Expertise
Four domains. One security mission.
My expertise is structured around the areas where future digital risk is becoming operational reality: quantum technologies, AI, digital investigation and cyber resilience.
* 1. Post-Quantum Security
I work on the transition from current public-key cryptography to quantum-resistant security models. This includes post-quantum cryptography, crypto-agility, quantum-safe identity, quantum communication infrastructure and the strategic risk of collect-now-decrypt-later attacks.
- Post-quantum cryptography readiness
- Crypto-agility and migration planning
- Quantum Key Distribution and quantum communication infrastructure
- Quantum-safe identity and trust services
- EuroQCI, Lat–LitQN and PIONIER-Q-SAT related work
* 2. AI Security Governance
AI adoption creates new security, accountability and resilience problems. My work in this area focuses on helping organizations understand and govern AI-related risks before they become uncontrolled operational dependencies.
- CARI — CISO AI Readiness Index
- CAISO — Chief Artificial Intelligence Security Officer concept development
- AI security governance and accountability structures
- AI-related cyber risk assessment
- Executive-level readiness for AI-enabled threats
* 3. Digital Forensics
Digital forensics is the bridge between technical evidence, investigation logic and defensible decision-making. My work covers cybercrime investigation, digital evidence models, OSINT and incident reconstruction.
- Cybercrime investigation and digital evidence
- Forensic readiness for organizations
- OSINT and evidence-based analysis
- Incident reconstruction and investigative workflows
- Digital evidence object models and forensic methodology
* 4. Cyber Resilience
Cyber resilience is not only a technical state. It is the ability of an organization to anticipate, absorb, respond to and recover from digital disruption while protecting trust and continuity.
- Security governance and risk management
- Critical infrastructure protection
- NIS2, DORA and regulatory readiness
- SOC maturity and incident response capability
- Executive education and cyber decision-making