Who I work with

Built for startups selling into regulated markets

The common thread across my clients: a Canadian company, seed through Series B, whose customers are in the world’s most regulated and security-sensitive industries — in Canada, the US, the EU, and the UK.

Healthtech

My deepest vertical — I was CISO at Thrive Health and work with HeadCheck Health today. If you’re selling into hospitals, health systems, or public health, you already know the procurement bar: PHIPA and provincial privacy law at home, HIPAA the moment a US health system signs, and security reviews that assume you’ve done this before.

I’ve sat on the vendor side of those reviews and passed them. That experience transfers directly.

Fintech

Financial institutions run the most demanding vendor security programs in the private sector. SOC 2 is table stakes; after that come the bespoke questionnaires, the on-site (or on-call) assessments, and — if you’re selling into EU financial firms — DORA’s operational-resilience requirements landing on you as a critical vendor. The work is making your program legible to a bank’s third-party-risk team.

B2B SaaS selling to enterprise & government

The moment your first enterprise or public-sector deal appears, security becomes a sales function: questionnaires, SOC 2 or ISO 27001 as a contract condition, data-residency questions, public-sector procurement requirements. Companies like Dooly and Readymode work with me to keep that machinery from slowing revenue down.

A note on fit

The best engagements share a mindset, not just a stage: leadership that sees security as part of how the company wins deals and earns trust — and wants a real program, built honestly, at a sensible pace.

And to be equally honest about the other side: if what you want is a certificate on the wall with nothing behind it, I’m not the right fit — and I’ll tell you so on the first call.

Sound like your company?

The next step is a 30-minute conversation — no pitch, no obligation. An honest read on where you stand and what actually matters next.