SELECTED WORK · ENTERPRISE SECURITY

Security transformation across six organisational boundaries.

A CIS Controls programme connected current-state evidence, capability ownership, secure information flows and a prioritised transition roadmap across six major IT departments.

Previous professional experience · ASELSAN

SETTINGDefence enterprise
SCOPESix IT departments
FRAMEWORKCIS Controls
BOUNDARYSeparated and air-gapped zones

THE PROBLEM

Controls crossed departments, but ownership and implementation capacity were distributed.

Security improvement required a shared current-state view and a feasible path forward while respecting separated infrastructure, information-classification and defence-sector flow constraints.

A control list could not substitute for capability ownership and transition design.

MY CONTRIBUTION

Connect security intent to organisational capability.

  • Initiated and led the CIS Controls transformation.
  • Assessed current capability across six major IT departments.
  • Connected controls to owners, dependencies, implementation constraints and priorities.
  • Modelled secure enterprise infrastructure and information flows across separated zones.
  • Worked through enterprise architecture governance to align security, data and IT-service decisions.

THE ARCHITECTURE APPROACH

Assess capability, not paperwork alone.

01

Establish current capability

Use evidence of people, process and technology—not policy statements alone.

02

Model information flow

Make classification, zone boundaries, allowed paths and control points explicit.

03

Prioritise a feasible transition

Sequence controls against risk, ownership, dependencies and implementation capacity.

04

Communicate across departments

Translate security objectives into decision-ready responsibilities and architecture views.

OUTCOME

One transformation logic across six departments.

The programme created a shared current-state picture, clearer capability ownership and a prioritised roadmap grounded in enterprise information-flow and architecture constraints.

BROADER EXPERIENCE

Security architecture informed by CISO and engineering practice.

Earlier HAVELSAN responsibility included ISO 27001, risk, incident response, secure development, awareness and cross-functional governance. That experience helped keep enterprise architecture connected to operational security practice.

Relevant capabilities: enterprise security architecture · CIS Controls · ISO 27001/27002 · information flows · capability assessment · roadmap design · governance.

Disclosure note. The case uses public-safe capability and organisational scale only. Network design, security-control status, vulnerabilities and internal architecture are not disclosed.

RELATED DECISION

Do security controls have clear ownership and a feasible transition path?