Hire me
HR Hire the operator

Evidence, not opinions. Here is exactly what you get.

Everything a buyer needs to decide on one page: the deliverables, the full capability matrix, the seven operations, how an engagement runs, the terms, who this is for, and the questions procurement asks. No forms, no sales sequence. One email starts it.

01 What you get

Three things leave every engagement. Nothing else needs to.

Slide decks do not survive an auditor, a board question or a lawyer. These do.

Deliverable 01

Findings report

  • Every finding ranked by real risk, not scanner score
  • An owner and exactly one action attached to each
  • Written for the engineer and the board in the same document
  • Conditional grammar: what the system permits, never speculation
Deliverable 02

Evidence register

  • The artefact behind every claim: configs, logs, screenshots, requests
  • Hashed and time-stamped, chain of custody kept
  • Reproducible by your own team or by a regulator
  • Mapped to ISO 27001, NIST CSF 2.0, CIS v8, ATT&CK, RDI or BIO as agreed
Deliverable 03

Read-out and retest

  • One session, engineers and management together
  • Decisions recorded, not just findings presented
  • Retest of the fixes where in scope
  • Signed attestation of what was tested and what held
02 Capabilities · the full matrix

Three domains. Thirty-six disciplines.

Everything the operator has run in production, grouped by domain. Tools named where they matter. This is the bench behind the six operations below.

Cyber security

16

Compliance, risk and governance

Risk registers, policy, control mapping and audit evidence that is technically enforceable.

NIST CSF · ISO 27001 · CIS Controls · GDPR · RDI · BIO

Vulnerability management and exposure

CVSS analysis, risk-based prioritisation, remediation tracking, trend reporting across asset groups.

Tenable · Nessus · OpenVAS · Qualys

SIEM, log correlation and threat hunting

Detection engineering, hypothesis-driven hunts, ATT&CK-mapped use cases, enrichment pipelines, noise reduction.

Splunk · Sentinel (KQL) · Sumo Logic · Kibana / ELK · AlienVault

Incident detection, response and forensics

Triage to root cause, containment and eradication, memory and network forensics, timeline reconstruction.

Wireshark · Sysmon · ELK · Sentinel

Network security and segmentation

VPN, DMZ, VLAN, micro-segmentation and Zero Trust to stop lateral movement, legacy estates included.

Zero Trust · AS400 / IBM i

Next-gen firewalls and network controls

Policy design, application control, SSL inspection, threat feeds, firewall log correlation in the SIEM.

Palo Alto · FortiGate · Check Point · Cisco ASA

Secure protocols and cryptography in use

Certificate chains, cipher hardening, protocol misuse detection, key lifecycle.

TLS · IPsec · SSH · DNSSEC

Cloud security and hybrid estates

Architecture and operations, internal cloud audit frameworks for drift, privilege exposure and compliance deviation.

Azure · AWS · GCP · Sentinel · Intune · Entra · EPM

Identity and access management

RBAC, PAM, SSO, lifecycle automation, conditional access, least privilege and endpoint privilege management.

Entra / Azure AD · Okta · Active Directory

Endpoint security and XDR

Hardening, telemetry analysis, detection tuning, device control, endpoint-to-identity correlation.

Cortex XDR · Defender for Endpoint · CrowdStrike

Web application and API security

OWASP Top 10, API audit frameworks for exposure, authentication models, authorisation logic, validation, logging.

OAuth2 · OIDC · Burp Suite

Penetration testing and offensive security

Logic flaws, access-control weaknesses, identity abuse and misconfigurations over tool-only exploitation.

Kali · Burp · Nmap · Metasploit

Security awareness and insider risk

Awareness programmes, phishing simulations, insider-risk controls tied to HR and compliance processes.

Programmes · simulations

Tooling, automation and infrastructure as code

SIEM tuning, IR workflows and reporting automated; IaC security; monitoring and analysis pipelines.

PowerShell · Python · Node.js · Terraform · Azure Automation

Asset inventory and compute visibility

Unified view across servers, VMs and endpoints by correlating scanner, MDM, directory and SIEM data.

Tenable · Intune · AD · SIEM

Backup, recovery and platform hardening

Ransomware recovery validation with forensic checks, DR optimisation, baselines for Windows, hybrid and legacy platforms.

Rubrik · Veeam · Barracuda · VMware · Hyper-V · Intune / Jamf

Blockchain security and engineering

07

Smart-contract engineering and security

Checks-effects-interactions, reentrancy prevention, upgradeability patterns, safe token handling.

Solidity · EVM

Oracle and pricing integration

Freshness checks, fallback logic, manipulation-resistant price paths.

Oracles · TWAP

Staking, rewards and tiering logic

Abuse-resistant reward and tier designs.

Tokenomics

Governance architecture

Modular execution, role-gated calls, on-chain auditability.

