// 02 · Operative profile

About the operator.

file://simone.deyzel/bio.md · v2026.07

TL;DR Cybersecurity consultant, ethical hacker and forensic investigator. Eighteen years in enterprise IT before the offensive work: governance, operations management, business systems analysis.

The certifications have stacked up fast this past year across governance, privacy and offensive security. ISO/IEC 27001 Internal Auditor (exam booked 28 August), IAPP CIPT (targeted November) and OSCP (targeted December) are booked or in progress. I'll keep going. Being three years out of date and not knowing it is the real risk in this field.

Most people here came up one side or the other. I came in through governance and business analysis, then went deep on offensive work. So I can be in a board briefing on Tuesday and a shell on Thursday, and clients don't need three separate consultants to cover posture, resilience and regulatory alignment.

Most of my attention right now is on DORA. I hold DORA Foundations and the DORA TLPT Tester certification, and I've read the TLPT RTS and the TIBER-EU framework properly rather than in summary. Threat-led penetration testing is where regulated finance and offensive security actually collide. That's where I want the work.

I've delivered across financial services, SaaS and professional services. Finding the risk, building both sides of the response, and making sure the security programme matches what the business is actually trying to do instead of what the framework says it should want.

How I work.

Security fails when it's bolted on at the end. The engineers don't talk to the auditors. The auditors don't talk to product. Nobody knows what marketing signed up for with a company card last quarter.

So I map the real workflows before recommending anything. It's slower and it looks less impressive in a kickoff, but advice that ignores how people actually work gets ignored right back.

I test like an attacker and document like an auditor. The first part is the fun half. The second is the half that survives a regulator asking questions eighteen months later.

I also build software, which taught me something consultants tend to miss: a security programme that depends on me being in the room stops working the day I leave.

Where I sit.

Porto, Portugal. English and Afrikaans fluently, Portuguese slowly. EU regulatory work mostly, with cross-border privacy experience running back to South Africa and POPIA. Remote-first for most engagements.

Outside the perimeter.

When I'm not in someone else's network with permission, I'm building HAX (hax.xcontent.red), a monitoring platform for analysing real-world hacking tools. Otherwise CTF practice, and more regulation than anyone reads voluntarily.

Simoné Deyzel CEH Master · CHFI · ISC2 CC
// 02.1

Capability areas.

// Analytical

  • Business requirement specifications
  • System architecture documentation
  • Workflow mapping and optimisation
  • Stakeholder translation

// Cybersecurity

  • Information security governance
  • Digital forensics and investigation
  • Offensive security and red team operations
  • Data privacy and protection (GDPR / POPIA)
SYS · OPERATIONAL
LOC: PT-PRT
CRYPTO: TLS 1.3 / AES-256
00:00:00Z
SIMONE@HAX · v2.0