Business risk
Could a cyber incident materially disrupt operations, cause financial loss or expose critical information?

Independent cyber advisory & vCISO
Crannog provides the independent assurance layer between security activity and business risk. Senior judgement, not another layer of reporting.
Independent assurance. Senior judgement. Focused on what matters to your business.
Why independent assurance
Most organisations already spend — but several pressures make assurance increasingly important.
Could a cyber incident materially disrupt operations, cause financial loss or expose critical information?
Can you demonstrate appropriate security to major customers, partners and the organisations whose supply chain you support?
Can you show that cyber controls and governance meet regulatory, contractual and insurance requirements?
Are your existing security investments, MSPs, suppliers and controls focused on the risks that matter most?
The assurance gap
What Crannog does
Critical services, data, dependencies and external obligations.
Assess whether existing controls, suppliers and investments address those risks.
Separate material business risk from lower-value technical noise.
Give management clear decisions, actions and investment priorities.
Maintain oversight as the business, threats and obligations change.
Frameworks and tooling are inputs. The product is clearer business risk, better decisions and proportionate action.
The usual starting point
The foundation of an ongoing vCISO relationship. Includes AI usage / data exposure and OT / industrial environments where relevant.
Partnership levels
Choose the level of assurance and leadership the business needs.
Essential
Know whether the risks that matter are being addressed.
Managed
Keep material cyber risk visible, prioritised and under control.
Strategic
Bring senior cyber judgement into important business decisions.
Standalone advisory
Independent view of material risk and priorities.
Adopt AI while managing data and governance risk.
Address regulatory and supply-chain expectations.
Test whether controls deliver the intended outcome.
Improve executive understanding and accountability.
Reduce identity-led business risk.
Reduce cyber risk to critical operations.
Prepare management to decide under pressure.
Make better security spend and supplier decisions.
Strengthen the human layer where it matters.
Principal-led by design

Founder & Principal
25+ years across cybersecurity, technology and leadership. Internationally, including the United States.
Senior cybersecurity and product executive with experience spanning security research, engineering, product strategy, international growth and executive leadership.
Former VP Product Management at Tenable (NASDAQ: TENB); Ireland Site Leader and Board Member of Tenable Ireland. Built and led global teams of up to 100 people.
Senior roles across Intel, Symantec and Tenable — identity security, exposure and vulnerability management, EDR, SIEM, security research and AI-enabled security.
OECD and EU policy engagement, including work contributing to OECD Digital Economy Paper No. 307 on vulnerability treatment. Featured in IDA Ireland's Leadership Series.
Cybersecurity patent holder; contributor to Symantec's Internet Security Threat Report. Quoted by the Wall Street Journal, BBC, CIO Magazine, CNET and ZDNet.
The question is not “how many security activities are we doing?” — it is “are they addressing the business risks that matter?”

Why Crannog?
A crannog was a protected island settlement, used for centuries as a place of security and resilience.
Crannog Cyber takes inspiration from that idea — practical protection, built around what matters most.
PROTECT WHAT MATTERS. BUILD RESILIENCE AROUND IT.
What could hurt the business? · What are you already doing? · How do you know it is enough?
advisory@crannogcyber.com