Marco BrondaniSecurity, AI risk and platform strategyBook a call

Practice

I have run security and technology organizations. Now I audit whether yours stands up to regulators and attackers.

The work runs on OSRA, an open methodology for finding where AI operational risk actually lives: the infrastructure substrate that governance frameworks assume and never verify. Reading it well takes nearly three decades of having run security and technology functions.

Book a call

Scoped

Fixed scope, fixed fee, a defined end.

  • 3–4 weeks
  • Low five figures

AI Risk & Readiness Assessment

A fixed-scope diagnostic that examines what your AI systems actually do rather than what their documentation says they do, scored against the published OSRA model and returned as a prioritized remediation roadmap.

  • 6–8 weeks
  • Mid five figures

Full OSRA Engagement

All four OSRA phases run across the estate rather than a scoped sample, ending in a convergence risk summary and a remediation programme your teams can execute.

Ongoing

A standing relationship rather than a deliverable.

  • Monthly retainer
  • Four figures per month (indicative)

Fractional CISO Retainer

Senior security leadership for organizations that need CISO-level judgment without a full-time hire, and for the ones now working through what an assessment found.

  • Retainer or project
  • Four figures per month, or a fixed fee by project (indicative)

CTO Advisor

Work with founders and leadership teams on platform architecture, technology strategy, and the structural decisions that determine whether systems scale coherently or accumulate fragility over time.

  • Retainer or board seat
  • Four figures per month, or an annual fee for a board seat (indicative)

Executive & Board Advisory

Direct engagement with leadership teams, boards and audit committees on AI governance, platform risk, cybersecurity obligations and regulatory exposure, including non-executive director and advisory board roles.

Track record

  • Nearly three decades

    Running security and technology organizations as CISO and as CTO.

  • Four regions

    Deployments and accountability across the US, Europe, Japan and APAC.

  • Patents on AI agent infrastructure

    Named inventor on interoperable digital asset execution and on contextual data for AI agent activity, alongside three earlier web platform families.

  • OSRA, published in full

    Methodology, scoring model, practitioner templates and a 22-action catalogue, under CC BY-SA 4.0.

  • A worked example

    All four OSRA phases run against a DORA-regulated bank, published so buyers can read the output first.

  • Two books

    The Split Problem and The Hacker's Letters, both Quill House Press, 2026.

Writing

I have written two books, one on AI and one telling my years in security as fiction, and I have been writing essays long enough that they are worth reading before you book a call.

Read the writing

Next step

Book a call

A thirty minute call to establish what you are exposed to and whether an engagement is worth running.

Book a call