About

SecHB is one person. That is the point of it, and also its limit — both are stated plainly here.

Steve Krouglof

CISSP (ISC²) since 2010, earned in Vancouver. Around twenty years of information security work: risk assessment, threat modelling, security policy and standards, audit readiness, business continuity and disaster recovery, and security-awareness programmes.

I am also still an engineer. Recent building work includes multi-tenant services on Python/FastAPI with PostgreSQL row-level security and immutable audit logging, and a speech-processing pipeline for legal proceedings. This is why the deliverables point at artifacts: I can go and look at the database and the pipeline rather than take a policy's word for it.

I am completing an LL.B. in IT and personal-data law, expected 2027. That is education, not a licence — I am not a lawyer and do not practise law or give legal advice.

Selected background

  • SecHB — security and compliance consulting practice. Security audits and readiness assessments, policy and standards, risk assessment, continuity planning, awareness training.
  • Security advisor to a secure-communications product: secure information-exchange design and data-leakage review ahead of public release.
  • HIPAA/HITRUST readiness programme manager for a NYSE-listed communications company, across a distributed engineering organization. Its final audit was performed by PricewaterhouseCoopers. PwC audited that client's programme — PwC did not assess me, did not audit me, and has not endorsed me or this practice.
  • CTO / IT manager at a security-software company: environment-wide security policy from threat and risk assessment, and shipped security products.
  • Earlier — IT systems security consultant roles covering LAN/WAN and server estates of several hundred endpoints, data sanitization and recovery, continuity planning, and threat response.

Get in touch