Roles · timelocks

DeFi threat modelling

Flash-loan abuse, oracle manipulation, front-running and MEV exposure, mapped before deployment.

Threat models

Audit workflows

Static analysis, symbolic execution, fuzzing, false-positive triage, risk documentation.

Slither · Mythril · fuzzers

AI-assisted contract analysis

Security-first research with AI-assisted review pipelines, automated Slither runs.

Slither automation · Node.js

AI and machine learning for security

13

AI red teaming of LLM systems

Prompt injection, agentic attack chains, adversarial misuse of LLM-powered workflows; formal red-team AI training in progress.

OWASP LLM Top 10 · OSAI+ (in progress)

AI safety, governance and auditability

Per-user and per-model rate limits, full audit logging of AI interactions, input validation, role-based module access.

Governance · explainability

AI-assisted SOC operations

Log correlation, anomaly detection and detection enrichment with models in the loop.

Copilots · enrichment

Agentic AI and ReAct architecture

Autonomous agents with planning, tool invocation and self-correction, executed in isolated sandboxes per session.

ReAct · Docker sandboxes

Model orchestration

Multi-provider routing behind one API with fallback chains, reasoning-effort controls and routing telemetry.

OpenAI · Anthropic · open models

Local AI infrastructure

CPU and GPU inference stacks, LoRA and QLoRA fine-tuning, dataset curation.

Local inference · fine-tuning

Full-stack AI platform delivery

Production AI platform shipped end to end: backend, frontend, streaming, cost tracking, tiered access, JWT, TOTP/2FA.

Python · Flask · React · TypeScript

AI-driven threat intelligence

IOC correlation across sources, attack-chain reconstruction, automatic ATT&CK classification, YARA rule generation.

IOC engine · YARA · ATT&CK

Forensic evidence processing with AI

Multi-format ingestion (email, captured traffic, documents, audio, video), severity triage, chain-of-custody tracking.

Evidence pipeline

Network traffic and HAR forensics

Reconstruction of platform behaviour and session anomalies from captured HTTP sessions as auditable artefacts.

HAR · session analysis

Audio intelligence and transcription

Speech-to-text pipelines inside forensic workflows for structured dossier construction.

Whisper-compatible

Forensic prompt engineering

System prompts that separate facts, evidence and assumptions, with confidence labels per conclusion, for defensible output.

Auditable AI output

Security automation deliverables

Autonomous red-team simulations, analyst copilots, security playbook generators.

Automation
Almost two decades in productionCEH v12EXIN BlockchainAZ-900OSAI+ in progressITIL · MCSA seriesHBO IT
03 Operations · what you can book

Seven operations. Fixed scope, fixed price.

Six map to a layer of the chain: surface, deep or dark. The seventh is for when the chain is used against you. Price is set in the proposal after the scoping call, so the total is known before you commit.

OP 01Surface · audit

Security Audit and Evidence File

Control design and operating effectiveness against ISO 27001, NIST CSF 2.0, CIS v8, RDI or BIO. Output is the evidence file a regulator, a customer audit or a NIS2 supervisor asks for.

Typical duration
3–6 weeks
You receive
Audit report + evidence register + read-out
Done when the file stands on its own without the auditor in the room
OP 02Surface · exposure

Vulnerability Program Reset

Scanner output becomes a ranked remediation program with owners, deadlines and a trend line. Credentialed scan policies, asset grouping, reporting cycle.

Typical duration
2–4 weeks + cycles
You receive
Ranked register + reporting template + first cycle
Done when exposure is measurably lower after the second cycle
OP 03Deep · identity

Identity and Access Ledger

Every account, service identity, shared secret and vendor path listed with an owner, a last-use date and a decision. Legacy platforms included.

Typical duration
10 working days
You receive
Ledger + removal plan + before/after counts
Done when no account exists without a named owner
OP 04Deep · detection

Detection Engineering and Threat Hunt

Detections mapped to ATT&CK and the tradecraft targeting your sector, tuned in your SIEM, validated by hunts that either find something or prove coverage.

Typical duration
4–8 weeks
You receive
Rule set + coverage matrix + hunt reports
Done when coverage is visible on one page and noise is down
OP 05Deep · response

Incident Response and Recovery Validation

Triage to root cause, timeline from the logs that exist, and a tested proof that backups restore what you think they restore.

Typical duration
On call · 1–3 weeks
You receive
Timeline + recovery attestation + board memo
Done when a recovery has been timed and signed, not assumed
OP 06Dark · offensive

Offensive Assessment, AI Red Team, Smart Contracts

Authorised testing of web, API, cloud and pipelines, LLM workflows and agents, or smart contracts. Every finding reproduced and retested.

