Advisory Services
We take a small number of advisory engagements a year. They tend to be short, specific, and useful.
For enterprises, investors, family offices, and governments
Cybersecurity strategy
Where you are actually exposed, what to fix first, and what to ignore. Strategy that survives contact with a budget, a board, and a real adversary.
AI and the attack surface
What genuinely changes when both attackers and defenders have capable models, and what is noise. Most of the current conversation is noise, but the devil hides in the detail.
Technical diligence
An operator's read on a security company, its category, and its team, before the check gets written.
Policy and regulation
Where disclosure law, liability, and AI rules are heading, and what that means for your exposure. We have worked on this in the United States and Australia, in public and in the room.
For startups
Positioning and narrative
Making deep technical work legible to buyers, investors, and press without hollowing it out.
Founder counsel
From someone who did it for thirteen years, including the parts nobody writes about.
Community credibility
The security community can tell when it is being marketed to. We can help you not do that.
Introductions
Selectively, to people we actually know, when it is a genuine fit.
How it works
Engagements are structured to fit the problem: a single-day intensive, a defined block of days, an hourly consultation, a monthly retainer, or a standing advisory seat. We will advise you early if we are not the right fit. We decline engagements often enough that our acceptance means something.
Get in touch
Reach out and tell us what you are working on.