Payspan
$500M Acquisition Due Diligence
Led end-to-end security due diligence for a $500M acquisition, delivering $2.5M+ EBITDA improvement through vendor rationalization and risk consolidation.
$500M
Acquisition Secured
$2.5M+
EBITDA Improvement
I stay on as the fractional CISO after the board pack lands. Twenty-plus years of security leadership. A retainer you can keep, not a $400K hire.

“I do not advise from the sideline. I embed in your organization, own the security roadmap, and build something that lasts long after I leave. That is the difference between a consultant and a fractional CISO.”











Trusted by











Rob Pinataro at Payspan, John Skinner at Optum Health, Kemper Seay at Carter's, and Stacy Hughes, CISO at ABM, on the Graph Broker.
Payspan
“We could not have done it without Adil. Under his leadership we passed every audit at 100%. His partnership and expertise for a lean internal team cannot be overstated.”
Rob Pinataro
CEO, Payspan
Optum Health
“I wish we could have kept Adil longer. He led Landmark's mobile application management rollout on Microsoft Intune through design, implementation, testing, and production as we integrated with Optum. I would recommend him without concern.”
John Skinner
Optum Health
Carter's
“Adil was instrumental in helping us implement our DevOps program to world-class standards and secure our Manufacturing/OT plant with Zero Trust principles.”
Kemper Seay
Carter's
ABM
“Adil rebuilt our AI governance program and shipped an in-house Graph Broker in front of our SharePoint AI tooling. Native Microsoft permissions would have over-permissioned the Apps team; that was a real win for Security Operations.”
Stacy Hughes
CISO, ABM
Payspan
Led end-to-end security due diligence for a $500M acquisition, delivering $2.5M+ EBITDA improvement through vendor rationalization and risk consolidation.
$500M
Acquisition Secured
$2.5M+
EBITDA Improvement
Optum Health / Landmark Health
Designed, implemented, tested, and rolled out Microsoft Intune mobile application management for 5,000+ Landmark devices during the Optum Health integration, so corporate apps could be used without opening unmanaged BYOD risk.
5,000+
Devices Under Intune MAM
6 Months
Design to Production
Carter's
Stood up a DevOps program to a higher standard and secured a Carter's manufacturing/OT plant with Zero Trust principles over a 9-month engagement, reducing implicit trust between corporate IT and the shop floor.
9 Months
DevOps and OT Engagement
CI/CD
Pipeline, Secrets, Env Separation
ABM
Built ABM's internal AI governance program and an in-house Graph Broker in front of SharePoint AI tooling, so the Apps team could ship without native Microsoft Graph permissions that would have over-permissioned them.
Graph Broker
In-House Control Plane
Least Privilege
Apps Team Graph Access
20+
Years Experience
12
Industry Certifications
#10
OnCon Icon, 2022
If this is the work you need
Thirty minutes. I will tell you if I should own the next stretch, or point you somewhere better.
See if I should be in the roomThe gap
Most teams cannot hire a $400K CISO and still need someone who can talk to the board, ship AI with controls, and pass the next audit. That is the same conversation in three rooms.
You need SOC 2 to close that enterprise deal, but hiring a $400K CISO for a 200-person company does not make sense.
The models are going to production. Security and governance are still a slide in last quarter's deck.
You ask portfolio companies about their security posture and get blank stares or jargon. You need a translation.
The 30-minute call is how we pick the work. You do not need to shop five packages to book it.
Roll out AI across the company with security architecture, usage controls, and governance your board can defend. Built for teams that need to deploy, not just write policy.
Fractional CISO
Board reporting, audit ownership, and a security program you can keep. Not a $400K hire.
Security Architecture
Cloud, identity, and zero trust design your engineers can actually ship against.
Board Advisory
Quarterly briefings that turn cyber risk into a decision the directors can defend.
Compliance
SOC 2, ISO 27001, HIPAA, PCI DSS, and CMMC programs built for your stage.
This practice is for a specific stage. If you are not there, I will say so on the call.
50 to 5,000 employees, or scaling into that range.
You have outgrown ad-hoc security and need structured leadership.
Preparing for an audit, funding round, or acquisition.
You need someone who has been through this process dozens of times.
Deploying AI and need it secured.
Move AI into production with NIST AI RMF and EU AI Act guardrails, not after-the-fact policy.
Under 50 employees with no compliance requirements.
A fractional CISO may be premature. I can point you to lighter alternatives.
Need checkbox compliance with no strategic intent.
If you want a rubber stamp, we are not a match. I build programs that reduce risk.
Want 24/7 SOC operations or managed detection.
I design the strategy; I do not run a SOC. I can help you select one.
If this sounds like you, book 30 minutes. I will tell you straight whether a fractional CISO is the right next step.
See if I should be in the roomAssess, architect, then execute. The same 90-day sequence I use when the next audit, raise, or AI rollout cannot wait for a full-time hire.

Rapid security posture assessment. Asset inventory, gap analysis, risk quantification, stakeholder interviews. You get a clear picture of where you stand and what needs to happen first.

Build the roadmap. Policy framework, control selection, compliance mapping, vendor evaluation. Every decision tied to business outcomes, not checkbox compliance.

Execute and measure. Deploy controls, prepare audit evidence, train teams, establish board reporting cadence. Measurable progress every sprint, not a report that gathers dust.
SOC 2 in 4 months, ISO 27001 in 6 months, FedRAMP authorization in 12 weeks. Same sequence, scoped to the deadline in front of you.
See if I should be in the roomStraight answers to the questions leaders ask before engaging a fractional CISO.

Thirty minutes. I will tell you if a fractional CISO is the right move, or if a lighter path gets you through the next deadline.
●I reply within 24 hours · Thirty minutes · No commitment