Typical duration
2–4 weeks + retest
You receive
Findings report + retest letter
Done when every finding is fixed or formally accepted
OP 07Dispute · evidence

Litigation-Grade Evidence and Dispute Support

When the other side is bigger, better funded and controls the systems, the operator builds the technical case that outlives their story: acquisition with chain of custody, timelines from logs, captures and mail records, the gaps named as findings, a dossier written to be filed, and a technical expert next to your counsel.

Typical duration
Weeks to months · retainer
You receive
Filed-ready dossier + exhibits + expert statement
Done when the file stands in the room without the operator in it
04 How it runs

Five steps. No surprises.

01
Day 0 · 30 min

Scoping call

Your context, the systems in play, the question you need answered.

02
Within 2 business days

Fixed-price proposal

Scope, method, deliverables, price and date on one page.

03
Fieldwork

Evidence gathering

Walkthroughs, configuration reviews, log sampling, testing.

04
Read-out

Findings that carry weight

Ranked, owned, actionable. Engineers and board together.

05
Included

Retest and attestation

Fixes verified, file closed with a signed statement.

05 Terms of working

Plain terms. Written down before day one.

Confidentiality

NDA before scoping

Your NDA or the standard one, signed before any system name is spoken. Names are withheld in every public reference, always.

Data handling

EU-side, encrypted, deleted

Evidence lives on EU-hosted encrypted storage for the engagement and is deleted after hand-over. Deletion is confirmed in writing.

Capacity

One operator, limited slots

No subcontracting and no parallel overload. If a slot is not available, you hear it on the scoping call, with a date.

Authorisation

Written scope, nothing outside it

Every offensive step is authorised in writing with named systems and time windows. No destructive testing, no social engineering unless explicitly scoped.

Response

Reply within one business day

Email is answered within one business day, incidents faster when a retainer is in place.

Procurement

Supplier paperwork on request

Questionnaires, insurance and identity documents, data-processing agreement, chain-of-custody statement. KvK 84616458.

06 Fit

Who this is for. And who it is not.

A good fit
  • Organisations in regulated or supervised sectors: telecom, government, finance, healthcare, manufacturing
  • Teams facing an audit, a customer questionnaire, a NIS2 duty or a board question with a deadline
  • Environments with legacy and cloud side by side, identities nobody owns, vendors nobody mapped
  • Product teams shipping AI agents or smart contracts who want them tested before launch
  • Organisations, reporting persons and lawyers in a dispute with a party that is bigger and controls the systems
  • Buyers who want the person on the call to do the work
Not a fit
  • A compliance stamp without fixing anything
  • A 200-person managed SOC or 24/7 staffing
  • Testing systems you do not own or are not authorised to assess
  • Slide decks, awareness posters or generic policy packs
  • Anything that needs a team next week, rather than one operator with a plan
07 Questions procurement asks

Answered once, in writing.

How fast can we start?

Scoping call within days of your email. Written proposal within two business days of the call. Fieldwork usually starts within two to three weeks, depending on the scope and your team's availability for access and interviews.

Who actually does the work?

One senior operator, end to end. No juniors, no subcontractors, no hand-off to a delivery team. The person on the scoping call writes the report and answers for it afterwards.

How is pricing decided?

Fixed price per engagement, set in the proposal after the scoping call, so you know the total before you commit. Anything outside an agreed scope is quoted separately, never billed by surprise.

What do we receive at the end?

A findings report ranked by risk with an owner and one action per finding, the evidence register behind every claim, a read-out session for engineers and management together, and a retest with a written attestation where it is part of the scope.

Is the testing safe for production?

Every offensive step is authorised in writing, scoped to named systems and time windows, and rate-limited. Nothing destructive, nothing outside the scope form. Findings are demonstrated, not exploited beyond proof.

How do you handle our data?

An NDA is signed before scoping, yours or the standard one. Evidence is stored on EU-side, encrypted systems for the duration of the engagement and deleted after hand-over, with the deletion confirmed in writing.

Which frameworks do you audit against?

ISO 27001, NIST CSF 2.0, CIS Controls v8, MITRE ATT&CK for detection coverage, the RDI telecom security framework, and the Dutch government BIO baseline. NIS2 and the Cyberbeveiligingswet duties are mapped in every audit deliverable.

Can you act as the technical expert in a dispute against a large organisation?

Yes. That is Operation 07. The operator has built technical cases with counsel against parties many times larger than the client, from their own logs, captures and mail records, with chain of custody kept. The evidence, not the size of the opponent, decides. Reporting persons under the Dutch whistleblower law are supported with the same method.

Can you work under our procurement rules?

Yes. Supplier questionnaires, insurance and identity documents, a chain-of-custody statement for evidence and a data-processing agreement are provided on request. KvK 84616458.

08 Start

One email starts it.

Thirty minutes to scope it. A fixed-price proposal within two business days. Reply within one business day.