The four phases
Align
One strategy across domains, governed
Integrate protective objectives across physical security, cybersecurity, and executive protection into a coherent strategy. Reconcile competing resource constraints, operational friction, and security posture. Establish governance that connects protective decisions to organizational objectives and regulatory requirements. Create the alignment between threat intelligence, capability, and commitment that enables consistent protective posture.
What this phase produces
- Objectives integrated across domains
- Constraints reconciled
- Governance connected to objectives and regulation
- Intelligence, capability, and commitment aligned
Writing
14 articles on Align
When the Lights Go Out: What ISO 22301 Actually Does for Your Business
ISO 22301 is the international standard for business continuity management. This article explains what it actually requires, why it belongs in the boardroom rather than the risk register, and how to start applying its thinking before you pursue certification.
9 min readA GRC Blueprint for Directing 24/7 Security Operations at Scale
A large, multi-site security operation running around the clock is a live risk management system. Every shift, every post assignment, and every client contract carries obligations that can slip in small ways. This article applies the OCEG Principled Performance framework to a 24/7 security operations context, with a four-step implementation timeline.
9 min read· part 1
Beyond IT: GRC as an Enterprise Discipline
Many people first encounter GRC through cybersecurity, audit, privacy, or IT control work. But GRC is not an IT function. It is an enterprise discipline that helps organizations govern decisions, manage uncertainty, meet obligations, and act with integrity wherever decisions create consequences.
9 min read· part 2
GRC in Physical Security: Governing Protection, Duty of Care, and Resilience
In physical security, risk is not abstract. It has weight, movement, timing, location, and consequence. A guard standing post is not the same thing as a controlled security operation. A protective detail is not the same thing as an executive protection program. The difference is GRC.
12 min read· part 3
GRC in Mission-Driven Organizations: Turning Ethical Purpose into Accountable Action
A good mission does not eliminate the need for governance, risk management, and compliance. It increases it. This article applies GRC to a fictional nonprofit to show how mission-driven organizations convert ethical purpose into accountable action through board oversight, donor stewardship, campaign governance, and credible impact reporting.
14 min readThe Executive Protection Standard: What It Changes, and What It Requires
For decades, executive protection operated without a recognized national standard. The new ANSI-recognized standard changes that. This article examines what it changes, what it requires, and what the industry must do now to meet the floor it establishes.
8 min read· part 1
From Guard Gates to Grid Resilience: Why Physical Security Is Now Critical Infrastructure Risk Management
Power-company security has always been about gates, badges, cameras, patrols, and response. But the threat landscape has evolved so fundamentally that physical security must now be understood as critical infrastructure risk management. This article argues that security teams in the electric sector must think in terms of function, consequence, and resilience rather than perimeter alone.
10 min readFrom Stewardship to Enterprise: Why the Modern Family Office Requires Institutional-Grade Risk Management
The global wealth landscape is witnessing the rapid institutionalization of private capital. Family offices are evolving from discreet wealth preservation vehicles into sophisticated investment platforms, yet their security and risk management frameworks have not matured concurrently. This article examines the expanding threat landscape and the imperative to adopt enterprise-grade risk management.
8 min readThe Architecture of Trust: Risk Management in the New Era of Branded and Wellness-Centric Living
The global pipeline for branded residences is projected to exceed 1,000 schemes by 2030. As the value proposition shifts toward wellness, community, and curated lifestyle, the security and risk management implications are significant and largely unaddressed.
7 min read· part 9
Bridging the Silos: Protective Intelligence as the Core of Insider Threat Programs
Organizations with a formal, cross-functional insider risk management program avoid an average of seven major insider incidents per year, resulting in approximately $8.2 million in avoided breach costs. Yet only 63% of organizations currently operate such a program. The structural failure is not a lack of data. It is a failure to connect the data that already exists across organizational silos.
8 min readApplying ISO 31000 Under Pressure
What a risk management standard actually looks like when the country is on fire. Drawing from seven years of experience in Haiti, this article demonstrates how ISO 31000's framework for managing uncertainty translates into life-or-death operational decisions in one of the world's most complex security environments.
14 min readFrom Protective Detail to Enterprise Risk Program: Applying GRC to Executive Protection
Executive Protection should be governed as an enterprise risk function, not treated as a standalone protective service. When Governance, Risk, and Compliance is applied to an integrated EP program, it gives leaders a disciplined way to define authority, align protective decisions with enterprise risk appetite, meet duty-of-care and compliance obligations, and create accountable, auditable protection outcomes.
12 min read· part 2
The Intelligence-Led Executive Protection Detail
The era of the visible deterrent is over. The modern executive protection detail must evolve from a logistics-heavy guarding function into a dynamic, intelligence-driven operation. It is no longer about how close you stand to the principal. It is about how far ahead you can see.
8 min read· part 7
Navigating the Gray Areas: Ethics, Privacy, and Legal Compliance in Intelligence
The difference between effective intelligence gathering and an unlawful invasion of privacy often hinges on how data is collected and subsequently used, not merely what data is collected. A Protective Intelligence program that operates without strict ethical and legal guardrails is not a security asset; it is a liability.
8 min readServices that deliver Align
How the Trusted Advisor delivers this phase
The Trusted Advisor delivers Align through management consulting and cybersecurity GRC: governance that connects protective decisions to the organization's objectives, risk registers that quantify exposure across domains, and controls that hold under pressure.
Talk to the Trusted AdvisorGRC & Operations
Management Consulting
Mission-focused operations advisory and GRC implementation support for organizations building or maturing security governance frameworks. Translates strategic intent into executable programs — policies, controls, risk registers, and accountability structures that hold under operational pressure.
Cyber Risk & Compliance
Cybersecurity GRC
Governance, risk, and compliance advisory for organizations aligning cybersecurity programs to regulatory requirements and enterprise risk frameworks. Covers control design, policy development, risk register management, IT GRC implementation, and compliance readiness across NIST CSF, ISO 27001, and sector-specific standards.
Portfolio evidence