CAIRNCYBER ADVISORY

Independent security architecture

Security architecture for AI and emerging technology

I help regulated organisations adopt AI, agentic systems and emerging technology without waiting for their control frameworks to catch up. That usually means threat modelling what is actually being built, then designing controls that enforce whatever policy you have written.

CISSP · CCSP · Outside IR35 · Edinburgh and remote

The practice at a glance

15 years
Security and infrastructure architecture
CISSP · CCSP
Certified, ISC²
Outside IR35
B2B contracts, deliverable-based
Independent
No products, no vendor referral fees

Where I help

All services →

How engagements are shaped

Four shapes cover most of the work. Scope, duration and deliverables are agreed in writing before anything starts, and rates are quoted against that scope.

  • Discovery

    1 to 2 weeks

    You need a defensible view of where you stand before committing to a programme.

  • Architecture review

    2 to 4 weeks

    A specific design, platform or third-party system needs independent sign-off.

  • Embedded advisory

    3 to 12 months, part or full time

    A programme needs security design authority in the room while decisions are still being made.

  • Retained advisory

    Ongoing, defined days per month

    You need senior architectural input available on demand without carrying the headcount.

Contracting, IR35, insurance and onboarding →

Selected work

Engagements are described by sector and scale only. No client is named, and no client's security posture is described.

All engagement profiles →

Recent writing

The problems that come up repeatedly, written up in enough detail to be useful to someone solving them without me.

All insights →

Background

Fifteen years in security and infrastructure architecture, most recently as a Vice President and Security Architect in institutional banking, and before that leading security standards and AI governance at a global asset manager. Work has spanned generative and agentic AI, blockchain and crypto-custody, and large-scale cloud transformation in environments where controls have to be evidenced rather than described.

More about my background → · Capability statement →

Start a conversation

Send an outline of the problem and the timescale. I reply to every enquiry that is a plausible fit, usually within one working day.