// SECURITY LEADERSHIP, ADVISORY, AND STRATEGY · HANS STUDY · ONTARIO, CANADA

Security Leadership, Advisory, and Strategy

Most organizations don't need a full-time CISO. They need senior security judgement they can reach when a decision matters, a strategy that fits their risk and their budget, and one person who's accountable for seeing it through. That's the work. Independent, with nothing to sell you but the advice.

I act as a fractional CISO, security advisor, and strategist for regulated and operationally complex organizations: defence suppliers, critical infrastructure, public safety, and the operators who serve them. Strategy and governance, risk and compliance, framework alignment, vendor and third-party risk, and the board-level translation that turns a technical problem into a decision your leadership can actually make. The kind of leadership that usually means a quarter-million-dollar hire, sized instead to a few days a month.

I work remotely, which means location isn't a constraint. Most of this is done over a call and a shared screen, with on-site time when an assessment or a build calls for it. I'm based in Ontario and take engagements across Canada and the United States.

2 things set this apart from a conventional advisor. The first is defence supply chain compliance. I was doing NIST 800-171 and CMMC readiness in 2019 and 2020, and Canada's new CPCSC runs on the same technical baseline, so it's familiar ground rather than a framework I'm reading up on. The second is the boundary where operational technology, IT, and physical security meet. That's where a lot of real exposure hides, and it's rarely where a pure-IT advisor thinks to look.

Where to start

Fractional CISO and vCISO →

Senior security leadership on a recurring basis, sized to your stage and budget.

Security and technology strategy →

A roadmap, an architecture direction, and a risk-based plan your board can act on.

CMMC and CPCSC readiness →

Scoping, gap assessment, and attestation support for Canadian and cross-border defence suppliers.

OT/IT convergence security →

The physical, OT, and IT boundary, assessed and secured by someone who reads both sides.

Security consulting and assessments →

Independent assessments, architecture, network hardening, and project oversight.

Independent. Vendor-agnostic. No reseller agreements and no kickbacks, so a recommendation is a recommendation, not a quote in disguise.

A straight read on where you stand

Start with a 30-minute scoping call or email contact@hans.study. You'll get a straight read on where you stand and an honest answer on whether I'm the right fit.

Start a conversation