Diego Borghgraef · Belgium

Defensive security. Attack surface. Cyber M&A.

Senior Cyber Security Consultant at EY, four years in. I also build the tooling I use for it.

Diego Borghgraef

Terminal

Type help for the list of commands. Arrow keys for history, Tab to autocomplete.

visitor@hsky:~

SESSION READY

Run help to list commands.

Enter a command. Use the up and down arrow keys for command history and Tab for autocomplete.

Expertise

Defend & monitor

01

Defensive security

SIEM and SOC implementation, detection engineering, threat hunting, SOAR, incident response and forensics. Sentinel, Splunk, CrowdStrike, KQL.

02

Cloud security

Azure, IAM, networking, CIS benchmarks, Kubernetes, Intune and DevSecOps reviews.

03

OT security

Asset discovery, vulnerability assessment and posture reviews in industrial environments.

Assess & govern

04

Cyberfootprinting

External exposure discovery, OSINT, breach intelligence, metadata analysis and the automation behind it.

05

Offensive security

Authorised penetration testing of web applications, infrastructure and mobile platforms, plus purple-team and physical-security exercises. Burp Suite, Nmap, Kali, OWASP.

06

Governance and M&A

ISMS, ISO 27001, NIS2 and CyFun, risk management and cyber due diligence.

Work

Recurring engagement types from four years of client delivery, plus the internal tooling built to support them.

M&A

Cyber due diligence for acquisitions

Cyber risk assessments run as part of acquisition due diligence, scoped and delivered across multiple regions, feeding findings into the deal timeline alongside the legal and financial workstreams.

ASM

Attack surface management tooling

Internal tooling that continuously maps a client's external footprint: domains, exposed services, certificates and leaked credentials, correlated into a single view of what an outsider can actually see.

SIEM / SOC

Sentinel implementation, end to end

Microsoft Sentinel deployments from architecture through go-live: log source onboarding, analytics rules, SOAR playbooks and handover to the client's own SOC team.

Monitoring

Sentinel health and cost monitor

An internal web app that watches Sentinel log sources and flags what needs attention: sources gone quiet, ingestion costs drifting out of range, connectors reporting unhealthy.

The card grid above generalises real engagement types; client names and specifics stay confidential.

Background

Four years at EY, on projects in government, transport, pharmaceuticals, food production and critical infrastructure. Most engagements move between architecture, investigation and hands-on testing, and end with something the client's own team has to be able to run.

All offensive, phishing, physical-security and acquisition assessments described on this site were carried out as authorised professional work.

Education

Bachelor Information Security, Thomas More

Languages

Dutch, French, English

Outside work

FPV drones and 3D printing - flight films and builds.