// ABOUT HANS STUDY · INDEPENDENT NETWORK AND SECURITY CONSULTANT

Hans Study. Independent network and security consultant, CISSP.

I'm an independent network and security consultant based in Ontario, Canada, working with clients across Canada and the United States. I work as a fractional CISO and strategist for defence suppliers, critical infrastructure, public safety, and regulated organizations. The work is boutique: security leadership and strategy, enterprise networks, OT and ICS, controls and security systems, and the infrastructure underneath them, with a focus on defence supply chain compliance and the OT, IT, and physical security convergence boundary. Microsoft Windows, Cisco, Aruba, and Genetec Security Center are my primary stacks. Federal, defence, law enforcement, public safety, critical infrastructure, and enterprise.

Hans Study, CISSP, independent network and security consultant, Ontario, Canada

What I do

DO-01

Specialize in boutique networks and systems

Controls, security, and critical infrastructure. Small portfolio, deep engagement, no time spent juggling a hundred unrelated accounts. The work fits where the stakes are high and the cost of getting it wrong is real.

DO-02

Design networks and physical security systems

Greenfield and brownfield. Topology, segmentation, routing, wireless, and security architecture. Camera, access control, and intercom systems specified for the environment rather than copied from a previous job.

DO-03

Solve complex integration and technical problems

The systems that should work but do not. Cross-vendor integration issues. Performance and reliability problems that nobody else has been able to nail down. Pre-RFP technical review and owner representative work during deployment.

DO-04

Harden and tune infrastructure and organizations

Windows server and workstation baselines. Switch and firewall hardening. Genetec deployments where Defender exclusions and service accounts have to be exactly right. Tuning for VMS and access control workloads under audit.

DO-05

Mentor practitioners and integrators

Free, time-permitting. Junior practitioners moving into network or security work, integrator teams bidding their first complex project, and IT generalists handed a Genetec environment they did not design. Asynchronous over email when that fits, scheduled calls when the question is bigger.

What I do and what I don't

A quick filter before you book a call.

Not for
  • Helpdesk and end-user support. Password resets, laptops, printers.
  • Selling or reselling equipment or licences. No margin on anything, as the independence policy sets out.

Primary stacks

STK-01

Microsoft Windows (server and workstation)

Hardening, baselines, Active Directory design and tiering, Defender tuning for VMS and access control workloads, Group Policy at scale.

STK-02

Cisco

IOS, Catalyst 9000 series, ISE. Routing, switching, and the security tracks taught at the post-secondary level.

STK-03

Aruba

AOS-CX and CX switching. ClearPass on the policy side. Field-experienced in deployments where Aruba is on the bill of materials.

STK-04

Genetec Security Center

Architecture, deployment, troubleshooting. Directory, Archiver, Synergis, ConfigTool, Security Desk. The reference platform for VMS work on this site.

STK-05

Adjacent stacks

Axis, Bosch, Milestone, Avigilon, C-CURE 9000, Fortinet, Palo Alto, Juniper EX, and Alcatel-Lucent OmniSwitch. Selected when they are the right fit for the deployment.

How this started

I started the way a lot of people in this field do. Fixing computers for friends and family in the early 2000s. A part-time job at a local computer shop installing small business networks and CCTV systems. By 2010, that had grown into my own IT firm. I built and sold an earlier security practice in the years that followed.

What followed over the next fifteen years is where the depth comes from.

Where the depth comes from

I have spent my career working across public sector, defence, public safety, and critical infrastructure environments, designing and integrating the technology those organizations depend on. That includes years on federal mission-critical networks, where operational continuity was a daily responsibility, not a theoretical goal.

What keeps me in the work is curiosity. I take systems apart to understand how they function, push security controls to their limits, and apply the lessons to stronger designs. Same approach to work, play, and hobbies. That habit shapes how I approach both digital and physical security today.

That curiosity also pushed me into developing technical courseware and educational content, and into teaching at the post-secondary level as an associate professor. The courses ran Cisco CCNA, Introductory and Advanced Networking, Information Security, and Microsoft Windows Server and Workstation. Hundreds of students went through them. Teaching is where you find out how well you actually understand something. You cannot fake it when someone asks you to explain why, not just how. The courseware work continues through the Study Learning programme. The teaching was one chapter of it.

Books

I'm the author of The Study Guide series, a practitioner-focused book series for networks, physical security, and the integration problems that sit between disciplines. 3 titles are currently available:

Additional volumes are in development. Available on Amazon.

Credentials and platform experience

CISSP, from ISC2, is the credential I hold and keep current. A certification does not tell you whether the person can do the work, so the rest of this section is platform experience from 15 years in the field.

