45 Years in IT Security. Real Audits, Real Boardrooms.

CISSP since 2005, CISA since 2012. Former Internal Auditor at HP Canada, NAV Canada, and Shared Services Canada. I help certified auditors become capable ones, help businesses meet cyber insurance and regulatory requirements, and help executives manage cybersecurity risk — using what actually works in practice, not just what's in the Body of Knowledge.

I have advised on cybersecurity governance and risk for organizations including Bell Canada, Nortel Networks, HP Canada, NAV Canada, and federal and provincial government bodies. That work spans practical implementation, audit, and education — supporting executives making decisions, organizations meeting external requirements, and professionals building their expertise.

Choose Your Focus

For Certified Auditors

Certified but short on real-world audit experience? Practical training for CISA, CIA and CISSP holders — from planning and evidence through findings that management accepts and acts on.
Learn more →

For Small and Medium-sized Business (SMB)

Practical guidance to meet insurer expectations, reduce exposure, and demonstrate due diligence. Paves the way to show compliance to required standards, like PCI DSS.
Learn more →

For Executives

Fractional / Virtual CISO support to manage risk, guide decisions, and align cybersecurity with business priorities.
Learn more →

Start Here

Courses: Audit Findings That Land and the rest of the course catalogue — instructor-led, online, built on real audit experience.

Book: Audit Reports Reference Guide — the course content and reference material in one place, on Kindle.

You can contact me if you have suggestions or questions or want to book an appointment with me.

Background

I graduated from Queen's University in Kingston in 1985 with a B.A. in Computer Science, having worked four summers at IBM. I worked as a security consultant for numerous companies including Bell Canada, PetroCanada, Nortel Networks, HP Canada, NAV Canada, and in the public sector at the federal and provincial levels. I obtained the CISSP certification in 2005 and CISA in 2012. I became an IT Auditor at HP Canada and worked in Internal Audit until I retired in 2018. I have been a freelance instructor since 2018, delivering 45 different course titles, both on-site and online.

I have been teaching certification courses for eight years, including CISA, CISM, CISSP and related subjects. The course material is taken from the Body of Knowledge (BOK) sources for these credentials, plus my own experiences (24 years as a security consultant, 10 years as Internal Auditor, 5 years as systems administrator & programmer, 6 years as instructor) — but the BOKs stop short of showing how to actually put the credentials into practice. A newly certified professional can pass the exam and still have no idea how to write an audit report that survives management scrutiny. A new manager can receive that report and have no idea what to do with it. That gap is what my work fills.

My approach is grounded in decades of hands-on experience, beginning with early personal computing and evolving with modern enterprise environments. From implementing practical access controls in shared systems to advising on governance and risk, my focus has remained consistent: understand systems at a fundamental level, and apply that understanding to solve real-world problems — the kind the BOK doesn't cover.