Tom Smith
Tom Smith

About

I'm Tom. I have spent more than twenty years keeping businesses secure.

I work with growing businesses that have reached the point where security clearly matters and no one inside the company owns it.

That situation is more common than it sounds. The business has grown, it depends on technology for nearly everything, and customers or insurers have started asking questions that are difficult to answer. There is usually an IT provider doing capable work, but nobody whose job is to step back and decide what the business should be doing about security, and in what order.

This practice exists because the usual options do not fit that situation. A full-time security leader is more than most growing businesses need or can justify. Product vendors answer a narrower question than the one being asked. What is actually needed is someone experienced to look at the whole picture and help you decide what matters.

Background

Much of my career has been spent as the sole security and systems lead for a group of affiliated operating companies, responsible for everything from the systems people used every day to the security decisions nobody else was going to make. I have handled real incidents, not only planned for them.

That shapes how I advise. It is straightforward to recommend good security when someone else has to find the time and money for it. Having made those calls myself, with a limited budget, a small team, and a business that had to keep running while security improved, keeps my advice grounded in what can actually be done.

Certifications

CISSP, CISM, CDPSE, and PMP. They are worth stating plainly because they show the work has been measured against a standard. Judgment matters more than any of them, and no certification demonstrates that on its own.

What makes this different

Most security advice fails for one of two reasons. It is either too generic to act on, or it is written for an organization ten times the size of yours. Useful advice depends on knowing which parts of a framework apply to a smaller business and which parts can wait until you are much larger.

So the work is practical. Recommendations come with an order, a reason, and a realistic sense of effort. I explain them in language your leadership team can follow, because a recommendation nobody understands is a recommendation nobody funds. And because I work on both sides of this, the business side and the technical side, I can talk to your IT provider and your leadership team without either conversation getting lost.

I am not here to sell you software, and I am not going to scare you into a retainer. The goal is a business that knows where it stands, has a plan it believes in, and can explain both to anyone who asks.

Join the newsletter

Subscribe and I will send you the checklist: The Security Questions Every Growing Business Should Be Able to Answer. It is a self-scoring readiness check: you work through the questions, score yourself, and come away with a clear picture of where your business actually stands.

One email a week with practical security guidance for growing businesses. No sales pitches. Unsubscribe at any time, and your address goes nowhere else.