Simon Chapman

Offensive security leader, adviser and business co-founder.

I help founders, security leaders and investors fix operational problems in offensive security businesses and teams.

My work draws on more than 25 years in offensive security, including technical delivery, senior leadership and co-founding a penetration testing business.

Discuss your teamLinkedIn profile
Portrait of Simon Chapman

Recommendations have to work in a real business.

I have dealt with the practical consequences of hiring, utilisation pressure, client expectations and senior people becoming bottlenecks.

Technical work, leadership and building a business

I have worked as a developer, penetration tester, network engineer, technical architect, PCI QSA and Head of Pen Testing. I also co-founded and built a penetration testing business.

That background shapes how I approach a problem. I understand the technical work, the demands placed on consultants and the commercial consequences when delivery breaks down. Recommendations have to work inside a real business, with revenue targets, deadlines and clients to satisfy.

When I get involved

I am usually brought in when a business needs experienced offensive security leadership or an independent operational view, without another permanent senior hire.

Sometimes delivery is inconsistent, client communication is weak or senior consultants have become bottlenecks. Sometimes the business has grown, but its management capacity, career structures and delivery practices have not kept pace. My work helps establish what needs to change, who should take responsibility and how to judge whether the intervention is working.

Through Conversec, I support specialist pentest firms, MSSPs, cyber security consultancies, internal teams and PE-backed businesses. Engagements range from focused reviews and consultant development to ongoing fractional leadership.

Working with investors and acquirers

I help investors and acquirers understand how an offensive security capability actually operates: whether it can scale, where operational risk sits, how dependent it is on key people and how it could fit within a wider cyber security business.

This includes acquisition reviews, post-acquisition integration and examining how offensive security should operate alongside other cyber services.

Explore acquisition and integration support

Areas of expertise

  • Offensive security delivery leadership
  • Operating models and readiness to scale
  • Acquisition reviews and post-acquisition integration
  • Management development and reducing founder dependency
  • Consultant development, scoping and quality assurance

Examples of my work.

Writing and practical guidance

My articles examine delivery and leadership problems and explain the decisions involved. I label hypothetical examples, refer to standards where relevant and review guidance when my assessment changes.

Read the articles on team performance, reporting and QA, consultant development and offensive security leadership.

Discuss the decisions ahead for your business.

Tell me about the situation, the decisions you need to make and where experienced leadership or an independent view would help.