Integrated Perspectives. Clear Direction.
Cyber risk rarely fits neatly into legal, technical, or business domains. It lives in the space between them, which is usually nobody’s job. It is mine.
Start here
Ask your finance lead, your head of technology, and your lawyer who would call the cyber insurance carrier at 2am. Three different answers is a problem. The same answer for three different reasons is a bigger one.
Here are five more questions worth asking.
- Who owns each piece of our cyber risk — and do they know they own it?
- Has our incident response plan ever been run across teams?
- Can someone articulate our cyber insurance policy requirements, including for incident response?
- What have we promised customers about our security, and could we prove it is true?
- If someone left three months ago, does their access still work — and would anyone know?
Each of these comes from one of the eight domains the Assessment examines. There are three more.
If you can answer all five with confidence, you probably do not need me.
If two or three gave you pause, there is work to do.
Where to go
AboutMy Background
Law enforcement, legal, software, operations. Four roles —
I have sat in each of those seats and run into the same problem from
all of them.
ServicesMy Work
The gaps between your functions — who owns them, what has
never been tested, and what to do first. Two ways to start, both
flat-rate.
GuidesMy Materials
Executive guides on the decisions that matter more than they appear, written for the people who have to make them.
Let’s Connect
Whether you’re reaching out to continue a conversation or begin a new one, I’d be glad to hear from you.
— Jessica

