CISSP AdvisorySecurity Advisory
We provide information security advisory and consulting services by an ISC2-certified CISSP professional. We do not accept fixed-price contract (請負) work. We are available under quasi-delegation contracts (準委任), advisory retainers, or spot consulting engagements.
CISSP requires a minimum of five years of verified, hands-on security experience. The exam — an adaptive test of up to 150 questions delivered in English — is designed to assess judgment and decision-making, not memorization. After certification, holders must complete 120+ CPE credits every three years and uphold the ISC2 Code of Ethics. This combination of experience requirements, continuous education, and ethical accountability is what makes a CISSP a credible and trustworthy basis for independent third-party verification.
I've written about what actually changed after earning CISSP — from both an engineer's and a business owner's perspective — on Qiita (Japanese).
Fractional CISO Services
A Fractional CISO gives your organization access to senior security leadership on a retainer or spot-consulting basis — without the overhead of a full-time hire. Ideal for SMEs, startups, and foreign-owned companies in Japan that need strategic security direction but don't require a dedicated full-time CISO.
- Security strategy and roadmap development
- Executive-level risk reporting and security policy definition
- Incident response decision support and stakeholder communication
- Vendor and third-party security risk assessment
Cybersecurity Rating (SCS ★3) / Verification by an SCS Security Expert
We support companies preparing for ★3 under Japan's Supply Chain Security (SCS) Evaluation Framework, promoted by METI. The ★3 tier is a self-assessment verified by an SCS Security Expert (SCSセキュリティ専門家 — the framework's official designation), who independently reviews and signs off on 83 self-assessment criteria.
To register as an SCS Security Expert, a professional must hold one of the accepted credentials — CISSP, Registered Information Security Specialist (登録セキスペ), CISM, CISA, Certified Information Security Auditor, or ISO/IEC 27001 Lead Auditor — and complete the training designated by the framework. We meet the credential requirement as a CISSP holder and intend to register in line with the framework's schedule. The framework has not launched yet, so verification and sign-off will be available only after launch — but preparation and gap analysis can begin now.
- Gap analysis and advisory for SCS ★3 certification
- Review and guidance on 83-item self-assessment checklist
- Designing operations that leave evidence — annual reviews, access-right audits, asset inventories
- Verification and sign-off as an SCS Security Expert (after registration, once the framework launches)
- Continuous improvement support after certification
Published schedule (based on IPA materials, as of August 2026): December 2026 — training providers and evaluation bodies announced; around January 2027 — SCS Security Experts published; around March 2027 — ★3 and ★4 operations and applications open. Dates are subject to change by the framework operator.
Field-Based Expertise That Big Firms Can't Match
Large consulting firms tend to rely on document-based assessments because they have never worked in actual development environments. We bring hands-on perspective from both well-run projects and projects with serious security gaps — which means we know what real risks look like on the ground.
- IoT & OT Security: Firmware development on ESP32 and PIC microcontrollers, PCB circuit design through Gerber data and board assembly. We understand hardware-layer risks that cloud-only consultants never see.
- Real-World Risk Patterns: Hardcoded SSH keys, credentials committed to repositories, and other field-common vulnerabilities are familiar territory. We provide substantive verification — not rubber-stamping — that prevents self-assessments from becoming mere formalities.
- Cloud to Edge: Combining AWS cloud architecture with embedded and hardware development, we can assess risk across the full supply chain — from the data center to the device.
Security Advisory Services
- Security assessment and configuration audit for cloud (AWS) environments
- Network and access design support based on Zero Trust model
- Incident Response Plan (IRP) and risk management support
- VPN and IoT system security design and communication defense advisory
- Cloud security framework establishment, training, and continuous improvement support
Contract Terms & Fees
Contract Type: Advisory retainer or spot consulting
Fees: From JPY 100,000 per month (excl. tax; approx. 8 hours/month,
additional hours billed separately). Spot consulting also available.
For inquiries and quotations, please contact us through
this form.
