Azulea Security

Cybersecurity and AI risk advice for the executive who has to sign off on it.

Independent counsel for CIOs, CISOs and CTOs who need a defensible position, not a longer report.

W. Andrew Lemke, CISSP. Twenty-five years in cybersecurity, most recently as a senior director running security and resilience risk advisory for Fortune 250 clients in insurance, healthcare and financial services. Four issued U.S. cybersecurity patents.

The practice

Most security advice fails at the point where someone has to decide something. The assessment is thorough, the findings are accurate, and the executive still cannot tell the board what the exposure is or what it costs to close.

This practice starts at that decision. Engagements produce a position you can defend to an auditor, a regulator or a board committee, with the technical work underneath it done properly rather than summarized away.

What that looks like in practice

Selected work

  • A carrier spun out of a Fortune 100 insurer

    Built the entire cybersecurity program from the ground up as the company stood up as an independent entity, covering strategy, controls and the operating model.

  • Cyber resilience framework and advisory practice

    Authored a cyber resilience framework from nothing, aligned to NIST guidance in consultation with its author, and built the advisory service on top of it. The practice led to more than $30M in downstream services work.

  • U.S. banking sector resilience programs

    Led executive consulting and reference architecture for Sheltered Harbor, the banking industry's response to a catastrophic data event.

Start

Describe the decision you are facing. If the work is not a fit, you will get a straight answer and, where possible, a referral.

Describe your situation