<p class="wp-block-paragraph">I take on a small number of advisory engagements alongside the research and writing on this site. The work sits where security, infrastructure, and compliance meet: the SOC 2 that has to pass this quarter, the customer DPA that promises things your platform doesn’t do yet, the Kubernetes cluster the auditor flagged. I’ve spent 20+ years building that layer, and I hold a Master of Laws, so the audit finding and the contract clause land on the same desk. Mine.</p>
<p class="wp-block-paragraph">These engagements fit companies where security has become a revenue or liability problem: a regulated SaaS heading into its first SOC 2 or ISO 27001 cycle, an enterprise deal stuck on a security questionnaire, a platform carrying commitments nobody has mapped against reality, a migration that cannot fail. I work with founders, general counsel, and boards. If your question is which endpoint agent to buy, I’m the wrong person. If your question is who signs, who’s liable, and whether the infrastructure can back the promise, that’s the work.</p>
<h2 class="wp-block-heading">Audit-Readiness & Liability Diagnostic</h2>
<p class="wp-block-paragraph">A fixed-fee, three-week review with a hard edge: not just whether your controls would satisfy an auditor, but whether the security promises already sitting in your customer contracts are ones your platform actually keeps. You get a findings register an engineer can execute without a translator, a map of contractual commitments against real controls, and a short memo written for the board rather than the ticket queue. Some of these engagements end there, and the diagnostic is priced to stand alone. Others convert into the retainer below once the gaps have owners.</p>
<h2 class="wp-block-heading">Fractional CISO</h2>
<p class="wp-block-paragraph">Ongoing security leadership for companies that need the executive but not the full-time hire. I own the roadmap, run the audit relationship, answer the customer security questionnaires, work the DPAs alongside your counsel, and report to the board in language a board can act on. The difference from the usual vCISO arrangement is that I stay close enough to the engineering to fix what I flag. Policy on Monday, cluster on Tuesday. Monthly retainer, scope in writing.</p>
<h2 class="wp-block-heading">Migration & Sovereign Infrastructure</h2>
<p class="wp-block-paragraph">Scoped engagements for the moves that cannot fail: zero-downtime platform and database migrations, multi-region routing and failover design, sovereign and air-gapped environments, CMMC readiness for defense suppliers. It’s the same discipline documented across <a href="https://vkafed.com/writing/">the writing here</a>, applied to your topology and your constraints. Priced against what downtime costs you, not against a day rate.</p>
<h2 class="wp-block-heading">How an engagement starts</h2>
<p class="wp-block-paragraph">Message me on <a href="https://www.linkedin.com/in/vkafed/">LinkedIn</a> or use the <a href="https://vkafed.com/contact/">contact page</a>. We take a short call so I can hear the actual problem. If it’s a fit, you get a written proposal with a fixed scope, a timeline, and a number. If I’m not the right person for it, I’ll say so and, where I can, point you at someone better. I keep the client list short on purpose; the research stays half the job.</p>
I take on a small number of advisory engagements alongside the research and writing on this site. The work sits where security, infrastructure, and compliance meet: the SOC 2 that has to pass this quarter, the customer DPA that promises things your platform doesn’t do yet, the Kubernetes cluster the auditor flagged. I’ve spent 20+ years building that layer, and I hold a Master of Laws, so the audit finding and the contract clause land on the same desk. Mine.
These engagements fit companies where security has become a revenue or liability problem: a regulated SaaS heading into its first SOC 2 or ISO 27001 cycle, an enterprise deal stuck on a security questionnaire, a platform carrying commitments nobody has mapped against reality, a migration that cannot fail. I work with founders, general counsel, and boards. If your question is which endpoint agent to buy, I’m the wrong person. If your question is who signs, who’s liable, and whether the infrastructure can back the promise, that’s the work.
Audit-Readiness & Liability Diagnostic
A fixed-fee, three-week review with a hard edge: not just whether your controls would satisfy an auditor, but whether the security promises already sitting in your customer contracts are ones your platform actually keeps. You get a findings register an engineer can execute without a translator, a map of contractual commitments against real controls, and a short memo written for the board rather than the ticket queue. Some of these engagements end there, and the diagnostic is priced to stand alone. Others convert into the retainer below once the gaps have owners.
Fractional CISO
Ongoing security leadership for companies that need the executive but not the full-time hire. I own the roadmap, run the audit relationship, answer the customer security questionnaires, work the DPAs alongside your counsel, and report to the board in language a board can act on. The difference from the usual vCISO arrangement is that I stay close enough to the engineering to fix what I flag. Policy on Monday, cluster on Tuesday. Monthly retainer, scope in writing.
Migration & Sovereign Infrastructure
Scoped engagements for the moves that cannot fail: zero-downtime platform and database migrations, multi-region routing and failover design, sovereign and air-gapped environments, CMMC readiness for defense suppliers. It’s the same discipline documented across the writing here, applied to your topology and your constraints. Priced against what downtime costs you, not against a day rate.
How an engagement starts
Message me on LinkedIn or use the contact page. We take a short call so I can hear the actual problem. If it’s a fit, you get a written proposal with a fixed scope, a timeline, and a number. If I’m not the right person for it, I’ll say so and, where I can, point you at someone better. I keep the client list short on purpose; the research stays half the job.