About
SecHB is one person. That is the point of it, and also its limit — both are stated plainly here.
Steve Krouglof
CISSP (ISC²) since 2010, earned in Vancouver. Around twenty years of information security work: risk assessment, threat modelling, security policy and standards, audit readiness, business continuity and disaster recovery, and security-awareness programmes.
I am also still an engineer. Recent building work includes multi-tenant services on Python/FastAPI with PostgreSQL row-level security and immutable audit logging, and a speech-processing pipeline for legal proceedings. This is why the deliverables point at artifacts: I can go and look at the database and the pipeline rather than take a policy's word for it.
I am completing an LL.B. in IT and personal-data law, expected 2027. That is education, not a licence — I am not a lawyer and do not practise law or give legal advice.
Selected background
- SecHB — security and compliance consulting practice. Security audits and readiness assessments, policy and standards, risk assessment, continuity planning, awareness training.
- Security advisor to a secure-communications product: secure information-exchange design and data-leakage review ahead of public release.
- HIPAA/HITRUST readiness programme manager for a NYSE-listed communications company, across a distributed engineering organization. Its final audit was performed by PricewaterhouseCoopers. PwC audited that client's programme — PwC did not assess me, did not audit me, and has not endorsed me or this practice.
- CTO / IT manager at a security-software company: environment-wide security policy from threat and risk assessment, and shipped security products.
- Earlier — IT systems security consultant roles covering LAN/WAN and server estates of several hundred endpoints, data sanitization and recovery, continuity planning, and threat response.