Skip to main content
CISSP-ISSAP · 20+ Years · #10 OnCon Icon, 2022
Services

I get AI into production without opening a new risk class. I stay on as the fractional CISO.

Same 30-minute call either way. We pick the engagement after I hear the deadline. You do not need to shop a catalog first.

Featured

Secure AI Deployment

Roll out AI inside the business with controls

Traditional security frameworks do not cover model access, shadow tools, or vendor AI. I help you put AI into production with inventory, access controls, vendor checks, and board evidence. Starting at $15,000.

  • AI inventory of shadow tools and vendors
  • Access and model controls
  • Vendor AI due diligence
  • Board-ready evidence pack
View Secure AI Deployment

Fractional CISO

Enterprise security leadership at SMB scale

Get experienced security leadership without the full-time executive salary. I become an extension of your team, providing strategic guidance, board reporting, and hands-on security program development.

  • Security strategy and roadmap development
  • Board and executive security reporting
  • Risk assessment and management
  • Compliance program oversight
View Fractional CISO

Security Architecture

Design security that scales

Whether you're building from the ground up or modernizing legacy systems, I design security architectures aligned with Zero Trust principles that balance protection with operational efficiency.

  • Zero Trust architecture design
  • Cloud security architecture
  • Identity and access management strategy
  • Security tooling rationalization
View Security Architecture

Board Advisory

Translate security for decision-makers

Boards need to understand cyber risk to fulfill their fiduciary duties. I help with clear, business-focused risk communication and governance guidance.

  • Board presentation development
  • Cyber risk quantification
  • Security metrics and KPIs
  • M&A security due diligence
View Board Advisory

Compliance & Certification

Turn audits into a sales advantage

SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, and ISO 42001 programs built for your stage and timeline. Certification becomes a closer, not a stall.

  • SOC 2 Type I and II readiness
  • ISO 27001 implementation
  • HIPAA, PCI DSS, and CMMC roadmaps
  • Evidence collection and auditor coordination
View Compliance & Certification
Engagement Models

Flexible Ways to Work Together

I offer engagement models designed to match how you work - whether you need ongoing support or focused project delivery.

Monthly Retainer

Ongoing partnership

Ideal for organizations needing consistent security leadership. Includes a set number of hours per month, regular check-ins, and priority access for urgent matters.

Best for: Growing companies needing fractional CISO services

Project-Based

Defined scope and timeline

Perfect for specific initiatives like security architecture design, compliance readiness, or AI governance program development. Clear deliverables with fixed pricing.

Best for: Discrete projects with defined outcomes

Advisory / Board

Strategic guidance

Quarterly or ad-hoc advisory engagement for boards, executives, or security leaders who need experienced perspective on strategic decisions and risk governance.

Best for: Boards and executives seeking expert guidance

Next step

See if I should be in the room

Thirty minutes is enough to see whether you need a fractional CISO, a secure AI rollout, or a lighter first step. No obligation.