Security architecture consultancy

Security that is delivered, not performed.

Obsidian Cloud threat-models, design-reviews and governs enterprise and AI systems for regulated organisations. The output is work your team can act on the same week.

Our thesis

Innovation without governance is an unquantified liability.

20+

years across financial services, health, industrial, banking, consultancy and critical national infrastructure

2020

Obsidian Cloud established as an independent security consultancy

4

fixed-scope engagements, from a one-system review to a retained seat on your governance forum

Engagements

Four ways to work together

One sharp deliverable each. Most clients start with the Design Review Sprint. Engagements are sold under The Architecture Brief Advisory and invoiced through Obsidian Cloud.

01Start here

Design Review Sprint

STRIDE threat model, MITRE ATT&CK risk register, RiskScore findings and a mitigation roadmap for one system.

5 to 7 days · fixed scope
02

Compliance Gap Assessment

CIS Controls v8.1, SOC 2 or ISO 27001 control mapping against your actual estate, a prioritised remediation plan and an audit-readiness scorecard.

1 to 2 weeks · fixed scope
03

Agentic AI Threat Model

Fixed-scope review of one agentic or AI use case: MITRE ATLAS and STRIDE analysis, trust-boundary decomposition, risk register, prioritised mitigations and governance guardrails.

1 to 2 weeks · fixed scope
04

Fractional Principal Architect

A standing seat on your AI and agentic governance forum: design review gate, quarterly risk register refresh and on-call architecture sign-off.

Monthly · capped hours
SABSASTRIDEMITRE ATT&CKMITRE ATLASNIST AI RMFNIST CSF 2.0CIS Controls v8.1ISO 27001
The group

One consultancy. One publication.

Obsidian Cloud delivers the consultancy work and runs The Architecture Brief, the security-architecture publication that builds the audience and the authority behind it.

Commercial work is contracted under the Obsidian Cloud name. The publication stays editorially independent.

Obsidian CloudSecurity consultancy
The Architecture BriefPublication and advisory brand
The Architecture Brief

Built the defences. Decodes the failures.

A weekly security-architecture publication read by CFOs, CIOs and CISOs at regulated fintechs and enterprises. Each issue breaks down a real breach before the post-mortems are sanitised, and pairs it with the control or framework that would have closed it.

Leadership

Dwight Samuels, Chief Security Officer

Twenty years of hands-on security architecture across financial services, health, industrial, banking, consultancy and critical national infrastructure. Specialisms: data, platform, network, infrastructure and application security, identity and access management, Zero Trust, and agentic AI security.

CCSPTOGAF CertifiedMBCSPGDip Information Systems with Management Studies
Contact

Tell us the system you want tested

Name the breach, the AI use case or the control gap. We will reply with a scoped proposal. No form, no tracking: just email.