Top Gun Cyber
Engineering Risk Out — Not Just Documenting It

OT/ICS Security Assessments & Critical Infrastructure Advisory

Independent cybersecurity consulting for nuclear, energy, defense, and critical infrastructure organizations where the stakes are too high for checkbox compliance.

Q-Clearance (DoD Top Secret)
CISSP 15-Year Holder
GICSP SANS
CSSA SCADA Security Architect
FITSP Federal IT Security

Three pillars built on 20+ years of high-stakes operational experience

Assess deeply, identify critical consequences, engineer risk out — then translate findings into board-level decisions.

Security Assessments

Consequence-based risk methodology that identifies what actually matters — and engineers it out.

  • Plants assessed: Nuclear, Power Generation/Transmission/Distribution, Oil Pipeline/Storage, Hydro, Distribution, BESS, Wind, Data Center, Mining & Manufacturing
  • Nuclear reactor cybersecurity assessments (AP1000)
  • Black-box ICS/OT penetration testing
  • OEM product validation (GE, Siemens, Honeywell)
  • Tabletop exercises & attack path analysis
  • Digital twin & air-gapped AI assessments
  • NRC RegGuide 5.71, NEI 08-09, IEC 62443 alignment

Product & Commercialization Strategy

Bridge the gap between technical assessment and profitable go-to-market execution.

  • Cybersecurity portfolio development
  • Go-to-market strategy & revenue forecasting
  • M&A advisory & due diligence
  • International reseller & partnership negotiation
  • Data-driven business cases for C-suite approval
  • Sell-against strategies & competitive positioning

Crisis Leadership & Advisory

When incidents happen, experienced leadership makes the difference between containment and catastrophe.

  • Incident response strategy & playbook development
  • Ransomware & high-profile attack containment
  • Interim CISO / Deputy CISO advisory
  • SOC operations optimization & SLA management
  • MSSP strategy, RFP, and vendor selection
  • Board-level risk communication

Proof, not promises

Outcomes delivered across two decades of critical infrastructure security leadership.

100+

Critical plant systems assessed across Nuclear, Power, Oil & Gas, Mining & Manufacturing

$60M+

Above bookings plan at GE/Baker Hughes

$36M

IT/OT MSSP strategy at Newmont Mining

35K+

Endpoints managed at DHS/ICE SOC

Where I've Operated

Two decades across critical infrastructure, federal government, and Fortune 500 industrials.

Westinghouse Electric Idaho National Laboratory Schneider Electric GE / Baker Hughes Newmont Mining DHS / ICE Bureau of Reclamation Securicon

Ed Turkaly — Principal Consultant

Over 20 years of executive cybersecurity leadership across nuclear power, oil & gas, mining, data centers, and U.S. federal agencies (DoD, DHS). I've authored nuclear cybersecurity assessment plans for the AP1000 reactor, productized security portfolios like SecurityST™ and OTArmor™, directed 35,000+ endpoint SOC operations with 4-hour containment SLAs, and led $36M MSSP strategies while actively containing ransomware attacks.

My approach is simple: assess deeply, identify critical consequences, engineer risk out at the design phase, and translate findings into board-level decisions with clear ROI. Most consultants either assess OR build OR respond. I operate across all three.

Beyond the boardroom, I completed the 2,800-mile Tour Divide mountain bike race — the same grit I bring to containing high-consequence incidents.

Let's Talk

Available for assessment engagements, advisory roles, and interim CISO opportunities in nuclear, energy, defense, and critical infrastructure sectors.

turkaly@tgcyber.net