I build the security toolsI wish I’d had.
Fifteen years reading attack surfaces — breaking into banks, then securing them at AWS, now building autonomous defence at RiskProfiler. Every tool I ship is one I wanted as a customer.
A mountain and an attack surface are read the same way: everything is connected, and the real danger is whatever you haven’t mapped yet. I spend my days on security graphs and my weekends on real mountains — and I’ve stopped pretending they’re different problems.
Four camps, one climb.
Checkpoint firewalls learned from documentation. None of it was coursework, and none of it was assigned.
The formal education. The interesting part was happening elsewhere.
Three months building applications — the fastest way to learn how they break — then penetration testing networks, systems and people for global clients.
Security Hall of Fame at Sellfy. Researcher acknowledgement from Intuit. Findings reported to people who had not asked for them.
A country change, and the start of the enterprise half of the story. Two published papers followed — honeypot patching through cryptography, and IoT security risks in 5G.
Breaking things professionally, at the scale of a national publisher.
Mapping the internet attack surface of AWS, GCP, Azure, DigitalOcean and Oracle Cloud. The question it asks — what can an attacker see? — became the company. Repository ↗
Week one, he broke into the company’s master database account. Then said nothing for two weeks and watched how the organisation behaved — because access was never the interesting part. The report described a system, not a bug.
Led the rebuild of the entire cloud landing zone. Highly secure, heavily automated, and — the part people forget — maintainable by the team that inherited it.
Securing the largest financial institutions in EMEA — HSBC, Barclays, Credit Suisse, Santander, Vodafone. The lesson that stuck: modern infrastructure changes faster than any static security model can describe it.
Product security at the other end of the spectrum from a bank. Seven months — and the last time he would secure someone else’s estate.
Attackers move across boundaries freely; the tools defending against them do not. Unifying external threats — brand, third-party, attack surface — under one security graph was never about licence savings. It was about restoring context. Two people to roughly forty, on about $2M.
He marked it by taking Crib Goch — the knife-edge ridge, the exposed route, no comfortable way back.
The summit push. Twenty-six agents over a unified exposure graph.
“There is no challenge too big or topic too complex for him.”
What I do best.
Three fortes, sharpened over fifteen years. Everything else is in service of these.
Securing cloud estates that change faster than any static model — landing zones, attack surface, detection. Built to be inherited by the team that stays, not just shipped.
Two people to roughly forty on about $2M. First raise, first six-figure customer. Every hat a founder wears — and the judgement to know which ones to keep on.
The last three years turning security research into product — deciding what to build, keeping the innovation honest, and shipping to CISOs who have no time to waste.
KnyX — autonomous investigations
Twenty-six agents over a unified exposure graph, running the loop a senior analyst runs — and acting where policy allows.
An autonomous system that cannot show its work is not autonomous — it is unaccountable.
> knyx: standing by
Dispatches from exposed terrain.
Essays on agentic security systems, external exposure, and company building. No filler — if it isn’t worth an hour of a CISO’s attention, it doesn’t ship.
Proved in public.
Attack surface management and cloud-native threat hunting, taught the way they’re practised — Black Hat-grade material, run against your environment.
BOOK A TRAINING →Marked.
Four summits, each tied to a moment in the climb. The only section where the mountain voice speaks.
I’ve never climbed Kanchenjunga. But whether the mountain is real or metaphorical — when I say I’ll conquer it, believe me, I will.
The door is open.
Currently building autonomous external threat defence at RiskProfiler. Good conversations: security architecture, agentic systems, and company building.
