Impact
Five case studies
A resume bullet tells you what happened. It does not tell you what the situation actually was, what the alternatives were, or why the decision was defensible. These do.
Turning vulnerability counts into $46M of risk removed
Remediation was being prioritized by CVSS severity, which meant the loudest findings won and the most consequential ones waited. Re-sequencing around business impact removed roughly $46M of quantified annual exposure without adding headcount.
Read the case studyAn IPO-ready security program, one year early
A public offering sets a hard date and invites three sets of outside reviewers with different standards of proof. The program had to satisfy auditors, cyber-insurance underwriters, and regulators — and it did, twelve months ahead of the deadline.
Read the case studyCutting security spend 27% without cutting coverage
Most security portfolios are an archaeology of past incidents and past leaders. Mapping tools to controls rather than to budget lines showed where the overlap was, and returned 27% of annual spend.
Read the case studyA 24x7 SOC that didn’t hollow out the team
Outsourcing monitoring is easy and usually costs you your detection capability within two years. The design constraint was round-the-clock coverage that made the in-house team stronger rather than redundant.
Read the case studyStanding up security for a $6.5B retailer from zero
No prior enterprise security function, 40,000 employees, card-present and e-commerce payment environments, millions of transactions, and a PCI DSS obligation with an audit date attached.
Read the case studyThe principles underneath all five
These case studies look like five different problems. They were solved with the same six or seven positions, which are worth stating plainly.
Read the approachA note on numbers
Where these figures come from
The financial figures on this site are the outputs of quantified risk models and budget analysis I built and presented internally — the same numbers that went to the Executive Cybersecurity Committee, external auditors, and cyber-insurance underwriters. They are stated as approximations because that is what they are: modelled annualized loss expectancy, not accounting fact.
I am happy to walk through the methodology in an interview. That conversation is usually more informative than the number.