Advisory

Better decisions before more technology.

Haroon helps boards and executives decide where AI genuinely helps, what data and authority it should have, where it can fail, and what must remain a human decision. Cybersecurity is the foundation; evidence, accountability and business consequence set the direction.

01

Board & Executive Advisory

Cybersecurity translated into enterprise risk, strategy, investment priorities, governance and executive accountability.

  • Independent briefings for boards and chairpersons
  • Cyber-risk appetite, posture and oversight
  • Scrutiny of executive assumptions and reporting
  • Preparing boards to ask better questions
02

Cybersecurity Strategy & Resilience

Security operating models, resilience, risk prioritisation, architecture direction, incident preparedness and strategic transformation.

  • Security strategy and multi-year roadmaps
  • Operating model and capability design
  • Incident preparedness and response maturity
  • Resilience measured by outcomes, not audits
03

AI Strategy, Governance & Adoption

Practical advice for deciding where AI belongs, what authority it should have and how executives retain responsibility when systems act.

  • Executive AI adoption and governance decisions
  • Human oversight, escalation and responsible autonomy
  • AI security, data exposure and decision risk
  • Technology investment scrutiny before procurement
04

AI Security & Agent Risk

Security review for copilots, agents and AI-enabled workflows with access to sensitive information, systems and people.

  • Agent permissions, identity and approval boundaries
  • Prompt, data and internal-knowledge exposure
  • Autonomous action, logging and access revocation
  • AI-enabled fraud, deepfakes and impersonation risk
05

National Cybersecurity & Hybrid Threats

National cyber resilience, critical-infrastructure thinking, cyber strategy, intelligence-led security and the interaction between cyber, information, economic and physical security.

  • National cyber strategy and resilience
  • Critical infrastructure protection thinking
  • Hybrid threats across cyber, information and economic domains
  • Intelligence-led security for state stakeholders
06

Private Digital Risk

For family offices, UHNW individuals, executives, public figures, journalists and similarly exposed individuals. Private digital risk is different from enterprise cybersecurity - it is personal, reputational and often invisible until it is too late.

  • Personal exposure assessment and hardening
  • Protection against impersonation, extortion and leaks
  • Discreet, confidential engagement by design
  • Delivered through Blackstone Private
07

High-Consequence Independent Review

An experienced second opinion before a consequential decision is made - on a proposed cyber strategy, a security transformation, a major technology or AI initiative, a significant security investment, a material incident, or the assumptions underneath them.

  • Proposed cyber or security strategy
  • Major technology and AI initiatives
  • Security investment and procurement decisions
  • Material incident response and executive assumptions
  • AI vendor and technology due diligence
Independent Review

Sometimes the most valuable engagement is an experienced second opinion before a consequential decision is made.