Independent cybersecurity consulting for nuclear, energy, defense, and critical infrastructure organizations where the stakes are too high for checkbox compliance.
Three pillars built on 20+ years of high-stakes operational experience
Consequence-based risk methodology that identifies what actually matters — and engineers it out.
Bridge the gap between technical assessment and profitable go-to-market execution.
When incidents happen, experienced leadership makes the difference between containment and catastrophe.
Proof, not promises
Nuclear plant systems assessed
Above bookings plan at GE/Baker Hughes
IT/OT MSSP strategy at Newmont Mining
Endpoints managed at DHS/ICE SOC
Two decades across critical infrastructure, federal government, and Fortune 500 industrials
Over 20 years of executive cybersecurity leadership across nuclear power, oil & gas, mining, data centers, and U.S. federal agencies (DoD, DHS). I've authored nuclear cybersecurity assessment plans for the AP1000 reactor, productized security portfolios like SecurityST™ and OTArmor™, directed 35,000+ endpoint SOC operations with 4-hour containment SLAs, and led $36M MSSP strategies while actively containing ransomware attacks.
My approach is simple: assess deeply, identify critical consequences, engineer risk out at the design phase, and translate findings into board-level decisions with clear ROI. Most consultants either assess OR build OR respond. I operate across all three.
I hold a Q-Clearance (DoD Top Secret), CISSP (15-year holder), GICSP, CSSA, and FITSP certifications, and a Masters in Emergency Management (FEMA Body of Knowledge). Beyond the boardroom, I completed the 2,800-mile Tour Divide mountain bike race — the same grit I bring to containing high-consequence incidents.
Available for assessment engagements, advisory roles, and interim CISO opportunities in nuclear, energy, defense, and critical infrastructure sectors.
turkaly@tgcyber.netTGcyber.net | Boulder, Colorado | Remote / Travel Available