Skip to content

Selected work

Work & Case Studies

A few engagements in depth — challenge, action, and measurable result — followed by a broader slice of recent project work.

Secure Microsoft 365 Copilot Launch

Global food & beverage manufacturer

Challenge
Enable Microsoft 365 Copilot and generative AI across a global enterprise without exposing sensitive data through oversharing.
Action
Led the secure launch using Purview DSPM, insider-risk policies and SharePoint Advanced Management; red-teamed Copilot for data leakage; and governed AI use (M365 Copilot, GitHub Copilot, ChatGPT) plus agentic-AI policy via Power Platform DLP and Onyx.
Result
Copilot rolled out with oversharing controls and DSPM visibility in place — generative AI adopted on corporate data with guardrails, not guesswork.
  • AI Security
  • Purview DSPM
  • Copilot
  • Agentic AI

CASB & Shadow-IT Modernization

Global food & beverage manufacturer · global SaaS estate

Challenge
A noisy CASB program and rising risk from unsanctioned generative-AI SaaS on endpoints.
Action
Refreshed CASB policies, processes and use cases across Microsoft Defender for Cloud Apps and Zscaler — custom tags, automated monitoring, and SaaS API protections integrated with Office 365 and Workday.
Result
False positives cut by up to 75% and high-risk unsanctioned GenAI apps blocked — sharper signal, lower noise, tighter control.
  • CASB
  • Zscaler
  • Defender for Cloud Apps
  • Shadow IT

SOC 1 + ISO 27001 + SWIFT — Simultaneous Certifications

GlobalTrade Corporation · via Canadian Cyber

Challenge
Achieve multiple security certifications and concurrent audits on tight deadlines while running the business.
Action
Acted as vCISO — built the GRC framework, led ISO 27001 and SOC 1 implementation, SWIFT and Microsoft security work, and integrated as an extension of the client’s team through shifting priorities.
Result
Simultaneous certifications and concurrent audits completed — an ongoing security partnership (see the client’s recommendation).
  • vCISO
  • ISO 27001
  • SOC 1
  • SWIFT

National-Scale ISO 27001 (12M+ beneficiaries)

BISP · via Karandaaz

Challenge
Secure a national social-safety-net program serving 12M+ beneficiaries and reach ISO 27001 certification quickly.
Action
Reviewed existing processes, policies and workflows in an initial audit, built the GRC framework, and delivered the recommendations and controls needed for ISO 27001 ISM certification.
Result
ISO 27001 certification status attained in a short timeframe for a data-centric national program (see the client’s recommendation).
  • ISO 27001
  • GRC
  • Public Sector

More projects

Recent project work

AI Security2024 – Present

Microsoft 365 Copilot — Secure Launch

Led the secure deployment of M365 Copilot using Purview and SharePoint Advanced Management — insider-risk policies, data security posture management (DSPM), and oversharing controls before enabling generative AI on corporate data.

  • Copilot
  • Purview
  • DSPM
  • SAM
AI Security2025

Agentic AI & Power Platform Governance

Defined DLP policy for Power Platform connectors used by AI agents and built a secured AI Champions sandbox; configured Onyx policies governing data leakage and anomalous agent behaviour across users, agents, and cloud assets.

  • Agentic AI
  • Power Platform
  • Onyx
  • DLP
SecOps2024 – Present

Microsoft Security Copilot

Operationalized Security Copilot for the SOC — deployed the conditional-access optimization agent, generated incident reports, and identified use cases to improve detection and response efficiency.

  • Security Copilot
  • SOC
  • SOAR
Cloud Security2023 – Present

Defender for Cloud — CSPM & CWP

Matured cloud security posture management across multiple Azure subscriptions; aligned Azure Policy to NIST SP 800-53, ISO 27001:2022, and the Azure Cloud Security Benchmark, with DevOps pipeline integration.

  • Azure
  • CSPM
  • NIST
  • DevOps
Cloud Security2024 – Present

CASB / Shadow IT Program

Refreshed CASB policies across Defender for Cloud Apps and Zscaler, cutting false positives by up to 75%; blocked high-risk unsanctioned generative-AI SaaS on endpoints.

  • CASB
  • Zscaler
  • Defender for Cloud Apps
Identity2023 – Present

Conditional Access & Entra ID Protection

Re-architected Conditional Access and sign-in / user-risk policies with device-trust enforcement; presented MFA and risk strategy to CIO, VP, and Director stakeholders.

  • Entra ID
  • Zero Trust
  • MFA
SecOps2024 – Present

Microsoft Sentinel — SIEM & SOAR

Stood up Sentinel workspaces, data connectors, watchlists, and threat indicators; defined log-source, retention, and automated incident-response strategy.

  • Sentinel
  • SIEM
  • SOAR
GRC & Audit2014 – 2023

ISO 27001 Certification & vCISO Programs

Led ISO 27001 certification audits (2013 & 2022 standards) and virtual-CISO engagements for clients across healthcare, financial services, and MSP sectors; authored 140+ ISMS documents.

  • ISO 27001
  • vCISO
  • SOC 2
GRC & Audit2025

NIST CSF 2.0 Upgrade (IT + OT)

Contributed to a multi-day workshop upgrading the Cybersecurity Framework from 1.1 to 2.0, incorporating OT into the assessment and scoring with VP / Director stakeholders.

  • NIST CSF 2.0
  • OT
  • Assessment