Executive Advisory · Security & AI

Executive counsel on security, AI, and the strategy around them.

Soteric Cyber LLC is an independent advisory practice. I work with executives and boards on where to take security and AI, what to fund, and in what order — bringing a CISSP and 26 years across program management, engineering, and cybersecurity to decisions that are hard to reverse.

Taking on a limited number of engagements Remote-first · U.S. based
Soteric Cyber shield logo
Areas of work

Where I add the most value

Engagements are advisory: strategy, planning, governance, and the judgement calls that sit above delivery. Each one ends with something a leadership team can act on — a decision, a sequenced plan, and a defensible rationale for both.

Executive & Board Advisory

Security leadership at the altitude decisions get made. Shaping the strategy, framing the risk for people who control the budget, and standing behind it in the room.

  • Fractional CISO and security leadership
  • Board and executive reporting
  • Risk framing and investment cases
  • Customer and diligence conversations

Strategy, Roadmaps & Program Planning

Turning intent into a sequenced, funded plan — and the programme structure to run it. Twenty-six years of program management behind the estimates.

  • Multi-year security and technology roadmaps
  • Program and project planning, scope and sequencing
  • Milestones, dependencies, and resource plans
  • Governance cadence and executive reporting

Business Strategy & Capture

Positioning the business to win the work, and getting through the security questions that decide whether you do. Useful when security is a gate on revenue.

  • Capture strategy and bid / no-bid judgement
  • Proposal and solution positioning
  • Compliance posture as a competitive position
  • Customer security questionnaires and diligence
Where the two meet

Security and AI, from one advisor

Companies are committing to copilots, agents, and model-backed products faster than their governance was designed to handle, and the standard checklist has little to say about prompt injection, over-permissioned agents, or training data that quietly became a retention problem.

Covering both sides is deliberate. You get one position to take to the board rather than a security opinion and an AI opinion that have to be reconciled afterwards.

  • Shadow AI discovery — what the team is already pasting into public tools.
  • Workable guardrails — approved tools, data classes, and review paths people will follow.
  • Risk framing for LLMs — prompt injection, tool abuse, data exfiltration, agent blast radius.
  • Vendor AI review — what your SaaS vendors do with your data once "AI features" arrive.
  • Framing for leadership — the risk described in terms they can act on.
How it works

How engagements run

There is no long discovery phase before you learn anything. The early sessions are aimed at giving leadership a working picture of the position quickly.

Understand

A working session on what the business does, what would hurt most if it broke, what is already in place, and what leadership is being asked to decide.

Assess

A review of posture, programme, and AI exposure against a framework sized to your organisation — read at the level executives need it.

Prioritize

A readout ranked by risk, effort, and cost, with the handful of things worth funding first called out plainly.

Plan

A sequenced roadmap with milestones, dependencies, and the resourcing behind it — something you can fund and hold people to.

Guide

Steering the teams and vendors doing the work: reviewing designs and decisions, and keeping the programme honest against the plan.

Sustain

A standing advisory relationship as things change — new products, new vendors, new models, new regulations.

Getting started

If any of this is close to what you need, send a short note about the business and what is prompting the conversation. If it isn't a good fit, I'll say so and point you somewhere better.