Advisory
I advise companies and practitioners in five areas: cyber risk quantification, exposure management, data-driven security, AI risk, and AI security.
Typical work: building a cyber risk quantification program or making an existing one more useful; reviewing whether a risk model or quantification method will hold up with buyers, insurers, and auditors; model design and validation; the empirical grounding behind risk claims; measuring security posture and exposure; AI risk governance and securing LLM-based systems.
Advisory means judgment on direction and method, in a fixed number of hours. It is not delivery work or staff augmentation.
A free 15-minute call to see whether I am the right fit for your question.
Write to me on LinkedIn.
Building or improving a CRQ program
Setting up a cyber risk quantification program, or making an existing one more useful: defining the decisions it should support, choosing methods and data, calibrating against empirical loss data, validating the models, and reporting results that executives and boards can act on.
Monthly retainer
A monthly call plus async review of documents, models, and decisions. Fixed hours, 30 days' notice.
Fractional
One day a week, for building or running a risk quantification, exposure management, or AI risk capability.
One-off review
A written review of a risk model, a CRQ method, or a vendor's quantification claims, with findings you can act on.
Advisory board
For startups and scale-ups in security, risk, or AI.
Intro call
15 minutes, to check fit.
Deep-dive call
One hour on your risk model, quantification program, or AI risk question.
Call and written feedback
A call plus written feedback on a model, tool, or method.
Six months of support
Up to two calls a month over six months.