SC Cleared · Regulated Environments · CNI Experienced

Cyber SecurityConsultant

CNI  ·  GRC  ·  Cloud Security

I help regulated organisations build defensible security postures — from board-level strategy to technical implementation across Cloud, M365, and critical infrastructure environments.

Audit-ready GovernanceAudit & M365 AssuranceAI Security GovernanceSupply chain RiskBoard-level advisorySecure by DesignIncident readinessSecurity ArchitectureOT Security3rd Party Risk Management
20+
Years Experience
CNI
Nuclear + Oil & Gas
SC
Security Cleared
Cybersecurity operations centre with compliance dashboards for Cyber Essentials, ISO 27001 and NIST CSF

Cyber Security Consultant

All organisations face a growing gap between compliance obligations and operational security reality. I bridge that gap — providing independent consultancy across cloud security, GRC, and critical national infrastructure.

Cloud Security Architecture

Independent assurance of Azure and M365 environments — from secure configuration and identity governance to Defender suite optimisation and AI security controls.

GRC

Building governance frameworks that produce defensible, auditable security postures — not paper compliance. Risk registers, policy architecture, and control validation that hold under external scrutiny.

Critical infrastructure assurance

Independent security assurance for nuclear, electricity, and oil & gas environments — where IT/OT convergence, regulatory accountability, and safety risk demand a fundamentally different approach.

Audit & Control Validation

Producing the evidence that satisfies internal audit, regulatory assessment, and certification bodies — structured, defensible, and built to withstand scrutiny.

Threat detection & response

KQL-driven detection engineering across Microsoft Sentinel and Defender — translating telemetry into actionable intelligence and keeping detection logic ahead of evolving threats.

Board-level security advisory

Translating complex security risk into language boards act on — clear priorities, credible threat narrative, and strategic roadmaps aligned to business risk appetite.

Audio Introduction

Listen to a brief overview of my background and approach.

Consulting Philosophy

Strategy grounded in technical reality

Regulated organisations face a growing gap between compliance obligations and operational security reality. Independent consultancy closes that gap — not by adding process, but by building security postures that hold under scrutiny: from the regulator's desk to the board table to the OT control room floor.

01

Outcomes over outputs

Security programmes that satisfy auditors but fail under real pressure are not security programmes — they are risk. Every engagement I lead is designed to produce controls and governance that hold under scrutiny, not just on paper.

02

Technical depth enables strategic advice

Independent consultancy is most valuable when the advisor can operate at both board level and implementation depth. I translate between those layers — which means the strategy is grounded in what is technically achievable, and the technical delivery is aligned to genuine business risk.

03

Defensibility is the standard

In regulated and CNI environments, security posture must be demonstrably defensible — to regulators, auditors, insurers, and boards. That standard shapes every risk register, architecture decision, and governance artefact I produce.

Client Projects

Sizewell C is one of the UK's most significant nuclear infrastructure programmes. My current role providescyber security assurance and governance across its rapidly evolving digital, supplier and infrastructure environment.
Aligning regulatory obligations with practical controls, defensible evidence and secure programme delivery.

Cyber Security Assurance Lead

Sizewell C | Nuclear CNI

  • Lead 2nd line cyber assurance across digital, cloud, supplier and infrastructure programmes.
  • Review & Approve 3rd party Security Risk Assessments, challenging control design, technical evidence and proposed risk treatments.
  • Provide secure-by-design oversight across solution architecture, data flows, identity, access and 3rd services.
  • Advise senior security and programme leadership on material risks, assurance findings, remediation and escalation decisions.
  • Coordinate penetration testing, supplier assessments and control validation through to evidence-based closure.
  • Provision of governance and assurance through proportionate reviews of third-party cyber risk.

Cyber Security Lead

Sizewell C | Nuclear CNI

  • Translate ONR SyAPs, NCSC CAF, NIST CSF and ISO 27001 obligations into prcatical cyber requirements and controls.
  • Maintain the golden thread from risk → policy → control → evidence → assurance → governance reporting.
  • Management of evidence requirements, compliance dashboards and remediation evidence reporting.
  • Strengthen supply-chain assurance through third-party assessments reviews, contractual security requirements and controlled supplier access approval reviews.
  • Delivery of Cyber governance during the key construction phase in preparation for the transition to commissioning ensuring secure operations.

Cyber Security Specialist

Sizewell C | Nuclear CNI

  • Delivered hands-on cyber security engineering across Microsoft 365, Azure and endpoint environments.
  • Assessed vulnerabilities, investigated technical findings and developed practical remediation plans.
  • Designed, implemented and validated security controls covering endpoint protection, identity, access and cloud configuration.
  • Worked with internal teams, delivery partners and suppliers to embed secure-by-design principles into new and existing services.
  • Used security log data and technical evidence to verify control effectiveness and support compliance with recognised frameworks.

