A view of the work by capability rather than by employer: the controls designed, the risk taken off the table, and the outcomes that can be pointed at. Drawn from engagements across UK government, Critical National Infrastructure, manufacturing, and regulated enterprise.
Treating identity as the primary security boundary, so access is decided on explicit, auditable signals rather than assumed network trust.
Rebuilding detection so coverage maps to real adversary behaviour, and the gap between compromise and discovery keeps shrinking.
Designing cloud estates and the guardrails around them, so growth does not quietly outrun the controls.
Continuous validation and threat modelling embedded into how teams work, so assurance is something the organisation does for itself rather than waits to be told.