01 · Identity & Access

Identity as the control plane.

Treating identity as the primary security boundary, so access is decided on explicit, auditable signals rather than assumed network trust.

80%
High-risk sign-ins fell by 80% in a government tenant once Entra ID Protection, Conditional Access, and Defender XDR identity signals were wired to work together rather than in isolation.
Government
OAuth OIDC mTLS
Replaced implicit trust between internal services with explicit, auditable authentication across a government application estate, using OAuth, OIDC, and mTLS in place of standing assumptions.
Government
Device Trust
Built conditional access strategies that tie each access decision to device and workload posture, moving the boundary off the network perimeter and onto the identity itself.
Enterprise
Zero standing access
Removed permanent privileged access from a government application estate using Entra PIM, replacing standing admin rights with just-in-time elevation tied to approval and justification. Every privileged action now has an audit trail showing who approved it and why, not just that access occurred.
Government
02 · Detection & Response

Seeing the attack sooner.

Rebuilding detection so coverage maps to real adversary behaviour, and the gap between compromise and discovery keeps shrinking.

Months to weeks
Mean time to detect dropped from months to weeks across a government environment after Defender XDR and Sentinel were brought into the SOC and tuned against real signal.
Government
80%
Detection visibility improved by 80% across Azure, AWS, and GCP by rebuilding the Sentinel analytics rules from the ground up and aligning coverage to MITRE ATT&CK rather than to vendor defaults.
Financial Services
70%
Security incident exposure reduced by 70% across a Critical National Infrastructure enterprise after introducing zero-trust controls and tightening the underlying security architecture.
CNI
AI for SecOps
Hands-on with AI inside the security stack in production: Copilot for Security running in Sentinel, and Copilot configured for GitHub, used to speed triage and review rather than as a demo.
AI Security
03 · Cloud Architecture & Governance

Platforms that stay governed at scale.

Designing cloud estates and the guardrails around them, so growth does not quietly outrun the controls.

20+ accounts
Stood up AWS account governance from scratch for a government platform: VPC design, IAM service control policies, KMS in production, Control Tower guardrails, and four native security services running together (GuardDuty, Security Hub, Inspector, Macie).
Government
50 to 100
Migrated 50 to 100 workloads off an on-premise datacentre into Azure, then closed the datacentre on schedule with no programme management structure above the architecture role to lean on.
Government
20+ pipelines
Brought more than 20 CI/CD pipelines under one governance framework across Azure DevOps and GitHub, with security gates and policy-as-code so the controls travel with the deployment.
Enterprise
80%
Shadow IT exposure cut by 80% at a global manufacturer through governed provisioning and controlled third-party access, replacing unmanaged tooling with sanctioned routes.
Manufacturing
50 to 100 rules
Remediated 50 to 100 redundant, shadowed, and non-compliant firewall rules through AlgoSec across a global estate, taking out the cruft that hides real exposure.
Financial Services
Within target
Brought cloud spend back inside programme targets through structured cost governance: tagging discipline, budgets, right-sizing, and reserved instances, rather than blanket cuts.
FinOps
Zscaler ZIA & ZPA (Zero Trust)
Replaced legacy VPN and proxy infrastructure with Zscaler as part of a full datacentre closure, under programme pressure, with no rollback. ZIA and ZPA deployed in production across financial services and government. Integrated with Entra ID, Conditional Access, and a live Palo Alto and AlgoSec estate. The migration was done and operational before the legacy was retired.
Enterprise
Sentinel remediation
Delivered a Microsoft Sentinel remediation engagement, resolving platform configuration issues across nine data connectors and completing the Unified Defender Portal transition. Left the platform properly configured and operationally stable, not just technically functional.
SIEM
04 · Validation & Assurance

Proving the controls hold.

Continuous validation and threat modelling embedded into how teams work, so assurance is something the organisation does for itself rather than waits to be told.

6 months
STRIDE threat modelling went from years of stalled attempts to teams self-serving it within six months of a practical reintroduction, the point where it stopped being a security activity and became theirs.
STRIDE
50+ payloads
Ran more than 50 simulated attack payloads through Cymulate Breach and Attack Simulation as continuous control validation, treating it as a standing health check rather than a one-off test.
BAS
Adopted
After a proof of concept proved its worth, the red team folded Cymulate into their permanent assurance toolbox and DevOps teams began self-validating deployments without waiting on an external review.
BAS
$500K
Produced a costed security improvement backlog worth around $500K from ten stakeholder workshops, with an actionable design attached to every item so it could be picked up and built, not just logged.
FinOps
Cloud Migration
Led a six-month lift and shift migration from on-premises to Azure for a European airline, eliminating accumulated tech debt and cutting legacy vulnerabilities in container images by 60%. Governed the transition from day one so the cloud baseline was secure before the legacy estate was retired, not patched retrospectively after.
Tech Debt
Architecture board
Chaired an enterprise architecture board aligned to SABSA, and led the project design gates so work had to meet the security architecture standard before it could progress.
CNI
Want the detail behind any of these?
Happy to talk through the architecture, the trade-offs, and what did not work first time. Cloud security, Zero Trust, AI governance, or enterprise security strategy.