Three shapes the work takes.
One audit.
Architecture review, pre-audit readiness, vendor due diligence. Work with a defined end and a written deliverable you can hand to a board.
Fractional CISO.
Strategy, policy, compliance, vendor assessment, incident response — a security lead on the org chart for a fraction of the salary. When I sign your annual review, it’s because I read it.
Fractional CTO.
Security built in, not bolted on. Vendor selection, technical due diligence. When one head isn’t enough, I bring vetted people from iitcon.
Figures are indicative starting points, in USD. A firm fixed quote comes before anything starts — and I never bill by the hour.
Lived in, not studied.
HIPAA. HITRUST. SOC 2. NIST 800-53/171. ISO 27001. GDPR. PIPEDA / PIPA. I’ve mapped every one of these to production systems — controls against the data flow you actually have, then the gaps that matter closed.
The certifications belong on the cv page.
You get me.
Not a bench of juniors with my name on the invoice. I hold a small number of engagements at once, on purpose, and scope each one so I can actually deliver it. When a job needs more hands or round-the-clock coverage, iitcon is the vetted bench behind me — and you’ll know exactly who is doing what before anything starts.
What I won’t do.
I take the engagements I can do honestly. Which means a few I turn down:
- Write a policy you’ll never read so an auditor can tick a box.
- Run a phishing drill that humiliates your help desk while the executive team stays exempt.
- Sell you a SIEM, an EDR, or a CASB. I take no vendor commissions and never will.
- Soften a finding to protect someone’s quarter.