top of page

Services

Human-centered security awareness, paired with governance and compliance programs built to withstand audit.

My practice spans both pillars of security relevant to financial-sector organizations: the human element, through security awareness culture programs, phishing simulations, and role-based training that reduce human risk where technology alone falls short.

 

And the governance element: governance and policy design, risk assessment and third-party risk management, and compliance program management aligned to DORA, NIS2, GDPR and ISO 27001 — built to satisfy regulators and hold up in daily practice too.

Engagements range from focused, one-off projects to ongoing advisory retainers — whichever fits where your organization is right now.

ChatGPT Image Jul 15, 2026, 03_53_37 PM_edited.jpg

Security Training & Awareness

Technology can't stop every threat. People are often the strongest layer of defense, or the weakest, depending on whether the training actually lands. I build programs that go beyond compliance boxes: grounded in where your organization actually stands today, tailored to real risk profiles, and measured over time so you can see behavior genuinely changing.

Corporate Networking Event_edited.jpg

Security awareness culture programs

I start with a current-state analysis, then build a program from the ground up — aligned to your company's culture, combining mandatory training with ongoing awareness, and tailored to each team's actual risk profile.

_Hope is such a bait, it covers any hook

Phishing simulation campaigns

I onboard a platform or work within your existing tooling to build the annual phishing strategy, run the campaigns, and report findings that show real behavior change — not just click-rate numbers.

Exam_edited.jpg

Role-based
training

Executives, developers, and new hires face different risks and respond to different material. Training is built around each group's actual risk profile rather than a one-size-fits-all module everyone clicks through and forgets.

Security Guard Uniform_edited_edited_edi

Cyber and physical security awareness

Human risk doesn't stop at the firewall. I build awareness content covering physical security practices alongside cyber hygiene — the two are usually taught separately, when in reality most real incidents involve both.

Meeting_edited.jpg

Incident response tabletop exercises

A facilitated, scenario-based walkthrough where the right people talk through their actual response, compared against what your plan says should happen. The gap between the two is where the real fixes are.

Business Analyst Digital Pen Review Tech

Awareness maturity metrics & reporting

Every program starts with a clear baseline. From there, I measure progress against it using platform data, turning years of metrics into a picture of behavior change leadership can act on.

Governance, Risk & Compliance

Regulators don't reward good intentions, they reward evidence that your organization actually manages risk day to day. I build and run the governance structures, risk assessments, and compliance programs that hold up under real scrutiny, for the frameworks that matter most to financial-sector organizations right now.

Pink Key Shadow

Compliance program management

Building and managing compliance programs against DORA, ISO 27001, GDPR, and PCI DSS — the frameworks that actually apply to financial-sector organizations today, not generic best practice.

Image by Alexander Grey

Policy & procedure development

Policies and procedures written to be followed, not filed — aligned to how your teams actually operate and to the regulatory frameworks you need to satisfy.

Filling Checklist Form

Risk assessments

Regulatory gap analysis and readiness assessments that tell you exactly where you stand against ISO 27001 or NIST CSF, and what needs to close before an external audit does.

Image by Scott Graham

ISMS implementation

Reviewing and strengthening an existing ISMS, or building one from scratch aligned to ISO 27001, depending on where your organization is starting from.

Building

Third-party & vendor risk management

Assessing the risk your vendors and outsourcing partners bring into your organization, including full outsourcing risk assessments — a growing regulatory expectation under DORA specifically.

© 2026 MGH CYBER CONSULTING

bottom of page