Services

What I can help with

Two practice areas that keep meeting each other: securing the systems an organisation already runs, and putting AI to work inside them without opening new risk. Below is what that looks like concretely.

Cybersecurity

Application security and security architecture

For organisations that build or heavily customise their own systems

  • Security architecture review for IT systems and integrations
  • Threat modelling of applications and their surrounding environment
  • Risk-based prioritisation — what to fix first, and what can wait
  • Identity and access: authentication and authorisation design

You end up with a documented picture of where the real exposure is, and a prioritised list your development and operations teams can actually work through.

DevSecOps — security inside the delivery pipeline

For development organisations that want security built in, not bolted on

  • Establishing and integrating security controls in CI/CD
  • Secure development workflows in Git and GitHub
  • Code scanning and vulnerability management (GitHub Advanced Security, Azure DevOps)
  • Making findings actionable so they get fixed rather than accumulated

You end up with security checks running automatically on every change, and a process for handling what they find.

Security for production and OT environments

For manufacturing organisations with production-critical systems

  • Securing Manufacturing Execution Systems (MES) in production-near IT/OT environments
  • Authentication and authorisation for production systems
  • Business Impact Analysis for critical systems
  • Working within the constraint that production cannot simply be stopped

You end up with security measures that hold up in an environment where availability is the first requirement, not an afterthought.

Security operating model

For organisations where security work has no clear owner

  • How security should be worked with day to day, described concretely
  • Roles and responsibilities from a Security Champions perspective
  • Fitting security into an agile way of working rather than beside it
  • Cross-functional collaboration between development, operations and the business

You end up with a model that says who does what, so security stops depending on individual goodwill.

Security strategy and roadmap

For management teams that need a defensible plan, not a wish list

  • Multi-year security roadmaps prioritised by risk
  • Translating regulatory requirements into concrete initiatives
  • Sequencing work against budget and delivery capacity

You end up with a plan you can take to a board and to the people who have to execute it.

Standards and regulation in practice

For organisations facing NIS2, CRA or a certification requirement

  • ISO 27001 and ISO 27002 — what the requirements mean for your systems
  • NIS2 and the Cybersecurity Act
  • The Cyber Resilience Act (CRA) for organisations that ship products with software
  • ISO/IEC 42001 — management systems for AI

You end up with a clear reading of what applies to you and what has to change, separated from what doesn't.

Artificial intelligence

AI agents for information retrieval and decision support

For organisations whose knowledge is buried in documents nobody can find

  • Design and implementation of AI agents (including Copilot Studio)
  • Making large document collections searchable in plain language
  • Agents that support decisions rather than replace them
  • Fitting the agent into the tools people already use

You end up with a working agent your people actually use, not a pilot that stalls after the demo.

AI governance and safe adoption

For organisations deciding how far to let AI into their operations

  • ISO/IEC 42001 as a frame for managing AI use
  • What to allow, on which data, and under what controls
  • The security questions AI adoption raises — asked before rollout, not after

You end up with a position you can defend internally and to a regulator, and rules your teams can follow.

Also available

Project management

Complex IT projects from upgrades to new platform implementations, with budgets ranging from 0.5 to 23 MSEK.

Agile leadership

Scrum master and team lead work, and change initiatives tied to ways of working and process.

Development

Full-stack development experience, useful when a security recommendation has to be implementable by the team receiving it.

Practical

How I can be engaged

Fixed-scope assignment

An assessment, a roadmap, an operating model — agreed scope, agreed deliverable.

Ongoing advisory

Available on a recurring basis to the people who own security or AI decisions.

Interim role

Embedded as security lead or project manager for the duration of an initiative.

Depending on the scope and complexity of the engagement, I can offer flexible pricing options to suit your needs.

Questions

Before you get in touch

Do you work remotely or on site?
Both. I'm based in Sandviken and travel for work that needs to happen on site — production environments usually do.
What size of organisation do you work with?
I work with organisations of all sizes, from small startups to large enterprises.
Can you work alongside our existing IT supplier?
Yes, I can work alongside your existing IT supplier to ensure seamless integration and collaboration.
How do you handle confidentiality?
I take confidentiality seriously and will not disclose any information shared with me without explicit permission.
Do you work in Swedish or English?
Both. I'm fluent in both languages and can communicate effectively in either.

Tell me what you're dealing with

Describe the situation and I'll tell you whether I can help. I reply within [X business days].

Get in touch