Portfolio
Proof, not promises.
A selection of engagements across fintech, healthcare, AI SaaS, logistics, retail and energy — each one anonymised where required, and each one measured by what actually changed for the defenders.
140+
Engagements delivered
9
Regulated sectors
24m
Median containment
100%
Retest pass rate
Selected work
Engagements in the field
Fintech
Nordbank Digital
Offensive Security
Challenge — A challenger bank needed proof that its payment rails could survive a determined, funded adversary before a regulator audit.
Approach — Six-week red team: phishing-led initial access, lateral movement through CI/CD, and an attempted payment-rail pivot with full purple-team replay.
Outcome — Three critical attack chains closed pre-audit; detection coverage on the payment domain moved from 41% to 93%.
3
Critical chains closed
93%
Detection coverage
6wk
Engagement
Healthcare
Meridian Health Group
Security Operations
Challenge — 14 hospitals, no night coverage, and an alert backlog measured in weeks across a fragmented EDR estate.
Approach — Stood up managed SOC monitoring with tuned detections per clinical system, automated triage playbooks, and a 24/7 analyst rota.
Outcome — Median containment fell from 19 hours to 24 minutes with zero patient-facing downtime during rollout.
24m
Median containment
-88%
Alert noise
24/7
Coverage
AI SaaS
Vectorly
Threat Intelligence & AI
Challenge — A 40-engineer platform team was drowning in 12,000 open scanner findings with no way to rank real risk.
Approach — Deployed AI-driven vulnerability triage wired into their repos and runtime telemetry, with exploitability scoring and auto-generated fix PRs.
Outcome — Backlog cut by 91% in eight weeks; every remaining item is reachable, exploitable and owned.
-91%
Backlog
8wk
To steady state
1.4k
Auto fix PRs
Logistics
Portway Logistics
Governance, Risk & Compliance
Challenge — Enterprise deals were stalling in procurement because there was no SOC 2 report and no owner for security.
Approach — Fractional vCISO built the control set, evidence automation and vendor risk process, then ran the Type II observation window.
Outcome — SOC 2 Type II achieved in five months with zero exceptions, unblocking a seven-figure pipeline.
5mo
To Type II
0
Exceptions
$7M
Pipeline unblocked
Retail
Larkspur Retail
Training & Awareness
Challenge — Seasonal staff turnover kept phishing click rates above 30% across 6,000 store employees.
Approach — Continuous simulation campaigns tailored per role, five-minute micro-lessons, and manager-level reporting per store.
Outcome — Click rate down to 3.1% and report rate up 6x within two quarters.
3.1%
Click rate
6x
Report rate
6k
Staff trained
Energy
Helion Grid
Offensive Security
Challenge — A multi-account cloud migration for grid telemetry had no assurance that the blast radius was contained.
Approach — Cloud security assessment across identity, network and data planes, plus an assumed-breach exercise from a compromised workload.
Outcome — Cross-account escalation path eliminated and least-privilege baselines codified as policy-as-code.
0
Escalation paths left
118
Findings remediated
IaC
Guardrails shipped
Your engagement could be the next one here.
Tell us what keeps you up at night and we'll scope the shortest path from exposure to evidence.