日本語 | English

CISSP AdvisorySecurity Advisory

We provide information security advisory and consulting services by an ISC2-certified CISSP professional. We do not accept fixed-price contract (請負) work. We are available under quasi-delegation contracts (準委任), advisory retainers, or spot consulting engagements.

CISSP requires a minimum of five years of verified, hands-on security experience. The exam — an adaptive test of up to 150 questions delivered in English — is designed to assess judgment and decision-making, not memorization. After certification, holders must complete 120+ CPE credits every three years and uphold the ISC2 Code of Ethics. This combination of experience requirements, continuous education, and ethical accountability is what makes a CISSP a credible and trustworthy basis for independent third-party verification.

I've written about what actually changed after earning CISSP — from both an engineer's and a business owner's perspective — on Qiita (Japanese).

Fractional CISO Services

A Fractional CISO gives your organization access to senior security leadership on a retainer or spot-consulting basis — without the overhead of a full-time hire. Ideal for SMEs, startups, and foreign-owned companies in Japan that need strategic security direction but don't require a dedicated full-time CISO.

  • Security strategy and roadmap development
  • Executive-level risk reporting and security policy definition
  • Incident response decision support and stakeholder communication
  • Vendor and third-party security risk assessment

Cybersecurity Rating (SCS ★3) / Verification by an SCS Security Expert

We support companies preparing for ★3 under Japan's Supply Chain Security (SCS) Evaluation Framework, promoted by METI. The ★3 tier is a self-assessment verified by an SCS Security Expert (SCSセキュリティ専門家 — the framework's official designation), who independently reviews and signs off on 83 self-assessment criteria.

To register as an SCS Security Expert, a professional must hold one of the accepted credentials — CISSP, Registered Information Security Specialist (登録セキスペ), CISM, CISA, Certified Information Security Auditor, or ISO/IEC 27001 Lead Auditor — and complete the training designated by the framework. We meet the credential requirement as a CISSP holder and intend to register in line with the framework's schedule. The framework has not launched yet, so verification and sign-off will be available only after launch — but preparation and gap analysis can begin now.

  • Gap analysis and advisory for SCS ★3 certification
  • Review and guidance on 83-item self-assessment checklist
  • Designing operations that leave evidence — annual reviews, access-right audits, asset inventories
  • Verification and sign-off as an SCS Security Expert (after registration, once the framework launches)
  • Continuous improvement support after certification

Published schedule (based on IPA materials, as of August 2026): December 2026 — training providers and evaluation bodies announced; around January 2027 — SCS Security Experts published; around March 2027 — ★3 and ★4 operations and applications open. Dates are subject to change by the framework operator.

Field-Based Expertise That Big Firms Can't Match

Large consulting firms tend to rely on document-based assessments because they have never worked in actual development environments. We bring hands-on perspective from both well-run projects and projects with serious security gaps — which means we know what real risks look like on the ground.

  • IoT & OT Security: Firmware development on ESP32 and PIC microcontrollers, PCB circuit design through Gerber data and board assembly. We understand hardware-layer risks that cloud-only consultants never see.
  • Real-World Risk Patterns: Hardcoded SSH keys, credentials committed to repositories, and other field-common vulnerabilities are familiar territory. We provide substantive verification — not rubber-stamping — that prevents self-assessments from becoming mere formalities.
  • Cloud to Edge: Combining AWS cloud architecture with embedded and hardware development, we can assess risk across the full supply chain — from the data center to the device.

Security Advisory Services

  • Security assessment and configuration audit for cloud (AWS) environments
  • Network and access design support based on Zero Trust model
  • Incident Response Plan (IRP) and risk management support
  • VPN and IoT system security design and communication defense advisory
  • Cloud security framework establishment, training, and continuous improvement support

Contract Terms & Fees

Contract Type: Advisory retainer or spot consulting
Fees: From JPY 100,000 per month (excl. tax; approx. 8 hours/month, additional hours billed separately). Spot consulting also available.
For inquiries and quotations, please contact us through this form.