Get in Touch
Seattle and the Pacific Northwest

Security leadership without a full time CISO.

Clear policy, honest risk priorities, board reporting, and people who will look at how the work actually runs, without needing a full time CISO on payroll. Barry founded Seattle CISO. Associates, referrals, and partners handle the client work.

20+
Years in security
Navy
Submarine veteran
Seattle
Pacific Northwest
Hands on
Security leadership
Fractional CISO
Policy & risk
Board reporting
Incident readiness
Vendor review
Part time security leadership for Pacific Northwest organizations
Clear risk priorities
Policy staff can follow
Founded by a Navy submarine veteran
Background

From a submarine weapons deck to Seattle security work.

Barry started in the weapons department of U.S. Navy Trident submarines (USS Casimir Pulaski and USS Ohio), on Trident C-4 systems. Failure was not a ticket. It put people at risk. That is where the habit formed: check the real system, write down what you found, fix what matters.

U.S. Navy Enlisted Submarine Warfare Insignia (Silver Dolphins)
Qualified in submarines through systems walkthroughs and a qualification board

For the next twenty plus years he carried that into enterprise technology around Seattle: building, securing, and fixing infrastructure in the real world.

"We care more about what works on your floor than what looks good in a binder."

He started Seattle CISO for companies that need serious security help without a full time CISO. Between this practice and the rest of the portfolio, there are more kinds of work than one person can (or should) own. Associates take some of it. Referrals and partners take other parts. We put the right people on the job.

Private practice. Barry is the founder. This is not a government office and does not speak for the U.S. government. It is also not a pitch for Barry as the default assessor or solo consultant on every engagement. Client work is staffed through associates, referrals, and partners.

Why this work exists

Most companies put security off until something breaks.

Not because nobody cares. Because ops fills the calendar. Part time leadership is for that gap: senior enough to set direction, present enough to make progress.

Cloud boundaries
Teams inherit cloud tools and never write down who is responsible for what. When that boundary is fuzzy, reviews go badly and incidents get messy.
Checkboxes vs. protection
A binder full of policies is not the same as controls people actually use. We build both: protection that works, documented so others can see it.
Tech vs. leadership
IT, executives, and the board each need different detail. We translate so security decisions do not die in jargon.
What we offer

Practical security leadership. Not slide decks.

Part time leadership and hands on help. Policy people can follow, risk you can rank, and reporting leadership will read.

Core
Fractional CISO

Part time security leadership at the executive level. Policy, risk, board reporting, and program work on a schedule that fits how you actually run the business.

Program
Policy and risk

Security policies, risk lists, and control priorities that match real operations. Staff can follow them. Leadership can understand them.

Operations
Vendors and incidents

Vendor security reviews, incident response plans, and tabletop practice so you are not improvising when something goes wrong.

Leadership
Board and executive reporting

Plain status for executives and boards: where you stand, what gaps matter, what they cost to fix, and what a real incident would do to the business.

How we work

A security program you can keep running.

Simple sequence: learn the business, map real risk, close the gaps that matter, leave a program your team can maintain.

Step 1
Learn the business
People, systems, pressure points

Interviews, architecture reviews, and document collection. We start from how work actually happens, not a blank template.

Business context Technical reality What you must meet
Step 2
Write it down
What you have, what you need, what to fix first

Priorities tied to real risk and capacity. Not an endless checklist.

Step 3
Close gaps
Hands on help or clear advice

Fix what reduces risk. Skip what only looks good in a deck.

Policy Technical controls Training Executive reporting
What the work looks like

What a fractional CISO does week to week.

This is not a monthly pep talk. Expect a few dedicated days each month on the priorities that matter most. The first stretch is mostly diagnostic: read what you already have, talk to department leads about how data actually moves, map where sensitive information lives, and list where policy and reality diverge. That list becomes the agenda.

After that, the rhythm is practical. Vendor questionnaires and software reviews. Incident plans and a quick tabletop so people know their jobs. Checking that backups were actually tested. Helping staff report suspicious mail instead of ignoring it. None of that needs a full time seat. It does need someone who has done it before.

Boards and executives need regular status in business language: current risk, what is covered, what still gaps, what it costs to close, and what a serious incident would do. That translation is half the job.

Background

Operational experience. Not a binder full of certificates.

Security programs fail when the binder and the floor disagree. The people on the engagement (associate, partner, or trusted referral) are there to close that gap with judgment, not slogans.

Seattle CISO is Barry's commercial practice for Pacific Northwest organizations. He founded it. Client work goes out through associates and partners so different companies (and different kinds of work across the portfolio) can actually get covered.

Certificates can help sort résumés. They do not replace work that holds up when someone checks the system.

Enterprise security background
20+ years systems and security work in the Seattle area
Operational security leadership
Policy, risk, vendor review, and executive reporting for real businesses
Engineering & Technical Management (ETM)
Foundational tier: professional development standard for engineering and technical management work (not a commercial certification)
Silver Dolphins Insignia
Qualified in submarines
Attained through cross functional systems walkthroughs and a rigorous evaluation board
FTB MT
U.S. Navy Submariner | Weapons Department
USS Casimir Pulaski (SSBN 633) & USS Ohio (SSBN 726) · Trident C-4 systems
AI assisted documentation
Local tooling to draft and organize security program artifacts

Core Competencies

Program
Risk management Security policy Vendor risk Incident readiness Board reporting
Hands on work
Gap analysis Control design Document review Staff awareness
Tools
Local documentation aids Evidence organization
Leadership
Fractional CISO Executive briefings Board reporting
Get in Touch

Tell us what you need.

Send a short note. We'll get it to the right person: associate, partner, or referral. Private practice. Not a government service.

Select all areas where you need advisory or support: