>_ ENGAGEMENTS

[SERVICE.LIST] ROLAND SANOU — WHAT I AM ASKED FOR, AND WHAT I ACTUALLY DELIVER.
SCOPE AND TERMS AGREED BEFORE ANYTHING STARTS.

Information system security audit

The whole estate, not one application.

Architecture, exposure, identity and access, endpoint posture, backups, logging and what actually reaches an analyst. Delivered as a prioritised plan with the effort each item costs — a list of two hundred findings nobody can act on is not a report.

SECTORS · Mining · Education · Banking and mobile money · Defence and security · Public sector · Telecoms

Security automation

The alerts nobody triages because there is no time.

Enrichment, triage and response pipelines built on tooling a small team can keep running — orchestration, threat-feed ingestion, automatic report generation. Built at C-Prot to cut manual operational load by 60%, not as a slide.

READ THE METHOD

Architecture and recommendations by sector

A bank does not have a mining company's threat model.

Reviewing an existing system or designing the next one, with the constraints of the sector taken seriously: intermittent connectivity and OT on a mine site, shared workstations and minors' data in education, regulation and fraud in banking, classification and supply chain in defence.

SECTORS · Mining · Education · Banking and mobile money · Defence and security · Public sector · Telecoms

Mobile application audit

Banking, mobile-money and any app handling money or identity.

Static APK analysis across the four MASVS axes — storage, network, leakage, attack surface — with the boundary stated: what the method establishes firmly, and what needs a test device and a mandate. Reported in three states, never two.

READ THE METHOD

External exposure mapping

What an organisation exposes that it has no inventory of.

Domains, forgotten subdomains, certificate transparency, address ranges, published apps, third-party dependencies, and the existence of compromised credentials. Passive by default; active checks only under a written mandate naming the assets.

READ THE METHOD

Detection and machine learning

For teams whose model scores well and misses in production.

Review of corpus construction, splitting and evaluation — the biases that make a metric an impression rather than a measurement. Feature engineering for endpoint detection, and honest stratified evaluation instead of a single average.

READ THE METHOD

Data pipelines and MLOps

Getting the data to the model, and the model into production.

Ingestion, transformation, orchestration and deployment: the plumbing that decides whether a detection capability is a demo or a service. Built at C-Prot for a platform serving 5M+ endpoints.

READ THE METHOD

REQUEST A CONSULTATION

Tell me what you are trying to establish. I answer with what is feasible and what is not — including when the answer is that you do not need me.

Kept for 365 days, then deleted automatically. Never passed on to anyone. Ask at any time and it goes immediately.

How this data is handled
OP_CENTER
STATUS: ENCRYPTED
SYS_BOOT.exeDOSSIER.exeREGISTRY.exeNOTES.logSERVICES.exeFORMATIONS.dirEXPOSURE.shCV_DATA.dirSECURE_CONNECT