AI Risk & Readiness Assessment
A fixed-scope diagnostic that examines what your AI systems actually do rather than what their documentation says they do, scored against the published OSRA model and returned as a prioritized remediation roadmap.
Advisory
Most organizations do not see the gap clearly until something goes wrong. On one side is the infrastructure they have built, the platforms they run and the AI systems they are adopting faster than they understand. On the other is how those systems are actually overseen, interpreted for the board, and held accountable when the pressure arrives. Closing that distance is what I am hired to do.
The engagements vary. I start every one of them the same way, with an honest assessment of where things actually are rather than where they are supposed to be.
Scoped
Fixed scope, fixed fee, a defined end. I agree all three with you before the work starts, and I do not bill by the hour or let scope drift.
A fixed-scope diagnostic that examines what your AI systems actually do rather than what their documentation says they do, scored against the published OSRA model and returned as a prioritized remediation roadmap.
All four OSRA phases run across the estate rather than a scoped sample, ending in a convergence risk summary and a remediation programme your teams can execute.
Other scoped reviews follow the same shape: a security architecture review, pre-investment technology due diligence, or a regulatory readiness check before something becomes urgent. Ask on the call.
Ongoing
A standing relationship rather than a deliverable. We agree a cadence at the start and I hold to it, on a monthly fee fixed in writing before the first month runs.
Senior security leadership for organizations that need CISO-level judgment without a full-time hire, and for the ones now working through what an assessment found.
Work with founders and leadership teams on platform architecture, technology strategy, and the structural decisions that determine whether systems scale coherently or accumulate fragility over time.
Direct engagement with leadership teams, boards and audit committees on AI governance, platform risk, cybersecurity obligations and regulatory exposure, including non-executive director and advisory board roles.
Track record
Nearly three decades
Running security and technology organizations as CISO and as CTO.
Four regions
Deployments and accountability across the US, Europe, Japan and APAC.
Patents on AI agent infrastructure
Named inventor on interoperable digital asset execution and on contextual data for AI agent activity, alongside three earlier web platform families.
OSRA, published in full
Methodology, scoring model, practitioner templates and a 22-action catalogue, under CC BY-SA 4.0.
A worked example
All four OSRA phases run against a DORA-regulated bank, published so buyers can read the output first.
Two books
The Split Problem and The Hacker's Letters, both Quill House Press, 2026.
Next step
A thirty minute call to establish what you are exposed to and whether an engagement is worth running.