Advisory

I advise companies and practitioners in five areas: cyber risk quantification, exposure management, data-driven security, AI risk, and AI security.

Typical work: building a cyber risk quantification program or making an existing one more useful; reviewing whether a risk model or quantification method will hold up with buyers, insurers, and auditors; model design and validation; the empirical grounding behind risk claims; measuring security posture and exposure; AI risk governance and securing LLM-based systems.

Advisory means judgment on direction and method, in a fixed number of hours. It is not delivery work or staff augmentation.

How to start

A free 15-minute call to see whether I am the right fit for your question.

Write to me on LinkedIn.

For companies

Building or improving a CRQ program

Setting up a cyber risk quantification program, or making an existing one more useful: defining the decisions it should support, choosing methods and data, calibrating against empirical loss data, validating the models, and reporting results that executives and boards can act on.

Monthly retainer

A monthly call plus async review of documents, models, and decisions. Fixed hours, 30 days' notice.

Fractional

One day a week, for building or running a risk quantification, exposure management, or AI risk capability.

One-off review

A written review of a risk model, a CRQ method, or a vendor's quantification claims, with findings you can act on.

Advisory board

For startups and scale-ups in security, risk, or AI.

For risk and security practitioners

Intro call

15 minutes, to check fit.

Deep-dive call

One hour on your risk model, quantification program, or AI risk question.

Call and written feedback

A call plus written feedback on a model, tool, or method.

Six months of support

Up to two calls a month over six months.