Independent Cybersecurity Advisory
Strategic cybersecurity advice for businesses and leadership teams. I help you understand your real exposure, cut through the noise, and make confident security decisions.
No vendor ties. No reselling. No implementation agenda. Independent advice.
About
Independent Cybersecurity Advisor
I spent over a decade in cybersecurity on the execution layer. Risk assessments, audits, security awareness, penetration testing, data protection, compliance projects. I know that world inside out. I also know what happens when organisations treat security as a checkbox rather than a strategic asset.
Today I operate differently. I help leadership teams, founders, and boards understand their real exposure, cut through vendor noise, and make security decisions from a position of clarity rather than obligation.
I bring insight. I advise on what to prioritise, what to invest in, and which risks to accept. How to navigate compliance requirements without becoming constrained by them.
I don't have a vendor agenda. I don't resell software, licenses, or tools, therefore I hold no financial stake in what I recommend.
I practice under the business name Ørnsyn. In Norwegian, ørn means eagle and syn means sight. It reflects my approach. A higher perspective, focus on priorities and effective decisions.
How I work
I take time to understand your situation and the challenge you're facing. I ask direct questions and tell you how I can help, or point you forward if I'm not the right fit. Either way, you leave with a direction on the next steps.
We agree on scope, format, and timeline upfront. Whether a session, a project, or an ongoing arrangement. Pricing is agreed before we begin. Nothing is left open-ended.
You leave with a sharp view of what matters, actionable recommendations, and genuine feedback. The decisions and implementation are yours. I will make sure you know what to do next.
What I offer
Cybersecurity is full of noise. A decade in the field taught me what actually matters and how to act on it.
You have a specific decision to make, a vendor to evaluate, a tool to assess, or a risk whose significance is unclear. Bring it to a focused 90-minute session and leave with a clear point of view, not more questions.
Per sessionYour organisation is already using AI tools. The risk is often underestimated. I assess shadow AI exposure, data leakage through LLM usage, and access control gaps before they escalate into incidents.
Session-based or ongoingMost risk assessments produce documents nobody reads. This one produces a prioritised roadmap you can actually follow. Structured identification, honest scoring, and clear recommendations on what to fix first and what to accept. The decision stays with you.
Compliance advisory available for NIS2, DORA, GDPR, and EU AI Act.
Per EngagementNo implementation, audits, penetration testing, policy writing, or incident response. These are important services, but not mine. If that is what you need, I am happy to point you toward the right people.
Rate Card · 2026
Prices are starting points. Complex engagements scoped on request.
Advisory Sessions
Focused conversations for specific problems, decisions, or situations where you need expert insight.
Single Advisory Session
One specific challenge, decision, or question. A focused conversation with honest assessment and clear next steps. Typically 90 minutes.
AI Security Advisory
Assessment of AI usage, data exposure, and access control across your organisation. Scope varies with organisational size and complexity. Structured summary of risks and prioritised recommendations.
Security Investment Review
Evaluating a vendor, tool, or proposed spend. Independent assessment with no sales agenda. Pre-review, focused session, and written summary included.
Trusted Advisory
Input on key decisions and risks. An independent perspective for decisions where judgment matters. Typically an ongoing advisory relationship.
Risk & Compliance
For organisations that need a structured view of their security risks and compliance obligations, and a direction on what to address specifically.
Risk Assessment
Organisational · Vendor · AI · SaaSIdentification and prioritisation of your real security risks. Where you are exposed, what the consequences are, and what to do about it.
Compliance Advisory
NIS2 · DORA · GDPR · EU AI ActWhat the requirements mean for your organisation. Where the gaps are. What to prioritise and in what order.
All prices are net amounts. VAT is charged where applicable.
Contact
First conversation is a direct look at your situation and whether I can help. No pitch, no sales agenda. If I'm not the right fit, I'll point you in the right direction.
Discovery call · No chargeAvailable across Norway and internationally. Sessions in English or Norwegian.
Remote or on-site. Your preference.