Infosec HS
Identity & Privileged Access Security

Identity security, owned end‑to‑end, from governance to production.

Security programmes rarely fail at the strategy, or at the build. They fail in the gap between them. We work in that gap, across governance, technology and architecture, as one accountable partner.

Experience
8+ years
Clients
10+ enterprises
Sectors
Finance · Telecom · Pharma · Retail · Aviation
Interactive · move your cursor
They trusted us
KBCBanking
ProximusTelecom
EuroclearFinancial Markets
BelfiusBanking
Bank of IrelandBanking
GivaudanPharma & Fragrance
AvonGlobal Retail
Mercedes PayAutomotive Finance
DevoteamConsulting
ADB SafegateAviation Security
The end-to-end approach

One engagement. Three layers. No handover gaps.

Most security failures are born at the seams: strategy handed to one team, tooling to another, integration to a third. We stay across all three layers of the journey, so nothing is lost in translation.

01 · Why

Governance

Every engagement starts with the drivers. Regulatory pressure, audit exposure, third-party risk, operational continuity: we translate them into control objectives the board can defend and the audit can verify. Strategy before tooling, always.

  • NIS2 · DORA · ISO 27001 · SWIFT CSP · NIST
  • Maturity assessment & roadmap definition
  • Control design, gap assessment, audit readiness
  • RFP drafting & vendor selection
02 · What

Technology

Then the capabilities that enforce those controls operationally. Identity and privileged access across the platforms regulated enterprises actually run, built to solve business problems rather than to deploy tools.

  • CyberArk PAM, full stack · Privilege Cloud
  • SailPoint · Okta · ForgeRock · Entra ID
  • Vendor & third-party access management
  • Session monitoring · Federation · Secrets
03 · How

Architecture

Finally, the integration that makes it last. Resilient identity ecosystems across hybrid infrastructure, balancing security, scalability and the people who use them every day, so controls survive contact with production.

  • Zero Trust & secure remote access
  • HLD/LLD & enterprise integration
  • SAML · OIDC · OAuth2 · MFA/SSO · RADIUS
  • Automation, DevSecOps & SIEM observability
"A strategy is only as strong as its implementation, and an implementation only as durable as the strategy behind it. We remain accountable for both."
The partnership principle
Ways of working

A partner, not a vendor.

Engagements are shaped around where you are in the journey, not around a product to sell. Three typical entry points:

MODE 01

Advise

For leadership teams that need clarity before commitment.

  • PAM & identity maturity assessment
  • Target-state architecture & roadmap
  • Regulatory alignment (NIS2, DORA, SWIFT CSP)
  • RFP support & vendor selection
MODE 02

Deliver

For programmes that need a single accountable owner from design through to production.

  • Greenfield platform design & delivery
  • Vault consolidation & migration
  • Vendor & third-party access programmes
  • Enterprise integration: SIEM, ITSM, AD, cloud
MODE 03

Operate

For platforms that must keep performing in production and under audit, year after year.

  • Operating model & governance frameworks
  • KPI dashboards & executive reporting
  • BCP/DR strategy & resilience validation
  • Automation & operational enablement
8+
Years in the field
10+
Enterprise clients
5
Regulated industries
5+
Countries delivered
Behind the partnership

A decade in the field leaves marks a pitch deck cannot fake.

The end-to-end promise isn't marketing. It is a career path: years spent engineering the how inside production identity environments, spanning privileged access, IAM and IGA, identity federation and secrets management, then owning the what as platform architect and product owner, now defining the why alongside CISOs and boards.

That trajectory means every recommendation made at the governance table has already been tested against production reality, across the full identity estate: privileged access, identity lifecycle, federation and secrets. We only advise what we know how to deliver, and we only deliver what we know how to operate.

Said Hadj
Founder · Strategic Security Partner
CyberArk CCDE · Sentry · DefenderCertified
ISO/IEC 27001 PractitionerPECB
CISSPIn progress
French · Dutch · EnglishLanguages
Start a conversation

Where is the gap in your security programme?

An initial conversation carries no commitment. Share where your programme stands today, and we will provide a clear, considered view of where we can add value.

  • Direct line to a senior practitioner, not a sales desk
  • Confidential by default · NDA on request
  • A considered response, typically within two working days
Secure enquiry
Opens in your email client · or write directly to info@infosec-hs.com