Most security consulting is written for organisations that already have a security team. This page is for the ones that do not: the company with forty employees and one person who “does the IT”, the workshop with a production line older than its network, the practice that holds sensitive records and has never been asked to prove how it protects them.
You get the person you hired. Not a template, not a junior with a checklist, and not a 200-page report that ends up in a drawer.
Behind that is one person with twenty-five years in Linux and Unix, from Tele2 support to upstream open-source contributions, a completed degree in Network and IT Security and a bachelor’s in progress. More about who you would be working with.
What we do
Security audit, OT and IT
A practical assessment of what you actually run, not what the documentation says you run. Network exposure, authentication, patch reality, segmentation, backup that has been restored rather than assumed. On the OT side: what sits between production and the internet, what talks to what, and which of it can be reached from a desk.
You get findings ranked by what would hurt, with fixes you can carry out yourself where that is realistic.
GDPR and AI compliance
An audit of what you collect, why, where it goes and who can reach it, followed by plain advice on closing the gaps. For AI: where models touch personal data, what your suppliers are doing with your inputs, and what the EU AI Act asks of you at the risk tier you actually sit in.
This is compliance and technical advice, not legal advice. Where a question needs a lawyer, we say so rather than guess.
Data recovery
Deleted files, failed drives, corrupted volumes, broken arrays. Work is done on an image, never on your original media.
We tell you early when recovery is unlikely. A controller that has failed inside an SSD usually means the data is gone, and no honest process changes that. You are not billed for a miracle we cannot perform.
A drive that will not spin is a different problem. Mechanical failure needs a cleanroom and specialist hardware, which we do not have. We will tell you at the outset and point you to a lab, rather than open it on a bench and make the damage permanent.
Limited forensics
Incident triage and investigation: what happened, when, by what route, what was reached. Timeline reconstruction from logs, disk and memory, with evidence handled so it stays usable.
“Limited” is deliberate and it means something. This is investigative work to help you understand and respond to an incident. It is not court-certified expert-witness testimony, and if your matter is heading for a courtroom or the police, we will tell you at the outset that you need a certified examiner.
OSINT
Open-source intelligence, done from public sources only. Exposure mapping for your organisation and key people, supplier and counterparty checks, fraud and impersonation investigation, breach and credential exposure analysis.
We take authorised work only, and we document the sources so you can verify every claim rather than trust it.
OPSEC
Practical operational security for people who have a reason to need it: journalists, researchers, executives, anyone whose work attracts attention. Threat modelling against what actually threatens you, then device, account, communication and travel practice that survives contact with a normal working day.
Advice you cannot follow is not security.
Linux migration and daily use
Moving off proprietary platforms without breaking the business: what migrates cleanly, what does not, what the licensing actually saves you, and how the first six months really go. Then support for daily operation, because the migration is the easy half, and the year afterwards is where most of them fail.
Network topology, planning and consultation
Designing or redesigning a network to be understood as well as to work. Segmentation that reflects how your business is actually organised, remote access that does not become the way in, monitoring that tells you something, and documentation your successor can read.
What it costs
NOK 1,000–1,500 per hour, set by the nature of the work rather than by the clock. Routine advisory sits at the lower end; specialised investigative or incident work at the upper.
A lower hourly rate is negotiable for larger engagements or ongoing retainers, on a contract basis. If you need a fixed price for a defined scope, ask and we will quote one.
We would rather tell you an engagement is not worth your money than take it. That is not modesty, it is the only way this reputation is worth anything.
How it works
- You describe the problem. Use the form below, or email directly.
- We scope it together, in plain language, with an estimate before any work starts.
- We do the work, and you hear from us while it is in progress, not only at the end.
- You get something you can act on: findings, fixes, and the reasoning behind both.
If an engagement is outside what we can honestly do well, we say so and point you somewhere better.
Denne siden finnes også på norsk.
Get in touch
Tell us briefly what you need. You will get a reply from a human, normally within two working days.