Security Consultant

Northern Power Grid | Electricity CNI

  • Endpoint security controls within OT pre-production environment using Carbon Black EDR.
  • Authored (HLD/LLD) security designs, contributing to defensible architecture.
  • Delivered tailored application control baselines and custom EDR rule sets.
  • Mentored internal teams on secure operations, post-project handover.

Infrastructure Security Consultant

Ineos Oil & Gas | Oil & Gas

  • Delivery of a NIST-aligned cyber security programme across IT and OT infrastructure.
  • Oversaw onboarding of MSSP, SIEM (Dell SecureWorks), and tuning of IDS/IPS policies.
  • Deployed enterprise EDR, DNS security (Carbon Black, Cisco Umbrella), and IAM controls (OKTA).
  • Azure and O365 security architecture with hardened image deployments and automated patching.
  • Projects delivered despite the global Covid shutdown.

Infrastructure Security Engineer

Kobalt Music Publishing | Media & Entertainment

  • Deployed global EDR and SIEM solutions (Carbon Black, Splunk), enhancing detection and response.
  • Onboarded IAM solutions (OKTA) and drove secure integration with AWS, Confluence, and JIRA.
  • Hardened systems using CIS benchmarks, with automation of secure Windows 10 builds.
  • Developed and enforced global security policies, procedures, and vulnerability management processes.

Network Systems Analyst

ACCOR Hotels UK & Ireland | Global Hospitality

  • Delivered secure infrastructure support across 250+ sites during a major digital transformation, contributing to PCI DSS compliance across UK & European hotel networks.
  • Migrated legacy Exchange to Office 365, enabling secure and scalable email infrastructure.
  • Decommissioned legacy VPNs and coordinated secure firewall upgrades across 200+ Cisco devices.
  • Implemented secure scripting, patching automation, and compliance monitoring using PowerShell, SCCM, and event log auditing.

Technical Credibility

Platform & Framework depth

Technical capability that underpins Consultant capabilities.

Cloud & Identity

  • Azure Security Center
  • Microsoft Sentinel
  • Defender for Cloud
  • Defender for Endpoint
  • Entra ID / PIM
  • Conditional Access
  • Microsoft Purview
  • DLP & Intune MDM
  • M365 Copilot security
  • NCSC Cloud Principles

GRC & Frameworks

  • ISO 27001
  • NIST CSF
  • CAF (NCSC)
  • ONR SyAPS
  • Cyber Essentials Plus
  • NIS2 / UK CSR Bill
  • Third-party SRA
  • Risk register design
  • Audit evidence packs

Detection & Response

  • KQL (advanced)
  • Microsoft Sentinel
  • Tenable One
  • Carbon Black EDR
  • Splunk SIEM
  • Azure Monitor
  • Log Analytics
  • IR plan design
  • Threat hunting

CNI & OT Security

  • IT/OT convergence
  • OT risk assessment
  • ONR regulatory assurance
  • Nuclear (Sizewell C)
  • Northern PowergridCNI
  • Oil & Gas CNI
  • SC Cleared delivery

Network & Infrastructure

  • Zero Trust architecture
  • Network segmentation
  • Cisco firewall estate
  • VPN design & migration
  • IDS/IPS architecture
  • Hybrid estate security
  • Active Directory hardening
  • CIS benchmark hardening
  • Patch management pipelines
  • Legacy infrastructure migration

Explore More Resources

Dive deeper into cybersecurity implementations, live monitoring, and expert guidance.

Case Studies

Visual showcase of cybersecurity implementations, security architecture diagrams, and project outcomes.

  • Documented security architectures
  • Framework alignment evidence
  • Detection and monitoring implementations
  • Delivered project outcomes
Explore Case Studies

AI Assistant

Chat with my AI assistant trained on my Cyber Security expertise. Discuss your project, assess fit, and get expert guidance.

  • Discuss your security challenge
  • Explore how I approach CNI and GRC engagements
  • Understand if this engagement is the right fit
  • Open a conversation before committing to a call
Ask Brian

Blog

Practical guidance on cyber assurance, secure delivery and risk management — grounded in real engagements.

  • Cyber assurance and governance
  • Security by design principles
  • Risk management frameworks
  • Lessons from live engagements
Read the Blog

Get in Touch

The right engagement for the right challenge.
I'm not the right fit for every project — and I'll tell you that upfront.
For regulated organisations, CNI operators, and complex GRC programmes, I bring the kind of focused, senior expertise that changes outcomes.

Please use the contact form or connect on LinkedIn.

Contact Me

Get in touch to discuss your cybersecurity needs or ask questions about my services.

Kent Wildlife Trust logo
ACCOR HOTELS logo
KURT GEIGER logo
Kobalt Music logo
INEOS Oil & Gas logo
Sizewell C logo
Northern Powergrid logo
Brian Stephens

© 2026 Brian Stephens. All rights reserved.

Privacy Policy