The four tables

Four tables, one thing in common:
nobody sitting there can afford a mistake.

A

Chief executives and boards

The board appointment comes as the security expert supporting the chief executive, because around that table a voice with nothing to sell is almost always missing. Responsibility for information security now falls personally on the leadership: it is no longer reputation or money alone.

  • Independent director on boards and risk committees
  • Second opinion on technology choices and suppliers
  • Preparing the board for GDPR, NIS2, DORA and the AI Act
  • Support during an incident and in crisis communication
  • The mandate on a board →
B

Funds and investors

Before a transaction, somebody has to establish whether a technology company can genuinely do what it claims, and whether what it claims holds together. It is an examination of the documents and of the people, and it ends in a short document handed to the investment committee.

  • Verification of the technology and the intellectual property
  • The real security posture, not the declared one
  • Assessment of the key people
  • Technology due diligence →
C

Founders and companies building a product

The choices made in a product's first year look technical and reversible. By year five they are the product. And code now arrives faster than it gets read: the decisions inside it were made by a model, and signed by nobody.

  • Technical leadership from the design to the handover
  • The team: who to hire, who not to, and when
  • A written rule on generated code
  • How it gets built →
D

People in the public eye

Living under scrutiny creates a problem walls do not solve. A photograph forwarded for convenience, images from a set in the wrong chat: an attack is rarely needed. What is needed is protection no commercial product provides, and someone reachable when something happens.

  • Confidentiality of communications and material
  • Removal and containment of what is already out
  • Coordinated abuse campaigns
  • How those cases are handled →
Declaration of interests

I am a co-founder and technical director of CyberGrant, and the patents in the record are mine: on technical direction I am not impartial, and I say so. On the vendor I am: when I advise, my own technology is not among the options.

Valerio Pastore

Do you know the one thing almost nobody can do?Keep a secret.

Cases and products

There are no client names here.
The products are.

The best work is the work nobody ever heard about. Of the work for clients only the recurring situations remain, with no names, dates or details that would identify anyone. Of the products everything remains: they are in the record, line by line.

Table
Executives and boards

A decision already on the table

A critical supplier to choose, an acquisition, an artificial intelligence tool to authorise, an incident under way. The work ends in a written position, taken before the vote, that stays on the record.

Recurring outcome: a position on the minutes
Table
Funds and investors

A company to examine before signing

Technology, intellectual property, security posture, people. An examination of the documents and of the people, ending in a short document handed to the investment committee, with the answer even when it is unwelcome.

Recurring outcome: a short document
Table
People building a product

A product to build, or to put back on its feet

An architecture to choose, a team to put together, a prototype that grew fast and nobody knows how well it holds. The work starts with the design and ends when the team can walk on its own.

Recurring outcome: a team that carries on by itself
Table
People in the public eye

Private material back in circulation

Images from years before, content out before its launch, coordinated campaigns. Rarely an attack. The work is to find where it is leaving from, stop the spread and starve it of oxygen until it stops.

Recurring outcome: circulation exhausted
Record
1995 – 2022

Four products, from the first line to the market

Windows Limits, 1995, on PC Magazine's cover disc in February 1996. Xbinary, 2005, storing files online. Boole Server and BooleBox, conceived in 2008 and trading from 2011, five international awards in London. CyberGrant, 2022, Menlo Park, from which RemoteGrant, FileGrant, AIGrant, SecretGrant and EmailGrant come. Each built from scratch, with a team put together for it. Before that, at VALMAX Software: Valpas Box, The Guardian, CommHCat, VHarmor.

Every line can be checked. Open the record →  ·  How it gets built →

The same subject can also be taught. Two programmes for people who hold information that is not their own: a restricted one, by application, and a two-day seminar for a whole department or a whole organisation.

The two programmes