Back to home

Portfolio

Proof, not promises.

A selection of engagements across fintech, healthcare, AI SaaS, logistics, retail and energy — each one anonymised where required, and each one measured by what actually changed for the defenders.

140+

Engagements delivered

9

Regulated sectors

24m

Median containment

100%

Retest pass rate

Selected work

Engagements in the field

2025

Fintech

Nordbank Digital

Offensive Security

Challenge — A challenger bank needed proof that its payment rails could survive a determined, funded adversary before a regulator audit.

Approach — Six-week red team: phishing-led initial access, lateral movement through CI/CD, and an attempted payment-rail pivot with full purple-team replay.

Outcome — Three critical attack chains closed pre-audit; detection coverage on the payment domain moved from 41% to 93%.

3

Critical chains closed

93%

Detection coverage

6wk

Engagement

Red TeamCI/CDPurple Team
2025

Healthcare

Meridian Health Group

Security Operations

Challenge — 14 hospitals, no night coverage, and an alert backlog measured in weeks across a fragmented EDR estate.

Approach — Stood up managed SOC monitoring with tuned detections per clinical system, automated triage playbooks, and a 24/7 analyst rota.

Outcome — Median containment fell from 19 hours to 24 minutes with zero patient-facing downtime during rollout.

24m

Median containment

-88%

Alert noise

24/7

Coverage

Managed SOCMDRDetection Engineering
2026

AI SaaS

Vectorly

Threat Intelligence & AI

Challenge — A 40-engineer platform team was drowning in 12,000 open scanner findings with no way to rank real risk.

Approach — Deployed AI-driven vulnerability triage wired into their repos and runtime telemetry, with exploitability scoring and auto-generated fix PRs.

Outcome — Backlog cut by 91% in eight weeks; every remaining item is reachable, exploitable and owned.

-91%

Backlog

8wk

To steady state

1.4k

Auto fix PRs

AI TriageAppSecAutomation
2025

Logistics

Portway Logistics

Governance, Risk & Compliance

Challenge — Enterprise deals were stalling in procurement because there was no SOC 2 report and no owner for security.

Approach — Fractional vCISO built the control set, evidence automation and vendor risk process, then ran the Type II observation window.

Outcome — SOC 2 Type II achieved in five months with zero exceptions, unblocking a seven-figure pipeline.

5mo

To Type II

0

Exceptions

$7M

Pipeline unblocked

vCISOSOC 2Vendor Risk
2026

Retail

Larkspur Retail

Training & Awareness

Challenge — Seasonal staff turnover kept phishing click rates above 30% across 6,000 store employees.

Approach — Continuous simulation campaigns tailored per role, five-minute micro-lessons, and manager-level reporting per store.

Outcome — Click rate down to 3.1% and report rate up 6x within two quarters.

3.1%

Click rate

6x

Report rate

6k

Staff trained

Phishing SimsAwarenessMetrics
2026

Energy

Helion Grid

Offensive Security

Challenge — A multi-account cloud migration for grid telemetry had no assurance that the blast radius was contained.

Approach — Cloud security assessment across identity, network and data planes, plus an assumed-breach exercise from a compromised workload.

Outcome — Cross-account escalation path eliminated and least-privilege baselines codified as policy-as-code.

0

Escalation paths left

118

Findings remediated

IaC

Guardrails shipped

CloudAssumed BreachIAM

Your engagement could be the next one here.

Tell us what keeps you up at night and we'll scope the shortest path from exposure to evidence.