Cybersecurity Advisory, AI Governance & Speaking
CLEAR SCOPE · NAMED OUTCOMES
Defined engagements
Fixed scope, fixed duration, named deliverables.
Microsoft Sentinel → Defender Portal Readiness Assessment
For: enterprises and Microsoft partners running Sentinel in the Azure portal.
Why now: Azure portal support for Microsoft Sentinel ends 31 March 2027. Moving to the Defender portal can affect RBAC, incident correlation, automation, API integrations, and analyst workflows; each requires deliberate validation.
Duration: 3–4 weeks.
You receive: a prioritized impact register; a phased transition plan with named owners; validation criteria for each workstream; and a go/no-go evidence table leadership can sign.
Read the Sentinel transition guide →
DISCUSS A READINESS ASSESSMENTAI Agent Authority Review
For: organizations putting autonomous AI agents into production.
Why now: a 2026 Cloud Security Alliance survey found that only 28% of respondents could reliably trace agent actions to a human or system across all environments. Most organizations have not tested what their containment action actually stops.
Duration: 3–4 weeks.
You receive: an agent-registry gap list; an exposure-ranked inventory; a telemetry coverage map; and tested containment procedures with kill-switch and rollback results.
Read the AI agent identity research →
DISCUSS AN AGENT AUTHORITY REVIEWSOC & Detection Assurance Review
For: security leaders who want evidence that their detections work against their threat model.
Duration: 4–6 weeks.
You receive: detection coverage mapped to your threat model; a telemetry gap analysis; control-validation results; and a prioritized remediation plan with owners and effort estimates.
Read the containment assurance research →
DISCUSS A DETECTION ASSURANCE REVIEWCyber Risk Quantification & Investment Readiness Assessment
For: CISOs and security leaders preparing a funding, risk-appetite, control, or board-reporting decision.
Duration: 3–5 weeks.
You receive: prioritized loss scenarios; an evidence and assumption register; risk-appetite tests; control and investment comparisons; an executive decision statement; and a roadmap with named owners.
Explore the Cyber P&L framework →
DISCUSS A CYBER RISK ASSESSMENTMicrosoft deadline source · Cloud Security Alliance survey source
Cybersecurity, AI Governance, Speaking & Education
Ways to Work With Jessen

Security Operations, SOC & MSSP Advisory
I assess and strengthen internal, outsourced, and hybrid security operations: operating models, roles and escalation paths, incident command, detection coverage, KPI and KRI dashboards, technology strategy, and analyst enablement.

Incident Response & Executive Readiness
I prepare leaders and security teams to run a serious incident: readiness reviews, response plans, tabletop exercises, incident command structures, executive communication, recovery guidance, and post-incident improvement.

Detection Engineering & Threat-Informed Cyber Defense
I strengthen multi-vendor SIEM, XDR, EDR, and AI-enabled operations through security analytics, telemetry strategy, detection engineering, continuous control validation, threat hunting, SOAR automation, and analyst-workflow design. This includes responsible AI-assisted investigation and monitoring for AI applications, autonomous agents, and non-human identities.

Enterprise Vulnerability & Exposure Management
I build risk-based programs that reduce exposure across infrastructure, cloud, applications, and networks: prioritization models, remediation governance, EASM, attack-path analysis, dashboards, executive reporting, and coordination with the technical owners who have to do the work.

AI Governance, Cyber Risk & Compliance (GRC)
I connect security operations to enterprise and AI risk: ISO/IEC 42001 Artificial Intelligence Management System readiness, AI inventories, risk and impact assessments, governance roles, policies and controls, human oversight, audit-ready evidence, and executive reporting.

Speaking, Workshops & Cybersecurity Education
I deliver keynotes, executive briefings, workshops, university sessions, and community conversations built for the audience in the room. Topics include cyber resilience, incident leadership, AI and cybersecurity, digital safety, security careers, and translating cyber risk into business decisions.
ENGAGEMENT MODEL
How I engage
I work on fixed-scope assessments and ongoing advisory retainers. I also support Microsoft partners, MSSPs, and consultancies as senior delivery capacity under agreed subcontracting arrangements.
START A CONVERSATION
Why Work With Me
Strategy leaders can act on. Guidance teams can use.
I have contributed detections to products used by defenders and led security operations teams responsible for making those detections work during real incidents. I trace readiness across the full operating chain—telemetry, detection logic, analyst workflow, automation, and decision authority—and validate where it can fail under pressure.
Every assessment is designed to produce evidence that the operating model works in practice.
Related practical guidance: securing AI agents and non-human identities, pre-authorized containment and incident readiness, and Microsoft Sentinel transition validation.
- Business and Security Alignment: Translate technical risk into priorities leaders and teams can act on.
- Independent Perspective: Provide objective guidance shaped by your environment—not by a product sales agenda.
- Enterprise-Aware Approach: Design recommendations around operational complexity, business needs, and real-world constraints.
- Clear Outcomes: Establish focused priorities, measurable progress, and transparent communication.
- Lasting Capability: Strengthen the people, processes, and decision-making that remain after the engagement ends.