Advisory Practice

NIS2 compliance is not optional.

Serving operators across the UK, EU, and North America. Most critical infrastructure organisations do not know what they have exposed to the internet.

Services

01

Fractional CTO & Turnaround

Interim technology leadership for scale-ups and SMEs navigating complex architecture decisions, delivery risk, or leadership transitions.

Available on request

Cloud Architecture & Due Diligence

Technical due diligence for investors, cloud cost optimization, and architecture reviews for cloud-native platforms.

Available on request

How It Works

02
01

Share Context

You provide public IP ranges, or we discover them through passive reconnaissance.

02

Passive Scan

OSINT analysis via Shodan, Censys, and protocol fingerprinting. No internal access required.

03

Analysis

Firmware version checks, CVE cross-referencing, and exposure risk scoring against NIS2 Article 21.

04

Deliver

Executive briefing, technical annex, and 90-day remediation roadmap. Delivered async.

Built on twenty-five years of systems architecture

From industrial telemetry to telecom infrastructure, to IoT deployments across Europe. I have led engineering organisations of up to forty developers and advised boards on technology risk, security posture, and regulatory compliance.

"Most operators do not need another consultant in their office. They need an independent eye, a technical report they can show their board, and a roadmap they can execute."

— On the async model

Today, I operate through F.A. Martin, delivering technical assessments and compliance guidance for operators who cannot afford to get it wrong.

Your OT assets are exposed.
You just don't know it yet.

Get a Shadow OT Scan and know exactly where you stand before the auditor asks.

Start with a Shadow OT Scan

Or email: enquiries@famartin.ie