Focused on helping leaders strengthen cybersecurity, govern AI adoption, and turn high-consequence technology decisions into executable programs and working systems—through security leadership, targeted advisory, and hands-on delivery.
Security leadership and AI enablement that move with the business.
Principal-led engagements for leaders who need experienced judgment, an executable path, and enough hands-on depth to turn strategy into measurable progress.
Considering select professional engagements
Security leadership
Embed experienced security leadership where the business needs it most: setting direction, creating an operating cadence, and turning risk into decisions executives and technical teams can act on.
Typical outcomes
Security strategy, roadmap, and operating cadence
Executive risk measures and decision support
Program governance and incident readiness
Application and developer security leadership
Best for
Organizations that need senior security leadership without adding a full-time CISO.
Measured against
NIST CSF 2.0
ISO/IEC 27001
SOC 2
CIS Controls v8
FAIR risk quantification
Considering select professional engagements
AI enablement & governance
Turn AI interest into governed business capability with a practical use-case roadmap, clear human authority, and controls designed for how agents and teams actually work.
Typical outcomes
Use-case portfolio and adoption roadmap
AI policy and control architecture
Human approval, evidence, and rollback design
Agent governance and operating models
Best for
Leadership teams moving from AI experimentation to responsible adoption.
Measured against
NIST AI RMF 1.0
ISO/IEC 42001
EU AI Act
OWASP Top 10 for LLM Applications
Considering select professional engagements
Secure AI & agent delivery
Design and ship useful AI systems—not demos—with scoped context, durable memory, tool orchestration, and security built into the delivery path.
Typical outcomes
MCP servers and agent toolchains
Multi-provider AI applications
Workflow automation and integrations
Production prototypes and secure architecture
Best for
Teams that need a working, defensible system—not another slide deck.
Measured against
OWASP ASVS
NIST SSDF (SP 800-218)
MITRE ATT&CK
SLSA
Considering select professional engagements
Application & supply-chain assurance
Turn dependency, vulnerability, and architecture signals into prioritized engineering action that can be verified, repeated, and explained.
Typical outcomes
Dependency and attack-surface analysis
CVE remediation workflows
SBOM, license, and open-source risk review
Evidence-driven security automation
Best for
Engineering organizations that want security to accelerate delivery.
Measured against
CycloneDX & SPDX SBOM
CISA KEV
EPSS
OpenSSF Scorecard
OSV
Fractional leadership
Ongoing security leadership, operating cadence, and executive decision support.
Security strategy and roadmap
Executive and board-ready risk reporting
A standing operating cadence
Advisory intensive
A bounded strategy, governance, risk, or architecture decision moved to resolution.
A written recommendation with options and trade-offs
The evidence and reasoning behind the call
Named owners and next actions
Delivery sprint
Hands-on implementation, prototype, or security improvement with evidence and transfer.
A working system or control, not a slide deck
Runbook and operating documentation
Handover to an internal owner
How an engagement runs
Baseline the truth, prioritize honestly, operate the cadence, then hand it over.
Baseline
Establish what is actually true today: controls in place, real exposure, who owns what, and which decisions are already waiting on an answer.
Prioritize
Rank the work by risk reduced per unit of effort, and agree explicitly on what will not be done this quarter.
Operate
Run the cadence: remediation, measurement, and the executive conversations that keep a security program moving between reviews.
Transfer
Leave documented decisions, working systems, and an internal owner who can carry the program forward without the consultant.
Working principles
Evidence, not assertion
Recommendations arrive with the data and reasoning behind them, so they can be challenged, verified, and defended to an auditor or a board.
Client confidentiality
Client and employer names are never used as marketing. The résumé published on this site is deliberately employer-anonymized for exactly that reason.
Built to be handed over
Every engagement targets an internal owner. Success is a capable team that no longer needs the engagement, not a permanent dependency.
Coordinated disclosure
This site publishes a security.txt disclosure policy. Security advice is worth less from a practice that does not practise it.
Portfolio
Built by hand. Running in public.
Products and open-source systems built by Stephen M Abbott—evidence of the technical depth behind every professional engagement.
12 projects · refreshed Aug 5, 2026
SecurityLive · Active development
Python
security-recipes.ai
Turn CVE intelligence into verified, evidence-backed remediation teams can trust.
Open, self-hostable knowledge layer linking source-backed CVE research to bounded remediation recipes, required evidence, rollback guidance, and human-reviewed outcomes—built for teams that need traceable action, not another alert stream.
Map multi-ecosystem dependencies and surface supply-chain risk before production.
Supply-chain research tool that maps package dependencies across eight ecosystems and combines vulnerability, repository health, license, and SBOM analysis—so security and engineering leaders can triage risk before it ships.
Local-first studio to build, govern, and audit production-ready AI agents.
Unifies agent orchestration, workspace-aware coding, browser control, scheduling, integrations, memory, and auditable local workflows—so organizations automate with AI without surrendering data control or auditability.
Governed AI operations that critique, revise, and ship only under CI controls.
Live demonstration of agentic content operations with control retained at every step: an AI advisor reframes copy under code-enforced factual guards, opens a pull request, passes CI, merges, and deploys—proof for leaders evaluating governed AI enablement.
Raise enterprise message quality with AI inside Slack and existing channels.
Multi-provider writing assistant that rewrites, translates, summarizes, and reformats messages via Slack, HTTP API, CLI, or Python—clearer communication without pulling teams out of the tools they already use.
Open research experiment routing inference across volunteer nodes.
MIT-licensed research on pooled volunteer capacity (Claude, GPT, Grok, or Ollama) behind an OpenAI-compatible API—a distributed inference study, not a managed enterprise service.
Consumer lab: idea to illustrated, narrated children's storybook in-browser.
Browser-based story studio that writes, illustrates, narrates, and exports children's books with user-selected AI providers—end-to-end in the browser, framed as a product-lab experiment rather than an enterprise offering.
Portable Windows auto-clicker with record/replay and optional AI patterns.
Desktop automation utility with humanized cursor movement, global hotkeys, system-wide record/replay, and optional cloud or local AI pattern generation—no installer; a focused utility experiment, not an enterprise platform.
Non-custodial toolkit for accepting Dogecoin in person or online.
Small-seller commerce utilities: browser wallet tools, point-of-sale checkout, payment QR codes, on-chain verification, a local order ledger, and embeddable components—no processor custody; hobby commerce kit.
Chiefs fan site with an automated weekly game-preview desk.
Static fan site for the Arrowhead Paesano YouTube channel: privacy-friendly playback from a checked-in snapshot, plus a sourced weekly preview with matchups, projections, and a ready-to-shoot run-of-show.
Southwest outdoor gear storefront for desert travel and EDC.
Hosted storefront for desert exploration gear spanning apparel, outdoor accessories, and pet gear, with a merchandised catalog, checkout, and customer email capture.
Hobby Scrypt pool miner with live dashboard and hardware telemetry.
Full-stack Dogecoin pool miner for CPU and OpenCL GPUs, with live pool responses, share statistics, hardware telemetry, and on-chain wallet data—transparent hobby mining, not enterprise infrastructure.
Stephen leads with over 16 years of experience across enterprise technology, security engineering, program leadership, and product delivery—including 11 years focused on cybersecurity.
His résumé and portfolio show the operating range behind the consultancy: executive and board-level risk judgment, leadership of multi-team engineering organizations, measurable risk reduction at enterprise scale, and the ability to build the systems being advised—not merely describe them.
Bring Stephen the consequential problem: a security program that needs leadership, an AI initiative that needs guardrails and traction, or a system that must become both useful and defensible.