Matthew Carr
Matthew Carr presenting industrial control research to a conference audience
Disclosing industrial control research, DefCon.

Matthew Carr

I'm Matthew Carr, a CISSP-certified cybersecurity leader specialising in operational technology, critical infrastructure and offensive security. I work directly with executives and boards to turn technical security problems into clear business decisions.

CISSPWCITAtumcellOT and ICSOffensive securityBoard advisory

For more than fifteen years I have worked across critical infrastructure, national security and heavily regulated sectors. Before co-founding Atumcell I led adversary simulation and cyber-physical security research for large global organisations. I spent that time working out how to break industrial systems, which turns out to be useful preparation for telling a board which of their risks are real.

The research has been disclosed at DefCon and covered by the BBC, The Telegraph, The Register and Barron's. I have spoken on four continents, from a hacker conference in Sheffield to Gitex in Dubai. None of that matters to you on its own. It matters because it means when I tell you a risk is not worth your money, I have usually seen what happens when it is.

Disclosures and research

2024Progress MoveIt TransferCoordinated with the vendor and reported in the trade press.
2024Zoho DeskCoordinated with Zoho. Covered alongside the MoveIt finding.
2023N-able workgroup guidelinesVendor defaults that quietly exposed managed service providers.
2018Physically hacking SCADACyber-physical attack chains against industrial control systems.
2017ICS killswitchMulti-vendor industrial control research, disclosed at DefCon.

Selected speaking

Keynotes, panels and technical briefings across Europe, the Gulf, the United States and Asia-Pacific.

2024Start-Up and Tech, BaliSecurity as a strategic asset
2023Industrial Cyber Security Panel, USAIT controls against OT risk
2022Private Equity Conference, USACyber diligence in M&A
2020Expo 2020, DubaiSecurity at operational scale
2019Gitex, DubaiIndustry 4.0 attack surface
2019Gisec, DubaiCyber-physical attack chains
2019Logistics Security Event, UKTransport as attack surface
2018SteelCon, UKWhy reliable ICS networks are brittle
2018Confidence, PolandCyber security research

Press and commentary

BBC NewsCybersecurity research
The TelegraphMeltdown and Spectre
The RegisterPhysically hacking SCADA
Barron'sApple on-device scanning
Channel FuturesMoveIt and N-able disclosures
DatamationVulnerability scanning
LifewireDrone Wi-Fi research

Four things you can hold me to.

You work with me

There is no account manager and no rotating consultant. Atumcell's specialists support delivery behind me when the work needs hands, and I stay accountable for everything they produce.

I bring a recommendation

A list of findings just moves the risk onto your desk. I bring the finding, the options, what each one costs and what I would do, so a decision can be taken in the room.

The scope holds

The retainer has a boundary and I keep to it. Work outside it gets quoted separately, so your monthly cost stays at £4,950 and you are never surprised by an invoice.

I will tell you when to stop spending

Most of my career was spent attacking these systems. That makes it easy to say when a control is worth buying, and easier still to say when it is theatre.

CISO-as-a-Service is delivered by Matthew Carr and supported by Atumcell's cybersecurity specialists.

Start with a call.

Thirty minutes, confidential, and no obligation on either side. If the retainer is wrong for you I will say so on the call.

£4,950 per month. £5,000 onboarding assessment, waived on a twelve-month commitment.