01 · When People Call
People usually call at one of five moments.
“We need senior security leadership, but we are not ready for a full-time CISO.”
“We are about to approve an expensive AI, infrastructure, vendor, or build-versus-buy decision.”
“An acquisition or investment depends on technical claims nobody independent has verified.”
“The incident is supposedly contained, but the board wants to know whether the evidence supports that.”
“We keep facing consequential technical decisions and want a standing independent adviser.”
Know an executive in one of these moments? Send them this page. Facing one yourself? Bring me the decision.
02 · The Work
Four ways I take the difficult problem.
01
Security Leadership Sprint
$7,500 fixed · 7–10 business days · paid in full to schedule
For founders, CEOs, CTOs, and GCs of growing SaaS and technology companies. I assess the security program, compliance and customer pressure, incident readiness, and unowned risks, then deliver a prioritized 90-day plan and a concise executive memo, including whether fractional leadership is warranted at all.
Start a sprint →
02
Fractional CISO / Standing Independent Advisory
Strategic $8,500/month · Embedded $12,500/month · 90-day initial term
Senior security leadership without another full-time executive. Strategic covers security strategy and prioritization, compliance and security-review direction, board preparation, architecture and vendor second opinions, incident readiness, and direct executive access. Embedded adds a weekly operating cadence, active program steering, enterprise security-review support, and incident escalation. Billed monthly in advance. I hold at most two standing relationships at a time.
Discuss a security leadership need →
03
Executive Decision Review
$12,500 fixed · 3–5 business days · 50% to schedule
Before you sign it, fund it, deploy it, or defend it to the board, independently test the decision. Vendor, infrastructure, private AI, architecture, build or buy. The deliverable ends in one conclusion: proceed, do not proceed, proceed only if, or more evidence required.
Bring me the decision →
04
High-Stakes Reviews
Scoped after intake
An independent conclusion where someone else's technical conclusion carries material financial or governance consequences. Incident Closure Review, typically $20,000–$30,000+: whether the evidence actually supports “contained” and “closed.” AI / Technology Technical Due Diligence for transactions, typically $25,000–$45,000+: verify the technical claims before capital moves.
03 · The Problem
The decision is larger than anyone's certainty.
The people closest to an important decision can all be competent and still see different parts of the system. The vendor knows the product. The internal team knows the history. The deal team knows the thesis. Each view is partial, and each carries its own incentives. That does not make anyone wrong. It makes the decision worth testing.
My role is to test the claims, evidence, economics, assumptions, and failure modes independently, then give the person accountable for the decision a conclusion they can challenge and act on.
The question is not who sounds most confident. The question is what the evidence actually supports.
04 · Who Calls
I work directly with the person accountable for the decision. This is not staff augmentation.
Executives & boards
The room holds several technically plausible explanations and you need to know which one survives scrutiny.
Investors & private equity
The seller, management, the deal team, and the vendors can all have legitimate reasons to want the transaction to proceed. I test the technical thesis independently before capital moves.
Counsel
Technical reality has to become conclusions that withstand challenge, not advocacy dressed up as engineering.
Founders & technology leaders
Internal teams can be excellent and still be too close to the architecture, the prior decisions, or the implementation history to give you an independent test.
05 · Why Joey
I have spent my career in the difficult part of the problem.
At NCC Group I did acquisition-related security work: testing and examining technology before ownership changed hands. At IBM X-Force IRIS I worked high-severity incident response and investigations, inside technically ambiguous environments where the conclusion had to hold up in front of executives. At Microsoft I consulted inside enterprise-scale systems. Today I build and secure private AI infrastructure as co-founder and VP of Infrastructure & Security at Qompute AI.
The technology changes. The work does not. Enter the system. Separate evidence from assumption. Test the explanation. Tell the decision-maker what is actually true.
You get a conclusion you can test, challenge, and act on.
06 · Independence
Independence is not a disclaimer here. It is the product.
I am not paid by a hardware vendor to recommend more hardware. I do not need an acquisition to close, a prior technical thesis to be correct, or an architecture to become more complex. My economics do not depend on reaching a particular conclusion. That is what lets me disagree with the room when the evidence does.
This is not a claim that anyone else is compromised. Excellent people can still have different incentives, information, and perspectives. Consequential decisions sometimes deserve an independent test.
Any material conflict or commercial affiliation, including my role at Qompute AI, is disclosed before I accept an engagement. Where independence cannot reasonably be preserved, I decline the work.
