Five weeks since founding Hedgehog Security. The operational rhythm is taking shape; specific structural decisions about the practice are emerging.
This is a longer reflective post because the early founding period deserves explicit treatment.
What the past five weeks have produced
Specific operational establishment work.
The legal entity, the bank account, the basic infrastructure. Limited company registered, business banking in place, specific basic operational infrastructure established. Bounded but necessary work; now substantially complete.
Specific cumulative initial client engagement. Two client engagements have started; both draw on relationships from the previous CISO and conference work. Specific scope, specific deliverables, specific timelines — all defined.
Specific cumulative engagement with the broader practitioner network. Specific subsequent conversations with peer CISOs, with prospective clients, with specific industry contacts. The transition from "Gala Coral CISO" to "independent practitioner" requires explicit communication.
Specific cumulative writing on what Hedgehog does. Specific website content, specific service descriptions, specific operational guidance for prospective clients. Bounded work but useful for clarifying my own thinking.
The cumulative initial period has been productive. Specific subsequent decisions about scaling and specialisation will follow.
What is harder than expected
Three things.
The context-switching cost. Operational employment provides predictable structure; independent practice produces multiple parallel client engagements. Switching attention between specific engagements has cumulative cost; specific operational discipline about scheduling matters.
The administrative overhead. Specific cumulative invoicing, specific cumulative accounts, specific cumulative client onboarding — all are bounded but real. Specific cumulative discipline about administrative time matters.
The professional isolation. Operational employment provides cumulative team support; independent practice produces specific cumulative isolation. The cumulative correspondence network compensates partially; specific subsequent attention to professional connection matters.
These are predictable features of independent practice. The cumulative adjustment is bounded.
What is easier than expected
Three things.
Client acquisition through existing network. Specific relationships from the previous role and from conference engagement support specific subsequent client work without substantial marketing investment. The cumulative practitioner profile produces operational value.
Specific cumulative scope discipline. Independent practice supports clearer scope decisions than operational employment sometimes permits. Specific clients, specific engagements, specific deliverables — the cumulative discipline of explicit scoping is operationally workable.
Specific cumulative substantive engagement. Independent client engagements require sustained attention from the practitioner directly; specific cumulative cumulative substantive operational engagement is more accessible than at large operators.
The cumulative early experience supports specific subsequent decisions about how Hedgehog should develop.
What I am thinking about
Specific cumulative thinking through the early period.
Specialisation versus generalisation. Specific cumulative subsequent work could specialise (DDoS-defence, payment-card compliance, gaming-sector security) or generalise (broad cybersecurity advisory across sectors). Specific cumulative thinking favours bounded specialisation with general capability for related work.
Scale versus solo practice. Specific cumulative subsequent thinking about whether to remain solo or to grow. The cumulative early decision is to remain solo through the first year; specific subsequent decisions about scaling will follow.
Specific cumulative client mix. Specific cumulative thinking about what client mix is operationally sustainable — large operators, small businesses, public sector, specific other categories. The cumulative early observation is that the mix matters less than the substantive engagement.
Specific subsequent decisions will inform the practice's development.
What this means for the notebook
Specific cumulative writing from independent practice will be bounded by client confidentiality; specific cumulative general patterns can be discussed.
The weekly cadence continues. Specific cumulative subsequent posts will reflect the operational reality of the practice; the cumulative archive grows.
A small reflection
Founding work is operationally rewarding in ways that operational employment is not. Specific cumulative direct client engagement, specific cumulative own operational decisions, specific cumulative cumulative responsibility for outcomes — all produce specific cumulative cumulative satisfaction that operational employment bounds.
The cumulative early experience is, on balance, positive. Specific subsequent work will inform specific cumulative subsequent decisions.
More in time.