A crannog, an ancient island dwelling, on a still lake at dawn

Independent cyber advisory & vCISO

Are you protecting your business against the cyber risks that actually matter?

Crannog provides the independent assurance layer between security activity and business risk. Senior judgement, not another layer of reporting.

Independent assurance. Senior judgement. Focused on what matters to your business.

Why independent assurance

Cybersecurity is rarely a blank-sheet problem

Most organisations already spend — but several pressures make assurance increasingly important.

Business risk

Could a cyber incident materially disrupt operations, cause financial loss or expose critical information?

Customer & supply chain

Can you demonstrate appropriate security to major customers, partners and the organisations whose supply chain you support?

Regulation & compliance

Can you show that cyber controls and governance meet regulatory, contractual and insurance requirements?

Investment effectiveness

Are your existing security investments, MSPs, suppliers and controls focused on the risks that matter most?

The assurance gap

Activity is not the same as assurance

You may already have

  • An MSP / IT provider
  • Microsoft security & endpoint controls
  • Backups, firewalls and cyber insurance
  • Policies, training and compliance activity

But can management answer

  • What are our material cyber risks?
  • Which controls and suppliers address them?
  • Where are the important gaps?
  • Are we spending on the right things?
  • What should we do first?

What Crannog does

Start with the business outcome, then use evidence, controls and frameworks to support the answer

01

Understand

Critical services, data, dependencies and external obligations.

02

Assure

Assess whether existing controls, suppliers and investments address those risks.

03

Prioritise

Separate material business risk from lower-value technical noise.

04

Advise

Give management clear decisions, actions and investment priorities.

05

Govern

Maintain oversight as the business, threats and obligations change.

Frameworks and tooling are inputs. The product is clearer business risk, better decisions and proportionate action.

The usual starting point

The Cyber Baseline & 90-Day Plan

The foundation of an ongoing vCISO relationship. Includes AI usage / data exposure and OT / industrial environments where relevant.

  1. 01Business & exposure contextWhat could materially hurt the business?
  2. 02Evidence-led control reviewAre current controls and suppliers addressing it?
  3. 03Governance & preparednessWho owns the risk, and are we ready?
  4. 04Material risk prioritisationWhere are the gaps that actually matter?
  5. 05Management action planWhat should we do first — and over the next 12 months?

Partnership levels

Three levels of vCISO partnership

Choose the level of assurance and leadership the business needs.

Essential

Independent Assurance

Know whether the risks that matter are being addressed.

  • Baseline & roadmap
  • Annual risk refresh
  • Key-control assurance
  • Management risk briefing

Managed

Ongoing Cyber Governance

Keep material cyber risk visible, prioritised and under control.

  • Quarterly risk governance
  • Supplier / control assurance
  • Remediation priorities
  • Incident tabletop & reporting

Strategic

Virtual CISO

Bring senior cyber judgement into important business decisions.

  • Regular executive engagement
  • Strategy & investment planning
  • Board-level risk reporting
  • Incident / crisis leadership

Standalone advisory

Focused engagements where a specific business driver or risk needs deeper attention

Cyber Baseline & 90-Day Plan

Independent view of material risk and priorities.

AI Security & Governance Review

Adopt AI while managing data and governance risk.

NIS2 & CyFun Readiness / Assurance

Address regulatory and supply-chain expectations.

Security Tool & Control Assurance

Test whether controls deliver the intended outcome.

Board & Executive Cyber Training

Improve executive understanding and accountability.

M365 / Identity Security Review

Reduce identity-led business risk.

OT / Industrial Cyber Risk Review

Reduce cyber risk to critical operations.

Incident Response Tabletop

Prepare management to decide under pressure.

Security Investment / Vendor Review

Make better security spend and supplier decisions.

Employee Cyber Resilience Training

Strengthen the human layer where it matters.

Principal-led by design

Senior cyber leadership. Directly accessible.

Crannog Cyber Advisory logo

Thomas Parsons

Founder & Principal

25+ years across cybersecurity, technology and leadership. Internationally, including the United States.

Senior cybersecurity and product executive with experience spanning security research, engineering, product strategy, international growth and executive leadership.

Executive & board

Former VP Product Management at Tenable (NASDAQ: TENB); Ireland Site Leader and Board Member of Tenable Ireland. Built and led global teams of up to 100 people.

Global cyber experience

Senior roles across Intel, Symantec and Tenable — identity security, exposure and vulnerability management, EDR, SIEM, security research and AI-enabled security.

Policy & industry influence

OECD and EU policy engagement, including work contributing to OECD Digital Economy Paper No. 307 on vulnerability treatment. Featured in IDA Ireland's Leadership Series.

Research & recognition

Cybersecurity patent holder; contributor to Symantec's Internet Security Threat Report. Quoted by the Wall Street Journal, BBC, CIO Magazine, CNET and ZDNet.

The question is not “how many security activities are we doing?” — it is “are they addressing the business risks that matter?”

Crannog Cyber Advisory logo

Why Crannog?

A crannog was a protected island settlement, used for centuries as a place of security and resilience.

Crannog Cyber takes inspiration from that idea — practical protection, built around what matters most.

PROTECT WHAT MATTERS. BUILD RESILIENCE AROUND IT.

A useful first conversation

What could hurt the business? · What are you already doing? · How do you know it is enough?

advisory@crannogcyber.com