// GREATER TORONTO AREA · ENTERPRISE, HEALTHCARE, CRITICAL INFRASTRUCTURE · HANS STUDY

Security Leadership and Advisory for the Greater Toronto Area

The Greater Toronto Area runs on the kind of systems I spend my time securing. Hospital networks bound by PHIPA, transit and infrastructure operators, utilities, manufacturers, and a dense layer of enterprises whose risk sits as much in their buildings as in their data centres. It's also wall-to-wall converged environments where the cameras, the access control, the building systems, and the corporate network share infrastructure that nobody owns end to end.

I provide fractional CISO leadership, security strategy, and assessments to organizations across the Greater Toronto Area and the wider Toronto region. Most of the work runs remotely, over a call and a shared screen, with on-site time for assessments and walkthroughs, which is straightforward since I'm based in Ontario.

Where I add the most value here is the overlap of convergence and compliance:

  • Health networks carrying PHIPA obligations on top of building and clinical systems that were never segmented properly
  • Manufacturers and defence-adjacent suppliers now facing CPCSC, with the same NIST 800-171 baseline I've worked since 2019
  • Transit, utility, and infrastructure operators with OT and physical security riding the same networks as the business
  • Enterprises whose cyber-insurance renewal or client security review just turned "we should have a CISO" into "we need one now"

A health network worried about PHIPA and a flat building-systems network has the same root problem as a Toronto manufacturer facing CPCSC: exposure at the boundary between physical, OT, and IT, and a framework someone now expects them to satisfy. If you're a Greater Toronto Area organization that needs senior security judgement without a full-time hire, start with a scoping call or email contact@hans.study.

Where to start

Fractional CISO and vCISO →

Senior security leadership on a recurring basis, sized to your stage and budget.

OT/IT and Physical Security Convergence →

The boundary where the buildings and the data centre share a network nobody owns end to end.

Security Leadership, Advisory, and Strategy →

The full advisory practice: strategy, compliance, convergence, and consulting.

Senior security judgement, without the full-time hire

Start with a 30-minute scoping call or email contact@hans.study.

Start a conversation