CAIRNCYBER ADVISORY

About

I am Gary Johnston, a security architect working with regulated organisations on the security of AI, agentic systems and emerging technology. Cairn Cyber Advisory Ltd is my practice.

Most of my career has been in environments where a control has to be demonstrated rather than described. That covers institutional banking, asset management, telecommunications and most recently a large international law firm. I have held architectural oversight for systems processing multi-million-dollar transactions daily, and led the security review for an analytics platform operating over an asset base in the trillions.

The work I find most useful sits at the point where a new technology has outrun the organisation's control framework. Recent examples include an AI security standard with the gateway controls to enforce it, an institutional blockchain security standard built from nothing, and an overhaul of a set of enterprise security standards that had gone eight years without revision.

I work with engineers and with executives, and a good deal of the job is translation between them. A risk the committee cannot understand does not get funded.

How I work

Independent, and small on purpose. You get the person you engaged rather than a team assembled around a framework, and the work is judged on whether a delivery team could build from it. I would rather hand over a design decision with its rationale attached than a maturity score.

I write things down. Most engagements end with a document your organisation keeps and can maintain without me: a standard, a target architecture, a review with findings and a route to closing them. Advisory that leaves nothing behind has to be bought again every year.

Some of the thinking is public: Insights covers threat modelling AI features, gateway control design and evidencing AI governance, which is most of what clients ask about first.

The name

A cairn is a stack of stones placed to mark a safe route through difficult terrain. Each one is built by whoever passed before and maintained by whoever passes next. That felt closer to the work than anything involving shields or fortresses.

The mark takes that literally: four stones, each meeting the next along a shared contact edge, nothing balanced precariously. It is on the brand page if you need it for a supplier record or a conference programme.

Experience

  • Senior Security Architect (contract)

    2026 to present · International law firm, cloud migration ahead of an operational merger

  • Vice President, Security Architect

    2025 to 2026 · Global custodian bank, Edinburgh

  • Senior Security Architect

    2023 to 2025 · Global asset manager

  • Cloud Security Architect

    2021 to 2023 · Media and telecommunications group

  • Cloud Architect

    2019 to 2021 · Global network and IT services provider

Client names are omitted deliberately. I am happy to discuss specifics under NDA.

Talk it through

If the problem you have is in this territory, send an outline and I will tell you honestly whether I am the right person for it.