Cyber defence · consulting · engineering

I help organisations build cyber defence that works in the real world.

Detection engineering, incident response, threat-led testing, and the messy human reality of running security in real organisations. Based in the UK, working in UTC.

For the people who land here needing help

Privacy & anti-surveillance

Practical, opinionated, UK-flavoured resources for taking back control of your exposure and resisting the steady normalisation of surveillance. Long-time supporter of the EFF; long-time user of OpenPGP.

Recent writing

From the blog

Five Days in May: The Week That Defined Cyber Security in 2026

A reflection on a single week of cyber security disclosures — and what they tell us about the shape of the threat landscape, the maturity of attackers, and the choices defenders now need to make.

Sixteen-and-three-quarter years

Hedgehog at sixteen-and-three-quarter years. A short note on the arc, written from the calmer winter than the previous several have been.

What a Cyber and AI Non-Executive Director actually does in a board meeting

Stripped of the platitudes — the 24 hours either side of a UK board meeting, from the seat of the Cyber and AI NED. What I read in the pack, what I look for, what I ask, and what I write down.