High-security mobile, privacy-first systems, and responsible AI.
For people and organizations who care about privacy, practical AI governance, mobile hardening, and data-exposure reduction, delivered with enterprise discipline and independent accountability.
Your business is your business.
An advisory practice built around one idea: security and privacy belong together.
I harden the phones and laptops the work actually runs on, cut the exposure nobody agreed to in the first place, and deploy AI security tooling that does something other than generate alerts.
Before Styzza I was Security Infrastructure Architect for mobility and endpoint at Abbott Laboratories, then spent close to a decade at BlackBerry and BlackBerry Cylance helping the largest organizations in the world handle mobile, endpoint, and AI security. Styzza is that work without the layers in between.
Every engagement starts the same way. I look at how your systems get attacked, exposed, and misused in practice, then tell you which parts of that actually apply to you and what to do first.
Six things you can hire me for.
Named engagements with a defined start and end, not open-ended consulting hours. Most clients start with one and add others as they come up.
Mobile deployment and UEM
Standing up Intune or Workspace ONE, or fixing the one you already have. Enrollment flows, hardening baselines, app and update policy, and migrations off a legacy MDM that nobody wants to touch. This is the work I did in-house at Abbott and sat across from for a decade at BlackBerry.
Microsoft 365, identity, and BYOD
Tenant posture end to end: conditional access, admin role sprawl, sharing and DLP defaults, and logging that will still be there when you need it. Plus BYOD programs that hold up, so personal devices reaching company data is a decision you made rather than one that happened to you.
Gap assessments
A scoped review of where you are against where you need to be, whether that target is a framework, an insurer's questionnaire, a customer security review, or plain attacker reality. Findings ranked by what gets reached first, and the ones your team can close without me are marked as such.
Executive personal hardening
For founders, executives, and public-facing leaders whose personal phone is the softest target attached to the company. Four tiers, depending on where you're starting:
- Quick hygiene. The obvious gaps: passwords, backups, exposed accounts, device settings.
- Account and data hardening. Logins, recovery paths, and the records already sitting in broker databases.
- App and traffic control. What gets to run, phone home, or track you. The rest gets shut off.
- Complete overhaul. Devices, footprint, and communications rebuilt from the ground up.
AI security deployments
Choosing and rolling out AI-driven endpoint protection, EDR, and XDR, then tuning them until the alerts mean something. I sold and deployed this class of tooling at Cylance, which is also why I can tell you which part of a vendor's AI claim is the product and which part is the demo.
Advisory retainer
A standing arrangement for teams that don't need a full-time security hire but need someone to call. Vendor and tool decisions, architecture review before you commit, questions about AI tools your staff have already started using, and a second read on whatever landed in your inbox this week.
Executives, and the organizations they answer to.
Founders, executives, and anyone public enough that going after them personally is easier than going after the company. This usually starts with one specific worry: an address that turned up somewhere, a message that felt wrong, a phone that goes everywhere and holds everything.
Past the point where security is one person's side responsibility, short of a full-time security team. Getting Microsoft 365 and identity into shape, a BYOD program that isn't just a policy nobody reads, and a plan sized to the staff you actually have rather than the team you'd need to run it.
Security and privacy teams that want an outside read: mobile and endpoint posture across a large fleet, a UEM migration nobody internally has the bandwidth to own, or a gap assessment from someone with no platform to sell you at the end of it.
The rigor of a large security program. One person accountable for it.
Large organizations run real security programs: threat models, access reviews, incident plans, evidence an auditor will accept. Most of that discipline transfers to a 40-person company. The overhead and the eleven-person steering committee do not.
Two sides of the same problem. I built mobility and endpoint security in-house at Abbott Laboratories as Security Infrastructure Architect, then spent close to a decade at BlackBerry and BlackBerry Cylance as Principal Sales Engineer and Enterprise Account Executive, sitting with the largest organizations in the world while they worked out mobile, endpoint, and AI security. Seeing the same gaps from the buyer's chair and the vendor's chair is most of why Styzza exists.
BlackBerry named me Cybersecurity Sales Rep of the Year for North America and Latin America in 2024. The work was deploying AI-driven endpoint, EDR, and XDR against CrowdStrike, SentinelOne, and the rest of the field. I know what those products do in a bake-off because I ran the bake-offs, and won most of them.
I speak on ransomware, zero trust, and mobile security, and I'm active across ISACA, Black Hat, DEF CON, and BSides. I host a Chicago-area cybersecurity networking group, which is partly an excuse to hear what is actually breaking in other people's environments.
CISSP since 2009, ISC2 member 339888. Each badge links to the issuing body's own record rather than to anything I control. ISC2 verification is public and takes a last name and member ID.
Connect on LinkedIn ↗“On many occasions, Kerry would fire off accurate responses before I even had a chance to start writing, this was especially true for a highly demanding account of ours. Kerry's finesse and passion for his accounts truly shines when he is asked about technical certificate challenges, he blows me away! His ability to foresee needs and proactively act easily kept our accounts happy and renewals flowing.”
Doug, Senior Technical Account Manager at CrowdStrike. Worked alongside Kerry for five years on strategic accounts at BlackBerry Cylance.
“I have had the pleasure of working across the table with Kerry and have always known him to be a highly knowledgeable subject matter expert in IT services and mobility infrastructure. Among his peers, Kerry is an excellent resource on technology industry trends driving purchasing decisions and uncovering solutions to complex IT matters, especially those impacting large, multi-national brands.”
Kelsey, Enterprise Account Executive at Tray.ai. Worked with Kerry from the other side of the table.
How this actually starts.
No procurement cycle and no discovery phase you pay for. Most engagements run in three steps, and you can stop after any one of them.
Conversation
- Thirty minutes, no charge. You describe what's worrying you and I tell you whether it's worth paying anyone to fix.
- Sometimes the answer is that you're already fine, or that the fix is a setting you can change yourself this afternoon. You get told that either way.
Assessment
- A scoped review of the specific thing in question: how your team is using AI, your mobile fleet, identity and access, or what's already exposed.
- Findings ranked by what an attacker reaches first, not by severity score. The ones you can fix without me are marked as such.
Implementation
- I do the work, or I sit with your team while they do it, depending on which one gets it finished.
- Ongoing advisory afterward if you want someone to call when something changes. No minimum term.
Request a Consultation
Tell me what you're working on and I'll follow up to set up a first conversation. It goes to my inbox, not a queue.