Security was never the department of no.
The stereotype is a function that blocks things. Anyone who has done the job knows it’s the opposite.
The work is to understand what the business is actually trying to do, weigh real risk against real reward, and find the version that can go ahead safely. Saying no is the failure case. Making yes possible is the job.
Twenty years of that — second line of defence at Tier-1 banks, Deputy CISO at a regulated trading technology firm, advising critical infrastructure operators through a national CII regime — is twenty years of one question. How does this business get what it wants without getting hurt?
Hunter McKenzie asks it about AI.
We put AI to work in the parts of a business where the data is sensitive and the mistakes are expensive. Same discipline, different lever: work out what the system touches and where that data must never go, then build the version that can go ahead. We also govern and assure AI that others have built — the same question asked from the other side of the table, and the reason we’re trusted with the first job.
Headquartered in Singapore, operating from Singapore, London and across Africa, with a partner network for in-country delivery. We work with boards, executive teams, regulators, growth-stage companies and owner-operated firms.
Our work is senior-led and it leaves things behind. Every engagement hands over reusable assets — the policies, playbooks, templates, runbooks and working systems teams rely on long after we’ve gone.
Trey Mujakperuo
Trey is the founder and principal — a cybersecurity and technology risk leader with more than two decades of international experience across financial services, technology and critical infrastructure, who now spends most of his time building AI systems for organisations that can’t afford to get data wrong.
Senior roles in London, Singapore and across global teams: Cybersecurity Manager (Technical Programme Management) at Grab; Deputy CISO and Head of Information Security at ION Trading and Lab49; VP for Technology Risk Management (Second Line of Defence) and Internal Audit at JP Morgan. Earlier, security leadership and architecture roles at Credit Suisse, Cable & Wireless International, RBS / ABN AMRO, Tesco and Lucent Technologies.
He has spoken on cybersecurity, data protection and digital opportunity for African media and conference platforms — CNBC Africa, the South African Broadcasting Corporation, and the inaugural Cyber Security Indaba in Johannesburg, where he addressed opportunities for youth in the Fourth Industrial Revolution.
A certified scuba instructor, which is incident response with better scenery. He builds and flies FPV drones and model aircraft, which is a generous way of saying he builds things, flies them into trees, and rebuilds them better. And he used to drum in ChasingEnvy, whose album 3 Second Memory is still on Spotify and Apple Music — a drummer’s whole job being to hold the timing while everyone else does the interesting part.
Security incidents, deep water, homemade aircraft and live music have more in common than you’d think. Preparation matters. Small mistakes compound. Staying calm beats looking clever.
Three regions, three regulatory worlds
United Kingdom & Europe
Tier-1 investment banking, regulated trading technology, large-format retail. Frameworks: FCA, PRA, GDPR.
South-East Asia
Singapore-based security leadership at a regional digital platform and a regulated trading technology firm; current AI delivery work with a Singapore commodity trading and structured finance firm. Frameworks: MAS TRM, Singapore Cybersecurity Act 2018, PDPA.
Africa & emerging markets
Sustained engagement with African regulators, media and capability programmes, with delivery across Nigeria, South Africa and the broader continent. Frameworks: NDPA, POPIA, regional DPAs.
Eight principles
The first four are how we engage. The last four are how we build — and they’re the same four on the home page, because a philosophy that doesn’t show up in the architecture isn’t a philosophy.
Senior-led, always.
The people who scope your engagement are the people who deliver it. No selling by partners and delivering by graduates.
Plain English over jargon.
If the board can’t act on it, we haven’t delivered it.
Fixed fee, and we show the value first.
We quantify what a problem currently costs before proposing to solve it. If the return isn’t obvious, the scope is wrong and we’ll say so.
We’ll talk you out of things.
The most valuable recommendation we’ve made was to not build something. That’s part of the service, not a failure of it.
The data boundary comes before the feature list.
What the system touches, and where that must never go, decided before what it does.
AI prepares, a human approves.
Nothing consequential publishes itself. Arithmetic in code, judgement in the model, sign-off with a named person.
Boring, hireable stacks — and you own it at the end.
Components you could administer yourself, transferred to accounts in your name, keys rotated, runbooks written.
Evaluation, not just deployment.
AI systems drift. Live ones get a versioned test set and groundedness checks on anything board- or client-facing.
Being clear about this saves everyone a call
We don’t assure our own builds.
Where we built the system, our review of it is a quality gate, not independent assurance — and we’ll say so unprompted. If you need independence on something we built, we’ll help you scope it elsewhere.
We don’t sell licences or take vendor commission.
Tool and model subscriptions are yours, bought direct, in your name. We have no financial interest in which one you choose.
We don’t put regulated data through tools that weren’t agreed for it.
Not for a demo, not for a proof of concept, not to save a week.
We don’t build things we can’t hand over.
If the result would be a system nobody at your company could operate or leave, it’s the wrong system.
We don’t do staff augmentation.
We deliver scoped engagements with a defined end. The retainer that follows is optional and cancellable.
A senior core with a partner network around it
Every engagement is scoped and led by a principal. Around that, we draw on a curated network for specialist legal and regulatory counsel, technical implementation, in-country delivery, and additional build capacity on programme-scale work. We think this is the right shape for the work, not a compromise on it.
Capacity flexes to the engagement.
A multi-module build programme gets the delivery capacity it needs. A two-week policy pack doesn’t get padded to justify a team.
Specialists are specialists.
Singapore counsel on a Singapore compliance question. Nigerian counsel on NDPA. We’d rather bring the right person in than claim the expertise ourselves.
The advisory stays independent.
We hold no reseller agreements and take no vendor commission, so the tooling recommendation is the honest one.
Continuity is a design requirement, not a promise.
Runbooks are written during the build, not after. Documentation, credentials and handover are structured so an engagement survives any individual’s absence — including ours. We apply the bus-factor test to ourselves before we apply it to your systems.
