People

New threats.
Established judgement.

Ostiary is a UK human risk advisory. The threats are new; the method is not. Every recommendation rests on established research, observed evidence and the founders’ first-hand experience.

Founders

The people who do the work

Jamie Woodruff

Social engineering and keynotes

Ethical hacker and social engineering specialist. Jamie shows boards how attackers use trust, urgency and authority to get through well defended organisations.

Aaron Waywell

Security culture and behavioural science

Aaron leads security culture and behavioural science inside a major UK bank. He designs programmes that make the safe decision the easy one, and shapes Ostiary’s assessment and culture work.

Daniel McClure Fisher

Commercial, technology and AI

Daniel runs Dead Simple Computing, a managed IT provider in Reading, and leads Ostiary’s AI training. CISSP, MCIIS and Cyber Essentials Assessor, and an NCSC Assured Cyber Advisor through Dead Simple Computing.

How we work

The lines we hold

Blame-free

We look at process and conditions, not individuals. Findings are aggregated and no one is named.

Evidence first

Our view comes from structured assessment and observed reality. If a concern is not borne out, we say so.

Authorised and discreet

Every test has written authorisation and agreed rules of engagement. Sensitive findings stay with the people you nominate.

Start a conversation

Begin with a confidential briefing.

Discreet, candid and without obligation. Tell us what prompted the question and we will tell you honestly whether we can help.

Book a board briefing