Available for engagements

Protecting businesses
through expertise
not guesswork.

Independent cyber security consultancy with over 25 years in the software industry. Clear, practical advice for organisations of every size — from Cornwall to anywhere.

Scroll

25 years of hard-won
security experience

I'm Chris Kay-Ayling, an independent cyber security consultant based in the Southwest of Cornwall. Over the course of my career I have worked across software development, infrastructure, and security — giving me an unusually broad perspective on where vulnerabilities actually come from and how to close them.

I work with businesses, public sector bodies, and start-ups to understand their real risk exposure, build pragmatic defences, and navigate the often complex landscape of compliance and regulation — without the jargon. I also help organisations harness AI responsibly: using it to sharpen threat detection and response, while guarding against the new attack surfaces it introduces.

Whether you need a one-day workshop, an ongoing advisory relationship, or someone to lead a technical review, I bring the same commitment: honest, evidence-based advice that puts your organisation in a stronger position.

  • 25+ Years in the industry
  • 100+ Engagements delivered
  • SW Cornwall based
threat-assessment.sh

$ whoami

chris.kay-ayling

$ cat profile.txt

Role : Cyber Security Consultant

Location: Cornwall, UK

Exp : 25+ years

Stack : C# · PHP · MySQL · MSSQL

Infra : Linux · Cisco · Ubiquiti

Tools : GitLab · Spatial Systems · GIS

AI/ML : Threat Detection · LLM Security

$ ./check-vulnerabilities --scope all

[✓] Assessment complete — report ready.

What I can help with

Every engagement is tailored. These are the areas where I most commonly add value.

Security Assessments

Comprehensive reviews of your technical environment, policies, and processes to surface real risk — not just a checklist.

Penetration Testing

Structured, ethical offensive testing of applications, networks, and cloud infrastructure to find weaknesses before attackers do.

Compliance & Governance

Practical guidance on ISO 27001, Cyber Essentials, GDPR, and other frameworks — translating requirements into workable controls.

Security Awareness Training

Engaging, practical training for teams at every level — from the board to frontline staff — turning human vulnerability into human defence.

Incident Response

Rapid assistance when the worst happens — containment, investigation, recovery, and a clear post-incident improvement plan.

vCISO / Advisory

Fractional Chief Information Security Officer support — senior strategic guidance without the full-time overhead.

Spatial & GIS Security

Specialist security review for GIS platforms, mapping APIs, and spatial data pipelines — an often-overlooked attack surface with significant data-sensitivity implications.

Secure DevOps & Pipeline Review

Security integration into GitLab CI/CD pipelines — secrets management, SAST/DAST tooling, dependency scanning, and hardening your software supply chain.

Deep knowledge across the stack

A career that spans development, architecture, and security means I understand threats in context — not in isolation.

Application Security
Linux Infrastructure Security
Network Security (Cisco / Ubiquiti)
Cloud Security (AWS / Azure / GCP)
Penetration Testing
Risk & Compliance
Incident Response & Forensics
DevSecOps
Social Engineering & Phishing
Secure Software Development (C# / PHP)
Database Security (MySQL / MSSQL)
Spatial & GIS Systems Security
CI/CD Pipeline Security (GitLab)
AI-Driven Threat Detection & Defence
AI Security Risk Assessment

Frameworks & Standards

ISO 27001 NIST CSF Cyber Essentials Cyber Essentials+ GDPR OWASP Top 10 MITRE ATT&CK PCI-DSS SOC 2 NCSC CAF

Technologies

Linux (Debian / RHEL / Ubuntu) AWS Azure GCP Kubernetes Docker SIEM IDS/IPS Zero Trust PKI / TLS

Networking

Cisco IOS / NX-OS Cisco ASA / Firepower Ubiquiti UniFi Ubiquiti EdgeOS VLANs & Segmentation Firewall Policy Review VPN / IPSec / WireGuard Network Traffic Analysis

AI & Threat Intelligence

AI Threat Modelling ML Anomaly Detection LLM Security Review Behavioural Analytics UEBA AI-Assisted SIEM Adversarial ML Prompt Injection Defence

Development & Data

C# PHP MySQL MSSQL GitLab GitLab CI/CD Spatial Systems GIS / Mapping .NET SQL Injection Defence

Quick vulnerability scan

Enter a hostname or public IP address to run a fast port and service scan powered by Nmap. Results are returned in seconds and displayed below.

Scans are limited to top 100 ports  ·  3 scans per IP per hour  ·  60 s timeout

Results will appear here once a scan completes.

Independent, impartial, experienced

As an independent consultant I have no products to sell and no quotas to meet. My only incentive is to give you the best advice possible.

Having built and secured software and infrastructure myself — across C#, PHP, SQL databases, Linux systems, Cisco and Ubiquiti networks, and spatial platforms — I understand the trade-offs teams face at every layer of the stack, which means my findings are grounded in reality and actually get fixed.

Based in Cornwall, I work with clients across the UK and internationally, combining remote-first delivery with on-site presence where it matters.

  • 01
    Vendor-neutral

    No commercial relationships that could bias my recommendations.

  • 02
    Plain English

    Reports and advice written for decision-makers, not just technologists.

  • 03
    Delivery-focused

    I stay engaged until recommendations are understood and actionable.

  • 04
    Discreet

    Complete confidentiality — I understand what's at stake when sensitive vulnerabilities are uncovered.

Let's talk about your security

Whether you have a specific concern, need a quick sense-check, or want to explore a longer engagement — get in touch. I'm happy to have an initial conversation at no charge.

Southwest Cornwall, UK
Response within 1 business day

Your message is confidential. I typically reply within one business day.