[SERVICE.LIST] ROLAND SANOU — WHAT I AM ASKED FOR, AND WHAT I ACTUALLY DELIVER.
SCOPE AND TERMS AGREED BEFORE ANYTHING STARTS.
shield_lock
Information system security audit
The whole estate, not one application.
Architecture, exposure, identity and access, endpoint posture, backups, logging and what actually reaches an analyst. Delivered as a prioritised plan with the effort each item costs — a list of two hundred findings nobody can act on is not a report.
SECTORS
· Mining · Education · Banking and mobile money · Defence and security · Public sector · Telecoms
conveyor_belt
Security automation
The alerts nobody triages because there is no time.
Enrichment, triage and response pipelines built on tooling a small team can keep running — orchestration, threat-feed ingestion, automatic report generation. Built at C-Prot to cut manual operational load by 60%, not as a slide.
arrow_forwardREAD THE METHOD
architecture
Architecture and recommendations by sector
A bank does not have a mining company's threat model.
Reviewing an existing system or designing the next one, with the constraints of the sector taken seriously: intermittent connectivity and OT on a mine site, shared workstations and minors' data in education, regulation and fraud in banking, classification and supply chain in defence.
SECTORS
· Mining · Education · Banking and mobile money · Defence and security · Public sector · Telecoms
phone_android
Mobile application audit
Banking, mobile-money and any app handling money or identity.
Static APK analysis across the four MASVS axes — storage, network, leakage, attack surface — with the boundary stated: what the method establishes firmly, and what needs a test device and a mandate. Reported in three states, never two.
arrow_forwardREAD THE METHOD
hub
External exposure mapping
What an organisation exposes that it has no inventory of.
Domains, forgotten subdomains, certificate transparency, address ranges, published apps, third-party dependencies, and the existence of compromised credentials. Passive by default; active checks only under a written mandate naming the assets.
arrow_forwardREAD THE METHOD
smart_toy
Detection and machine learning
For teams whose model scores well and misses in production.
Review of corpus construction, splitting and evaluation — the biases that make a metric an impression rather than a measurement. Feature engineering for endpoint detection, and honest stratified evaluation instead of a single average.
arrow_forwardREAD THE METHOD
account_tree
Data pipelines and MLOps
Getting the data to the model, and the model into production.
Ingestion, transformation, orchestration and deployment: the plumbing that decides whether a detection capability is a demo or a service. Built at C-Prot for a platform serving 5M+ endpoints.
arrow_forwardREAD THE METHOD