CRED-01

Networking platforms

  • Cisco: routing, switching, and security in the field across Catalyst, Nexus, Meraki, ASA, and FTD platforms. Taught CCNA at the post-secondary level for multiple years to hundreds of students.
  • Aruba (HPE): field-experienced with Aruba CX, Aruba OS, and ClearPass.
  • Alcatel-Lucent Enterprise: field-experienced with the OmniSwitch family in security network deployments.
  • Juniper: field-experienced with the EX series for security and enterprise environments.
  • Palo Alto Networks and Fortinet: field-experienced on next-generation firewall design and operation.
CRED-02

Wireless

  • Ekahau for predictive site survey design, validation surveys, and troubleshooting on enterprise Wi-Fi deployments. Trained on Ekahau and CWNP material.
  • Field experience across Cisco, Aruba, and Meraki wireless platforms in airports, transit, government, and enterprise environments.
CRED-03

Physical security platforms

  • Genetec: field-experienced across Security Center, Omnicast, Synergis, and AutoVu.
  • Software House C-CURE 9000, Milestone XProtect, Avigilon Control Center, Axis Communications, and Axon Body and Fleet.
CRED-04

Microsoft

  • Active Directory design and tiering, Group Policy at scale, and Defender tuning for VMS and access control workloads.
  • Field experience hardening Windows Server 2016, 2019, 2022, and 2025 in production environments.
CRED-05

Forensics

  • Trained in mobile device forensics and computer forensics.
  • Field experience handling evidence networks and isolated investigative environments for law enforcement and corporate investigations.
Note

A note on certs versus practice

I took the courses, sat the exams, and did the work. CISSP is the one credential listed on this site. The priority has been doing the work, teaching it, and writing about it.

The teaching is worth highlighting separately. I taught Cisco CCNA, Introductory and Advanced Networking, Information Security, and Microsoft Windows Server and Workstation at the post-secondary level for multiple years. Hundreds of students went through those programs. That is a different kind of credential than a paper cert. It is the credential of having to explain the material to people learning it for the first time, every term, in a way they can actually use.

Compliance frameworks I work in

I advise organizations operating under:

CMMC 2.0US Department of Defense CPCSCCanadian Program for Cyber Security Certification ISO/IEC 27001Information security management
NIST SP 800-171Controlled unclassified information
NIST SP 800-53Security and privacy controls for information systems
NERC CIPCritical infrastructure protection
GO-ITSGovernment of Ontario IT Standards
ITSG-33Government of Canada
TIA-942Data centre infrastructure

Compliance work is not about applying frameworks as written. It is about helping organizations understand what each framework actually requires, given the technical and organizational constraints they are already operating under.

What I do, in plain terms

I work independently. No equipment sales, no margin on anything specified, no commission. The independence policy sets out what that covers. The recommendation reflects what the environment requires. That is the only thing it reflects.

  • Enterprise and control network architecture
  • Industrial and OT network design
  • Genetec Security Center, Software House C-CURE, Axis, Milestone, Avigilon, Axon
  • ICAT (Integrated Communications, Access, and Technology) design
  • Data centre and structured cabling advisory
  • CMMC, CPCSC, NIST 800-171, ISO 27001 compliance support
  • Owner's representative and project advisory
  • Mentorship and technical guidance for security integrators and IT teams

Speaking and writing

I have presented on cybersecurity resilience and infrastructure security at industry conferences and events.

The Articles at hans.study/articles/ is my working library of technical articles on switch hardening, Windows server hardening, Genetec deployment, OT and ICS security, and integration practices for security networks. The Knowledge Base at hans.study/standards-guidance/ is the reference library: vendor configuration templates, the Canadian Security Install Reference series, and the standards work that informs day-to-day field decisions. The StudyByt3s podcast covers the work that sits between IT, physical security, and OT, in the format of a conversation rather than a tips-and-tricks show.

Practitioner-grade utilities at hans.study/tools/ back up the writing. Switch configuration generator, Windows hardening script generator, subnet calculator, conductor and BOM calculator, SCHANNEL crypto config. Each one is a tool I needed at some point and decided was worth building properly.

Open source

The tools I use on engagements are public on GitHub, each with a page here that explains how it works.

Where I work

Based in Ontario, Canada. Engagements span Canada and the United States. Federal, provincial, municipal, and private sector. Virtual and on-site. The sectors page lists the government, public safety, critical infrastructure, transportation, and multi-site work.

If you landed here looking for the short answer to "who is this and what do they do," there is a focused entity card at Who is Hans Study?

How the practice works

The person you hire is the person who does the work. That is the whole arrangement, and it is worth stating plainly because it is not how most of this industry operates.

Sole practitioner. Part-time help comes in per engagement when the work needs it, for site walks, configuration pulls, evidence and log collection, device inventories, scheduling, and documentation. That exists so my attention goes to the parts that need it. What never happens is somebody else's judgement being sold under my name. I do the looking, the analysis, and the conclusion, and I am the one you talk to about it.

Practically, that means capacity for multi-site work, without the arrangement where a senior name wins the engagement and a junior delivers it. It also means honesty about availability. If a timeline does not work, you will be told that rather than handed to someone else.

Nothing is sold here except the advice itself. No hardware, no software, no installation, no commissions. The independence policy sets out exactly what that covers and what it costs.

Published elsewhere

Writing and listings on sites I do not control, which is the part that counts.

Connect

For project work and general inquiries, send a note via the contact page or directly to contact@hans.study. For book questions, review copies, errata, or bulk orders, use book@hans.study. For media, podcast, and speaking inquiries, reach out at media@hans.study. Mentorship is free and time-permitting; the form on the mentorship page is the right starting point for that.

ORCID iD: 0009-0000-5322-5033