Top Gun Cyber
Engineering Risk Out — Not Just Documenting It

OT/ICS Security Assessments & Critical Infrastructure Advisory

Independent cybersecurity consulting for nuclear, energy, defense, and critical infrastructure organizations where the stakes are too high for checkbox compliance.

Q-Clearance (DoD Top Secret)
CISSP 15-Year Holder
GICSP SANS
CSSA SCADA Security Architect
FITSP Federal IT Security

Three pillars built on 20+ years of high-stakes operational experience

Assess deeply, identify critical consequences, engineer risk out — then translate findings into board-level decisions.

Security Assessments

Consequence-based risk methodology that identifies what actually matters — and engineers it out.

  • Plants assessed: Nuclear, Power Generation/Transmission/Distribution, Oil Pipeline/Storage, Hydro, Distribution, BESS, Wind, Data Center, Mining & Manufacturing
  • Nuclear reactor cybersecurity assessments (AP1000)
  • Black-box ICS/OT penetration testing
  • OEM product validation (GE, Siemens, Honeywell)
  • Tabletop exercises & attack path analysis
  • Digital twin & air-gapped AI assessments
  • NRC RegGuide 5.71, NEI 08-09, IEC 62443 alignment

Product & Commercialization Strategy

Bridge the gap between technical assessment and profitable go-to-market execution.

  • Hired, mentored & trained a global team of pre-sales cybersecurity architects
  • Cybersecurity portfolio development
  • Go-to-market strategy & revenue forecasting
  • M&A advisory & due diligence
  • International reseller & partnership negotiation
  • Data-driven business cases for C-suite approval
  • Sell-against strategies & competitive positioning

Crisis Leadership & Advisory

When incidents happen, experienced leadership makes the difference between containment and catastrophe.

  • Incident response strategy & playbook development
  • Ransomware & high-profile attack containment
  • Interim CISO / Deputy CISO advisory
  • SOC operations optimization & SLA management
  • MSSP strategy, RFP, and vendor selection
  • Board-level risk communication
  • Multi-year program business case investments

Proof, not promises

Outcomes delivered across two decades of critical infrastructure security leadership.

100+

Critical plant systems assessed across Nuclear, Power, Oil & Gas, Mining & Manufacturing

$60M+

Above bookings plan at GE/Baker Hughes

$36M

IT/OT MSSP strategy at Newmont Mining

35K+

Endpoints managed at DHS/ICE SOC

Invited Speaking & Recognition

Presenting on supply chain security since before it was a mainstream industry focus — invited by international institutions and premier ICS conferences.

"Averting Supply Chain Attacks" — S4x19

Main Stage Presentation · S4 Conference (Dale Peterson) · Watch the talk →

Invited Speaker — United Nations: Supply Chain Security Presented — International Atomic Energy Agency: Supply Chain Security (internal session)

Where I've Operated

Two decades across critical infrastructure, federal government, and Fortune 500 industrials.

Naval Air Systems Command (NAVAIR) Pentagon Westinghouse Electric Idaho National Laboratory Schneider Electric GE / Baker Hughes Newmont Mining DHS / ICE Bureau of Reclamation Securicon

Ed Turkaly — Principal Consultant

Over 20 years of executive cybersecurity leadership across nuclear power, oil & gas, mining, data centers, and U.S. federal agencies (DoD, NAVAIR, Pentagon, DHS). I've authored nuclear cybersecurity assessment plans for the AP1000 reactor, productized security portfolios like SecurityST™ and OTArmor™, directed 35,000+ endpoint SOC operations with 4-hour containment SLAs, and led $36M MSSP strategies while actively containing ransomware attacks.

My approach is simple: assess deeply, identify critical consequences, engineer risk out at the design phase, and translate findings into board-level decisions with clear ROI. Most consultants either assess OR build OR respond. I operate across all three.

Beyond the boardroom, I completed the 2,800-mile Tour Divide mountain bike race — the same grit I bring to containing high-consequence incidents.

Let's Talk

Available for assessment engagements, advisory roles, and interim CISO opportunities in nuclear, energy, defense, and critical infrastructure sectors.

turkaly@tgcyber.net