Impact

Five case studies

A resume bullet tells you what happened. It does not tell you what the situation actually was, what the alternatives were, or why the decision was defensible. These do.

Global Food Manufacturer · Risk

Turning vulnerability counts into $46M of risk removed

Remediation was being prioritized by CVSS severity, which meant the loudest findings won and the most consequential ones waited. Re-sequencing around business impact removed roughly $46M of quantified annual exposure without adding headcount.

Read the case study
Global Food Manufacturer · Governance

An IPO-ready security program, one year early

A public offering sets a hard date and invites three sets of outside reviewers with different standards of proof. The program had to satisfy auditors, cyber-insurance underwriters, and regulators — and it did, twelve months ahead of the deadline.

Read the case study
Global Food Manufacturer · Portfolio

Cutting security spend 27% without cutting coverage

Most security portfolios are an archaeology of past incidents and past leaders. Mapping tools to controls rather than to budget lines showed where the overlap was, and returned 27% of annual spend.

Read the case study
Global Healthcare Organization · Operations

A 24x7 SOC that didn’t hollow out the team

Outsourcing monitoring is easy and usually costs you your detection capability within two years. The design constraint was round-the-clock coverage that made the in-house team stronger rather than redundant.

Read the case study
Sporting Goods Retailer · Build

Standing up security for a $6.5B retailer from zero

No prior enterprise security function, 40,000 employees, card-present and e-commerce payment environments, millions of transactions, and a PCI DSS obligation with an audit date attached.

Read the case study
Operating philosophy

The principles underneath all five

These case studies look like five different problems. They were solved with the same six or seven positions, which are worth stating plainly.

Read the approach

A note on numbers

Where these figures come from

The financial figures on this site are the outputs of quantified risk models and budget analysis I built and presented internally — the same numbers that went to the Executive Cybersecurity Committee, external auditors, and cyber-insurance underwriters. They are stated as approximations because that is what they are: modelled annualized loss expectancy, not accounting fact.

I am happy to walk through the methodology in an interview. That conversation is usually more informative than the number.