Diagnosis
Establishing what is actually true about the estate, the risk and the dependencies before anyone proposes a solution.
Trusts, family offices, law firms and private advisory groups work with information that cannot be treated like ordinary company data. Privacy, continuity and control are part of what their clients are paying for. I think of these as high-discretion environments, and the work I do sits almost entirely inside them.
In such a place a technology decision is also a decision about who can see the information, where it is allowed to travel, how long the organisation could run without a given supplier, and whether recovery is real or merely assumed. Most of these organisations hold decades of confidential records on systems designed before any of those questions were asked of them.
The aim is not to lock everything down. Good control is what lets an organisation move quickly and be confident about it, rather than move carefully and hope.

Establishing what is actually true about the estate, the risk and the dependencies before anyone proposes a solution.
Framing consequential choices for principals and boards so the trade-offs are legible without requiring them to become technologists.
Deciding where systems run, what information each may reach, which suppliers are involved, what happens if one of them becomes unavailable, and who is accountable for each part once the consultants have gone. In the profession that is called the architecture and the operating model. In practice it is the way people, systems, suppliers and decisions fit together day to day.
Security, privacy, identity and AI governance treated as one domain rather than four committees.
Setting the path for a programme, choosing vendors, and holding delivery to it without absorbing the delivery itself.
Where AI belongs, where it does not, what the data layer has to be first, and what authority a system may hold.
Continuing senior judgement for an organisation that does not need, or cannot justify, a permanent executive in the role.
A defined period covering an executive gap, a modernisation, a stalled programme or an operating-model change, with a stated end.
An independent view of what is being proposed, what it will cost, what could go wrong, and what I would do instead. On an AI decision, a cloud move, an outsourcing arrangement, a supplier, or an investment with technology in it.
One question, one answer, a fixed scope. A technology assessment, a review of whether the organisation is ready for AI, a test of whether recovery actually works, a technology review after an acquisition, or a reset with a deadline on it.
You do not need to decide in advance what kind of help this is. Describe the situation and the shape usually becomes obvious to both of us.
A short description of the situation is enough to start. No preparation, no document, no procurement process. If it is not something I am the right person for, I will say so and point you at who is.
I look at what is actually true rather than what the last report said: the decision in front of you, what it depends on, what it will cost to reverse, and where the real risk sits. This is deliberately short.
If there is work worth doing, you get it in writing: what it covers, how long, what you receive and what it costs. Sometimes the honest answer is that the problem does not need an adviser, and that is a perfectly good outcome.
Nothing about the first two steps commits you to the third.

The work is executive rather than delivery, so what it produces is a decision somebody can defend, written down.
One consequential choice, framed so the trade-offs are legible without anyone having to become a technologist first.
What the estate, the risk and the dependencies actually are, before anyone proposes a solution.
What moves, in what order, with what has to be true before each step.
Which one, why, what it costs to leave, and what happens if they become unavailable.
For an acquisition or an investment: what is real, what is claimed, and what the buyer inherits.
What a system may see, what it may suggest, what it may carry out on its own, and who is answerable for each.
For something that has stalled: why it stalled, and the smallest change that restarts it.
A question about a file from fifteen years ago should not take three people and a morning.
Institutional knowledge that lives in a long-serving employee's head is a continuity risk with a retirement date attached.
Entity and portfolio reporting assembled by hand is slow, and the errors are invisible until they are expensive.
Knowing who processes what, where, under what terms, and how quickly any of them could be replaced.
The confidentiality obligation does not relax because the tool is useful.
Systems, access and knowledge surviving a departure, an illness or a succession.

The personal side of the same problem, handled with the same discretion as the institutional side: assessment of where a principal and household are exposed, identity and privacy design, secure remote and travel access, review of home and personal technology, provider selection, and incident-readiness planning. Where specialist protection providers are involved, the work is coordination with them.
It does not include physical protection, monitoring around the clock, managed detection, digital forensics or incident response. Those are different disciplines and are named here so nobody assumes otherwise.
From one engagement in this sector:
A substantial share came off the annual licensing bill, and recovery was demonstrated through a ransomware exercise rather than assumed. From one engagement, anonymised.
Start with the problem, not the service.
You do not need to decide in advance whether this is advice, an interim role or a single review. Describe the situation and the shape becomes obvious.