Engineering Risk Out — Not Just Documenting It

OT/ICS Security Assessments & Critical Infrastructure Advisory

Independent cybersecurity consulting for nuclear, energy, defense, and critical infrastructure organizations where the stakes are too high for checkbox compliance.

Request Consultation Explore Services
Q-Clearance (DoD Top Secret)
CISSP 15-Year Holder
GICSP SANS
CSSA SCADA Security Architect
FITSP Federal IT Security

Core Services

Three pillars built on 20+ years of high-stakes operational experience

🔍

Security Assessments

Consequence-based risk methodology that identifies what actually matters — and engineers it out.

  • Nuclear reactor cybersecurity assessments (AP1000)
  • Black-box ICS/OT penetration testing
  • OEM product validation (GE, Siemens, Honeywell)
  • Tabletop exercises & attack path analysis
  • Digital twin & air-gapped AI assessments
  • NRC RegGuide 5.71, NEI 08-09, IEC 62443 alignment
📊

Product & Commercialization Strategy

Bridge the gap between technical assessment and profitable go-to-market execution.

  • Cybersecurity portfolio development
  • Go-to-market strategy & revenue forecasting
  • M&A advisory & due diligence
  • International reseller & partnership negotiation
  • Data-driven business cases for C-suite approval
  • Sell-against strategies & competitive positioning
🛡️

Crisis Leadership & Advisory

When incidents happen, experienced leadership makes the difference between containment and catastrophe.

  • Incident response strategy & playbook development
  • Ransomware & high-profile attack containment
  • Interim CISO / Deputy CISO advisory
  • SOC operations optimization & SLA management
  • MSSP strategy, RFP, and vendor selection
  • Board-level risk communication

Track Record

Proof, not promises

100+

Nuclear plant systems assessed

$60M+

Above bookings plan at GE/Baker Hughes

$36M

IT/OT MSSP strategy at Newmont Mining

35K+

Endpoints managed at DHS/ICE SOC

Where I've Operated

Two decades across critical infrastructure, federal government, and Fortune 500 industrials

Westinghouse Electric Idaho National Laboratory Schneider Electric GE / Baker Hughes Newmont Mining DHS / ICE Bureau of Reclamation Securicon

Ed Turkaly — Principal Consultant

Over 20 years of executive cybersecurity leadership across nuclear power, oil & gas, mining, data centers, and U.S. federal agencies (DoD, DHS). I've authored nuclear cybersecurity assessment plans for the AP1000 reactor, productized security portfolios like SecurityST™ and OTArmor™, directed 35,000+ endpoint SOC operations with 4-hour containment SLAs, and led $36M MSSP strategies while actively containing ransomware attacks.

My approach is simple: assess deeply, identify critical consequences, engineer risk out at the design phase, and translate findings into board-level decisions with clear ROI. Most consultants either assess OR build OR respond. I operate across all three.

I hold a Q-Clearance (DoD Top Secret), CISSP (15-year holder), GICSP, CSSA, and FITSP certifications, and a Masters in Emergency Management (FEMA Body of Knowledge). Beyond the boardroom, I completed the 2,800-mile Tour Divide mountain bike race — the same grit I bring to containing high-consequence incidents.

Let's Talk

Available for assessment engagements, advisory roles, and interim CISO opportunities in nuclear, energy, defense, and critical infrastructure sectors.

turkaly@tgcyber.net

TGcyber.net | Boulder, Colorado | Remote / Travel Available