Home / Advisory

Executive Cybersecurity & Risk Advisory

Helping organizations understand cyber risk, strengthen security strategy, achieve compliance, and build sustainable cyber resilience — at the level where the decisions actually get made.

Capability domains

Four domains of capability

Organized by what I can take responsibility for, rather than by tool familiarity. Most engagements draw on more than one.

Cybersecurity Leadership

Setting direction and owning risk at executive and board level — including fractional security leadership where an organization needs the function before it can justify the hire.

Security StrategyExecutive AdvisoryvCISO Cyber Risk ManagementBoard ReportingProgramme Design
GRC & Compliance

Subject-matter expertise in risk-based certification and accreditation. Compliance treated as a structure for governing risk continuously, not a hurdle cleared once a year.

FISMARMF & DoD RMFFedRAMPNIST CSF ISO 27001HIPAAPCI DSSGDPR
Security Engineering

The technical substance beneath the advice — architecture, exposure management, and readiness for the day prevention fails.

Zero Trust ArchitectureCloud SecurityVulnerability Management Identity & AccessIncident ReadinessSecurity Architecture
Strategic Domains

Sectors where the consequences of failure are borne by people rather than balance sheets — health data, nonprofit operations, and the digital systems institutions increasingly depend on.

Health InformaticsNonprofit SecurityDigital Trust Cyber ResilienceEmerging Technology RiskGovernance
Advisory services

Where the writing meets the work

Each service corresponds to a published title. The books are not marketing material — they are the method, written down.

Executive & vCISO Advisory

Cybersecurity strategy and risk management at board level — establishing what is genuinely material, where investment should go first, and how oversight holds together over time. Also available as fractional security leadership.

Mapped title
Cybersecurity Strategy and Risk Management
View book

Federal Compliance Advisory

FISMA, RMF and FedRAMP navigated as a practical sequence rather than a documentation exercise — authorization, control selection, evidence, and the reporting that survives audit.

Mapped title
Practical FISMA‑RMF‑FedRAMP
View book

Zero Trust Advisory

Zero Trust as an architecture and a sequencing problem, not a product purchase — identity, segmentation, and verification designed for what a federal or enterprise environment can realistically absorb.

Mapped title
Zero Trust for Federal and Enterprise Leaders
View book

Security Architecture Services

Designing and reviewing the control points that determine whether security holds under pressure — across on‑premises, cloud and hybrid environments, including the seams between them.

Mapped title
Security Gate
View book

Vulnerability Management Advisory

Turning scan output into a defensible programme: finding real exposure, prioritising by consequence rather than severity score, tracking remediation, and proving improvement over time.

Mapped title
Vulnerability Management Handbook
View book

Security Operations Advisory

Practical guidance for security officers and operations teams — incident handling, monitoring, documentation and the day-to-day authorization work that keeps systems defensible.

Mapped title
The ISSO Field Guide
View book

Emerging Technology Risk Advisory

Looking further ahead than the last incident — which cyber, AI and technology risks are likely to become material over the next one to three years, and what is worth starting now.

Mapped title
Security Frontier
View book

Awareness & Executive Education

Challenging the assumptions leaders inherit about cyber risk. Delivered as executive briefings, workshops and keynotes for audiences who need clarity rather than alarm.

Mapped title
The Big Lies About Cybersecurity
View book
How engagements work

From conversation to measurable change

No two organizations arrive at the same point, but the shape of the work is usually consistent.

01
Understand
What the organization does, what it depends on, and what would genuinely hurt if it failed.
02
Assess
An honest read on current posture — exposure, governance, compliance position and capability gaps.
03
Prioritise
A defensible sequence — what to do first, what can wait, and what the trade-offs actually are.
04
Sustain
Capability that outlasts the engagement, so the organization is not dependent on an outside adviser indefinitely.
Frameworks

The standards I work within

Knowing a framework is not the same as knowing how to make an institution genuinely defensible under it.

FISMA
Federal information security management and reporting.
RMF & DoD RMF
Risk Management Framework, including defence implementations.
FedRAMP
Authorization for cloud services in federal use.
NIST CSF
Cybersecurity Framework for organizational risk management.
ISO 27001
International information security management standard.
HIPAA
Protected health information security and privacy.
PCI DSS
Payment card data security requirements.
GDPR & DIACAP
Data protection regulation and legacy accreditation.
Delivery

Delivered through Lausey Technology

Lausey Technology is the commercial cybersecurity advisory and risk management firm I founded. Where an engagement needs a delivery organization — assessments, implementation, GRC programmes, vulnerability management or sustained capability building — the work is carried out through Lausey.

Executive Cybersecurity Guidance
Measurable Risk Reduction
Sustainable Capability
Visit Lausey Technology →
Dr. Yawo O. Kondo — Lausey Technology

Let's discuss your cybersecurity challenge

Most conversations start with one problem and quickly surface three others. Tell me where things stand and we can work out what needs attention first.