// SECURITY LEADERSHIP, ADVISORY, AND STRATEGY · HANS STUDY · ONTARIO, CANADA
Security Leadership, Advisory, and Strategy
Most organizations don't need a full-time CISO. They need senior security judgement they can reach when a decision matters, a strategy that fits their risk and their budget, and one person who's accountable for seeing it through. That's the work. Independent, with nothing to sell you but the advice.
I act as a fractional CISO, security advisor, and strategist for regulated and operationally complex organizations: defence suppliers, critical infrastructure, public safety, and the operators who serve them. Strategy and governance, risk and compliance, framework alignment, vendor and third-party risk, and the board-level translation that turns a technical problem into a decision your leadership can actually make. The kind of leadership that usually means a quarter-million-dollar hire, sized instead to a few days a month.
I work remotely, which means location isn't a constraint. Most of this is done over a call and a shared screen, with on-site time when an assessment or a build calls for it. I'm based in Ontario and take engagements across Canada and the United States.
2 things set this apart from a conventional advisor. The first is defence supply chain compliance. I was doing NIST 800-171 and CMMC readiness in 2019 and 2020, and Canada's new CPCSC runs on the same technical baseline, so it's familiar ground rather than a framework I'm reading up on. The second is the boundary where operational technology, IT, and physical security meet. That's where a lot of real exposure hides, and it's rarely where a pure-IT advisor thinks to look.
Where to start
Fractional CISO and vCISO →
Senior security leadership on a recurring basis, sized to your stage and budget.
Security and technology strategy →
A roadmap, an architecture direction, and a risk-based plan your board can act on.
CMMC and CPCSC readiness →
Scoping, gap assessment, and attestation support for Canadian and cross-border defence suppliers.
OT/IT convergence security →
The physical, OT, and IT boundary, assessed and secured by someone who reads both sides.
Security consulting and assessments →
Independent assessments, architecture, network hardening, and project oversight.
Independent. Vendor-agnostic. No reseller agreements and no kickbacks, so a recommendation is a recommendation, not a quote in disguise.
A straight read on where you stand
Start with a 30-minute scoping call or email contact@hans.study. You'll get a straight read on where you stand and an honest answer on whether I'm the right fit.
Start a conversation