Core Service

Independent Security Governance Advisory

Security governance is a leadership responsibility. Keown & Associates provides independent security advisory to boards, executive leadership, and risk owners who require structured counsel — free from vendor relationships, operational bias, and internal assumptions.

Our role is not to manage security operations. It is to ensure that the people responsible for organisational decisions have clear, defensible, and independent guidance on security risk.

What Advisory Covers

Advisory engagements are structured around the decisions, governance requirements, and oversight obligations of leadership — not around operational security tasks. The scope varies by organisation and context, but centres on five areas.

Security Governance

Establishing the policy frameworks, oversight mechanisms, accountability structures, and reporting lines that enable security to function as a managed organisational discipline — not an isolated operational function. We work with leadership to define what good governance looks like in practice and how it connects to broader enterprise risk management.

Programme Direction and Oversight

Providing independent strategic direction to security functions and their leadership. This includes evaluating programme design, identifying gaps in coverage or accountability, aligning security objectives with organisational priorities, and supporting the development of defensible, evidence-based security strategy.

Assurance and Independent Review

Offering boards, audit committees, and risk owners independent assurance that security programmes are performing as intended — not just as reported. We evaluate whether controls are effective in practice, whether governance structures are functioning, and whether risk is being managed proportionately.

Architecture and Investment Counsel

Advising on major security investments, capital programmes, and architectural decisions — from new builds and significant refurbishments to technology procurement and integrator selection. Our counsel is vendor-agnostic: we have no commercial interest in the outcome and no relationships with suppliers or system providers.

Board and Executive Decision Support

Retained advisory providing boards, directors, and senior executives with independent security risk insight to support informed decision-making. We translate complex security environments into clear, concise positions that leadership can act on — structured for governance, accountability, and strategic clarity.

Who Engages Advisory Services

Advisory clients share a common need: independent, expert security counsel at the level at which decisions are made. They are not looking for operational security management — they are looking for strategic clarity and governance-ready direction.

  • Boards and directors seeking independent assurance on security risk and programme performance
  • Chief executives and senior leadership requiring objective security counsel without vendor entanglement
  • Risk, compliance, and audit functions responsible for security oversight and reporting
  • Legal counsel and family offices managing complex security environments for high-profile individuals or organisations
  • Risk owners facing governance pressure from regulators, insurers, or institutional stakeholders

What Advisory Delivers

Advisory engagements are structured to produce informed decisions at leadership level — not reports that accumulate without action. The output is clarity, direction, and governance-ready documentation.

  • Independent position: analysis that is free from vendor relationships, product portfolios, or operational bias
  • Governance alignment: security positioned within enterprise risk management, board reporting, and accountability structures
  • Strategic coherence: security objectives connected to organisational priorities, not defined in operational isolation
  • Decision-ready insight: complex security environments translated into concise, structured positions for leadership
  • Defensible rationale: documented reasoning structured to withstand board and audit committee review, and external assurance requirements
Desmond Keown, CPP — Practice Principal, Keown & Associates
Practice Principal

Independent counsel led by Desmond Keown, CPP

Advisory engagements are led by Desmond Keown, CPP, bringing structured security risk judgement to board, executive and senior management decisions involving protective strategy, assurance, governance and risk treatment.

When to Engage

Advisory is most valuable when executive leadership faces decisions with significant security or governance implications — where the cost of a misjudgement is material and independent counsel is essential.

  • When leadership needs independent security judgement, free from vendor or operational bias
  • When security spend, strategy or governance arrangements are unclear or contested
  • When assurance is required before major decisions, investments or organisational change
  • Board or audit committee seeking independent assurance on security risk exposure or programme effectiveness
  • Governance pressure from regulators, insurers, or institutional investors requiring demonstrable oversight
  • Leadership uncertainty about whether the security function is delivering appropriate value and coverage
  • Major investment decisions requiring objective evaluation of proposals, vendors, or system architectures
  • Post-incident review requiring independent analysis of what failed, why it failed, and what accountability exists
  • Security programme restructuring, including new leadership appointments, outsourcing decisions, or function redesign
  • Significant organisational transitions — mergers, acquisitions, new market entry — that alter the threat landscape

Advisory and Assessment

Advisory engagements frequently draw on structured security risk assessment findings as an evidential input. Where an independent physical assessment of a specific environment is required, this is conducted as a separate, dedicated engagement. Learn more about our security risk assessments.

Discuss an Advisory Requirement

Engagements are structured discreetly and tailored to the strategic requirements of executive leadership and boards.