07 · Representative Work
The pattern, by kind of matter.
Transaction diligence
Security testing and technical examination of companies before acquisition, so the buyer knew what transferred at close.
High-severity incidents & investigations
Response, forensic investigation, and recovery in production environments: containment, evidence handling, and the executive conclusions that follow.
Executive technical review
Hardware, vendor, and architecture assumptions examined before capital commitment. The review that happens before the invoice, not after.
Private AI & infrastructure
Building and securing private AI infrastructure for real workloads, and evaluating deployment readiness for organizations moving sensitive work onto their own systems.
Client matters are confidential by default. References and sanitized work product are shared selectively, under NDA, with serious counterparties.
08 · How It Works
Four steps. No theater.
Confidential brief
You tell me the decision, the deadline, and what failure costs. NDA first if you prefer.
Diagnosis
I separate fact from inference, assumptions from evidence, and material unknowns from noise. Then I ask what would have to be true for the proposed decision to make sense, and whether the problem deserves an engagement at all. If I am the wrong person, I say so and point you at the right one.
Scope & engagement
Scope, evidence standard, and deliverable agreed in writing. Then the work: claims tested, economics rerun, boundaries probed, evidence preserved.
Evidence & recommendation
A signed conclusion with the evidence behind it, written for the room where the decision gets made, and willing to say the inconvenient thing when the evidence says it.
Proceed
Do not proceed
Proceed only if…
More evidence required
What the deliverable looks like: read an illustrative sample memorandum.
Standing advisory
For leaders who face consequential technical decisions repeatedly, fractional CISO / standing independent advisory replaces one-off reviews: a direct line, second opinions, architecture and vendor review, board preparation, incident escalation. I hold at most two standing relationships at a time so each one gets my full attention.
09 · Field Notes
Written judgment, published in the open.
Independent research and operating judgment for technical decisions with material consequences. Six representative notes:
When a Company Actually Needs a Fractional CISO, and When It Doesn't ↗
Fractional security leadership solves a judgment and accountability deficit, not a labor deficit. The conditions that create the need, what the role should and should not own, and seven questions to apply before buying anything.
The Incident Is Contained. That Does Not Mean It Is Closed. ↗
Containment is an operational state. Closure is a governance decision resting on different evidence. The five states that get collapsed into one announcement, and what a board should require before accepting that an incident is over.
Technical Due Diligence Should Test the Investment Thesis, Not Merely the Technology ↗
A technology assessment answers whether the systems are good. A transaction needs to know whether the technical facts support the economic bet being priced. Decompose the thesis, rank by valuation sensitivity, test what carries the money.
Private AI Is a Custody Model, Not a Hosting Model ↗
Running AI on your own infrastructure buys custody: the opportunity to control data, weights, and telemetry, plus the obligation to exercise it. Privacy is a property of the operated system, not of the building it sits in.
Cloud Security Architecture Is an Identity Problem Before It Is a Network Problem ↗
The cloud control plane is an authenticated API, not a network location, and control-plane authority includes rewriting the network controls themselves. Role chains, workload identity, deployment authority, and the gap between declared and deployed state.
Forensic Parsers Should Fail Closed ↗
Evidence-processing software that silently skips what it cannot read manufactures a gap the analyst cannot see. Truncation, dirty transactional state, failed integrity checks, and what to require of any tool whose output supports a conclusion.
Free research & tools
The Local AI Deployment Hardening Checklist, 40 checks across 6 domains for Ollama, vLLM, llama.cpp, and RAG stacks, free and printable. Tasia, an open-source tool that reviews a private AI stack's configuration and writes a hardening pack. The Private AI Exposure Index, ongoing research into how these systems are actually exposed, with the methodology published before the results. The Windows Gaming Reference Configuration, a reference build that keeps the security controls on, backs up policy before it changes anything, verifies the deployed state against what was declared, and publishes its benchmarks including the ones that show no change.
Field Notes, by email
One concise note when I find something worth knowing. Vendor claims tested, failure modes, infrastructure economics, lessons from incidents and live deployments. No news feed.
10 · Contact
Bring me the difficult problem.
Tell me what decision has to be made, when it has to be made, and what happens if the answer is wrong. I will tell you directly whether I am the right person for it, whether or not we work together.
Use the form · or email joey@victori.no
One or two lines is enough. Please do not send credentials, privileged material, or sensitive evidence through this form. NDA-first conversations are welcome.