBR.

The Chief AI Security Officer version of this is new and increasingly what gets asked for: one person to wrap their head around AI risk across security, legal, data, and the product teams shipping the models.

  • Fractional CISO: strategy, budget, board reporting, incident readiness, team development
  • Fractional CAISO: AI risk management and governance across the functions that each own a piece of it
  • Fractional CIO: technology strategy, vendor portfolio, and delivery accountability
  • Interim coverage during a search, plus help hiring the permanent person

05  ·  Technology Governance

Who decides, who pays, and who is accountable when it does not work.

Most governance failures I see are not control failures. They are decision-rights failures: three groups each believed another one owned the call, and the AI vendor got signed by whoever had a corporate card.

This work sets the operating model. Which decisions go to a committee and which do not, what a business case has to contain before it gets funded, and how the technology portfolio gets reviewed so that spend and risk are visible in the same conversation.

  • Decision rights and governance-forum design that does not add a committee
  • AI and technology intake: how a new tool or model gets approved, and how fast
  • Policy architecture: acceptable use, data handling, model lifecycle, vendor standards
  • Portfolio and spend review tied to risk, not just to renewal dates

06  ·  Board Advisory

Independent counsel for the people signing the disclosure.

Boards are being asked to oversee AI risk with materials written by the people whose programs they are overseeing. I sit on the other side of that: an independent read, in language a director can act on, with no product to sell you afterward.

I am an NACD certified director and I have presented to boards and audit committees for twenty years, including the meetings that followed an incident. I know what the questions sound like and what an honest answer costs.

  • Board and audit committee education on cyber and AI risk oversight
  • Independent review of management's security or AI reporting before it is presented
  • Technical due diligence for PE and VC on portfolio and target companies
  • Keynotes and panels: API security, agentic AI, post-quantum, geopolitical cyber risk

Not sure which of these you need?

That is a normal place to start. Describe the situation and I will tell you what the work actually is, including when it is smaller than you feared.

Book a 30-Minute Consult