Defence & Critical Infrastructure
Critical Infrastructure & Gov Advisory
Zero Trust and operational security for essential services, public bodies and the defence supply chain.
I harden converged IT and OT environments and give the board and the regulator assurance they can rely on.
- Independent and agnostic
- Evidence-driven analysis
- Clear, actionable recommendations
- Senior attention, end to end
The challenge
In operational environments, downtime is the incident.
When IT and OT converge, a problem that would be an inconvenience in an office becomes a safety or continuity event on the plant floor. Legacy systems were built for availability, not for a hostile network, and the same connectivity that improves oversight also widens the attack surface. A disruption here is measured in stopped production, regulatory scrutiny and, in the worst case, physical risk.
What I do
Resilience for systems that cannot stop.
Security that survives contact with a real operating environment — architecture, OT and reporting, aligned to the stakes.
How I workArchitecture Review
Assess segmentation, identity and trust boundaries against a real threat model.
Zero Trust Roadmap
A practical path to never-assume-trust, sequenced to operations.
OT / ICS Security
Protect operational technology without breaking the process.
Resilience Testing
Exercise detection, response and continuity under pressure.
Regulatory Assurance
Evidence of posture and progress for NIS2 and national obligations.
Board Reporting
Clear reporting the board and the authority can both rely on.
My approach
A methodology built for high-stakes environments.
I map the terrain, test it the way an adversary would, and harden what matters.
Explore my method- 01
Understand
Map assets, dependencies and the real threat model.
- 02
Discover
Collect evidence across IT and the OT nobody documents.
- 03
Assess
Test the architecture against how it would actually be attacked.
- 04
Harden
Prioritised, proportionate change with operational owners.
- 05
Assure
Continuous evidence for the board and the authority.
- A clear map of where IT and OT actually meet, and where trust is assumed rather than earned.
- A hardening roadmap sequenced around operations, not against them.
- Evidence of posture and progress you can put in front of the board and the regulator.
- Tested confidence that detection, response and continuity hold under pressure.
Case study
OT/ICS Security for an Industrial Manufacturer
IT/OT convergence secured and lines segmented — without ever stopping production.
Read the case study
Work & insights
What I’ve done
NIS2Public Body Operating an Essential Service
NIS2 compliance and operational continuity for an essential service, with a Zero Trust architecture and assurance demonstrable to the competent authority.Public Sector
NIS2NIS2 in practice: who is in scope, what changes, how to prepare
Directive (EU) 2022/2555 widens the perimeter and puts accountability on management bodies. An operational reading, without alarmism.12 Sep 2025 · 4 min read
OT/ICSOT/ICS security: protecting without stopping the process
IT/OT convergence, segmentation and patching in systems you cannot switch off.4 Nov 2025 · 4 min read
Frequently asked
Questions I get asked.
Will the assessment disrupt production?
No. I work within operational constraints, favour passive techniques in sensitive environments and agree any active testing with your operational owners in advance.
Do you cover both IT and OT?
Yes. The value is usually at the boundary between them — the connections and assumptions nobody has documented — so I assess the converged environment, not one half of it.
How does this relate to NIS2?
The work produces evidence of posture and progress that supports NIS2 and national obligations. I can align the scope to those requirements, but readiness is not the same as a formal compliance ruling.
Do you work with public bodies and the defence supply chain?
Yes. I work with essential-service operators, public bodies and defence-supply-chain companies, under confidentiality terms appropriate to the context.
Ready to start?
Let’s talk about your case.
Every situation is unique. Tell me the context and I’ll help you define the best approach.
Book a consultation