Independent security architecture
Security architecture for AI and emerging technology
I help regulated organisations adopt AI, agentic systems and emerging technology without waiting for their control frameworks to catch up. That usually means threat modelling what is actually being built, then designing controls that enforce whatever policy you have written.
CISSP · CCSP · Outside IR35 · Edinburgh and remote
The practice at a glance
- 15 years
- Security and infrastructure architecture
- CISSP · CCSP
- Certified, ISC²
- Outside IR35
- B2B contracts, deliverable-based
- Independent
- No products, no vendor referral fees
Where I help
AI & agentic AI security architecture
Threat modelling, gateway controls and governance for organisations putting AI into production under regulatory scrutiny.
Cloud & hybrid security architecture
Security architecture for cloud migration, platform build and post-merger integration in regulated environments.
Security standards & governance
Standards, control frameworks and governance processes that survive contact with an audit and with delivery teams.
Architecture review & assurance
Independent security review of designs, platforms and third-party systems before they reach production.
Blockchain & digital asset security
Security standards and architecture for blockchain, tokenisation and crypto-custody in regulated institutions.
How engagements are shaped
Four shapes cover most of the work. Scope, duration and deliverables are agreed in writing before anything starts, and rates are quoted against that scope.
Discovery
1 to 2 weeks
You need a defensible view of where you stand before committing to a programme.
Architecture review
2 to 4 weeks
A specific design, platform or third-party system needs independent sign-off.
Embedded advisory
3 to 12 months, part or full time
A programme needs security design authority in the room while decisions are still being made.
Retained advisory
Ongoing, defined days per month
You need senior architectural input available on demand without carrying the headcount.
Selected work
Engagements are described by sector and scale only. No client is named, and no client's security posture is described.
Establishing AI security governance at a global asset manager
Asset management · Institutional scale, UK-regulated
An enforceable AI security standard, with gateway controls behind it, in place before the main rollout.
Blockchain security standard for an institutional custodian
Custody and institutional banking · Global custody and asset servicing
A blockchain security standard giving the firm a defined basis for adopting digital assets.
Security review of an enterprise analytics platform
Financial services · Enterprise analytics platform, large and varied data estate
Independent approval to go to production, with conditions attached and compliance evidenced.
Recent writing
The problems that come up repeatedly, written up in enough detail to be useful to someone solving them without me.
Evidence, not attestation: making AI controls auditable
· 6 min read
ISO 42001, the NIST AI RMF and DORA ask different questions of the same estate. The organisations that answer them cheaply are the ones whose controls emit evidence as a by-product of running.
Agentic AI breaks your identity model before it breaks anything else
· 8 min read
Agents are non-human identities that act on a user's behalf, change task mid-flight and chain to other agents. Most enterprise IAM models have no representation for that, and the gap shows up as over-permissioned service accounts.
What an AI gateway is for, and what it is not
· 6 min read
An AI gateway is the control point that makes an AI policy enforceable. It is not a firewall for prompts, and buying one does not constitute governance.
Background
Fifteen years in security and infrastructure architecture, most recently as a Vice President and Security Architect in institutional banking, and before that leading security standards and AI governance at a global asset manager. Work has spanned generative and agentic AI, blockchain and crypto-custody, and large-scale cloud transformation in environments where controls have to be evidenced rather than described.
Start a conversation
Send an outline of the problem and the timescale. I reply to every enquiry that is a plausible fit, usually within one working day.