Incident Response Leadership
Incident command, triage, containment coordination, evidence handling, executive updates, and the post-incident improvements that actually stick.
ASK ANYTHING
Most security leaders do one or the other. Ask my digital twin about either — the war room or the codebase. It's built to tell you the truth, not the pitch.
OPEN TO SENIOR SECURITY LEADERSHIP ROLESMEET THE TWIN
A synthetic avatar — it introduces itself as Todd's digital twin, not Todd.
CURRENT FOCUS
Strongest fit: IR/SecOps leadership, security executive (CISO/VP), and AI security leadership — and I'm open to relocation. RedCon1 Response is how I stay close to the work between roles: advisory engagements, the hands-on forensic tooling I build, and writing that keeps my judgment sharp and current.
I'm an incident response and security operations executive — a decade leading incident command, digital forensics, and security operations across Fortune 15 healthcare, enterprise SaaS, marketplace, and defense-adjacent environments, after a first decade in business administration and finance.
I wrote The First 72 Hours: How Leaders Survive a Cyber Crisis and publish a newsletter of the same name on the decisions that determine whether a cyber crisis becomes a catastrophe — including two ideas I return to often: "forensic debt" and "confidence laundering."
LEADERSHIP FIT
Incident command, triage, containment coordination, evidence handling, executive updates, and the post-incident improvements that actually stick.
Recovery assumptions, backup and restoration priorities, ransomware readiness, crisis governance, and response planning driven by business impact rather than checklists.
Escalation design, ownership models, metrics, playbooks, and response workflows — practical process improvement that doesn't start with buying another tool.
AI security management, agentic SOC design, human-approved automation, and the governance layer organizations need when machines move faster than people can decide.
Agent Autopsy, the AI-agent forensics engine I built — Agentless, zero-egress, air-gap-native: when an autonomous agent causes a security incident, this is how you prove what it did — with a tamper-evident evidence chain, not a confident guess. Live demo →
Containment Command Lab — Agentic AI containment decision support for Incident Commanders. Machine-speed reasoning, human-approved action — the Judgment Bottleneck thesis, running as code. Live demo →
Air-Gapped Forensic Analyst — Local-LLM DFIR analyst for live Windows triage. Every finding traceable to a deterministic forensic tool; evidence never leaves the box. Live demo → · Source →
The First 72 Hours: How Leaders Survive a Cyber Crisis (Amazon) — the book, written for the leaders who will be in the room.
The First 72 Hours — the newsletter. The thinking, before you need it.
Earlier research (2017): A Novel Approach to Determining the Optimal Level of Investment within Information Security — applying Bayesian inference and Value-at-Risk (Marginal, Incremental, and Component VaR) to security investment decisions against the Gordon-Loeb optimum, years before risk quantification went mainstream in security practice. The judgment-and-evidence thread runs back a decade. Read on LinkedIn →
LET'S TALK
The best fit is an organization that wants a calm, operationally credible leader — someone who can sit with the technical team, brief the board, raise the floor on readiness, and build the response discipline that holds up before pressure finds the gaps.
Todd built this twin himself — an incident-response exec who ships AI.
Conversations may be logged to improve the twin.