// Platforms in the field
- Independent advisor
- Networks
- Physical security
- Cybersecurity
Independent advice on networks, physical security, and cybersecurity.
Hans Study is an independent network and security consultant based in Ontario, Canada. Boutique work in controls, security systems, and the infrastructure underneath them. Hardening and tuning specialist for Microsoft Windows, Cisco, Aruba, and Genetec. Clients engage Hans when the problem is complicated and they need someone who will tell them what is true, not what is profitable to say.
IndependentNo reseller margin
CurrentCISSP
Since 2019NIST 800-171
Networks
Enterprise, OT, and control networks. Topology, segmentation, routing, wireless, and the security architecture underneath. Cisco, Aruba, ALE, and Juniper.
Explore network work
Physical security
Cameras, access control, intercom, and VMS. Genetec Security Center, C-CURE, Milestone, Avigilon, and Axis. Specified for the environment, not copied from the last job.
Explore physical security
Cybersecurity
Hardening, tuning, and compliance. Windows baselines, switch and firewall hardening, CMMC, CPCSC, and NIST. Where the stakes are high and the margin for error is small.
Explore security work
Now available
Managed network and server support, and fractional CISO retainers.
Preventative monitoring, patching, and maintenance for the infrastructure a business actually depends on, on a monthly plan, with on-demand remote support when something breaks. Senior security leadership on retainer for organizations that need a CISO's judgment without a full-time hire. Independent, CISSP-certified, delivered remotely.
Networks and systems08 services
Hands-on technical work, done independently.
The delivery side of the practice. Design, review, troubleshoot, harden, and stabilize the systems and networks an operation runs on. Independent of reseller and integrator incentives. Hans works with integrators and end clients to make the system work for them.
All consultingGenetec Security Center
Independent Genetec consulting. Architecture review, sizing, federation, deployment oversight, and troubleshooting. Not a reseller, not an integrator. No license revenue.
CCTV and access control
Vendor-agnostic design and review across Genetec, C-CURE, Milestone, Avigilon, Axis, and Bosch. The system and the network it runs on, treated as one problem.
Physical security design
Design and gap assessment for access control, CCTV, and integrated physical security. From threat model to a specification an integrator can build to.
Enterprise network architecture
Most platform problems are network problems wearing a costume. Topology, segmentation, routing, and wireless designed properly from the start, not bolted on later.
Industrial and OT networks
Segmentation, the iDMZ, passive monitoring, and secure remote access applied in a way that respects how plant systems actually run.
Data centre and cabling
Physical-layer work is cheap to fix at design and expensive after construction. Pre-construction review catches it before it becomes an installed fact.
ICAT design and project advisory
Integrated facility systems advisory, owner's representative services, and commissioning oversight for complex physical security and technology projects.
Mentorship and technical guidance
For integrators on complex bids and practitioners closing a knowledge gap. An independent technical voice on a project already in progress.
Advisory05
Senior security judgement, when the decision matters.
The leadership and strategy side. Fractional CISO, security and technology strategy, defence supply chain compliance, and the OT, IT, and physical security boundary. Independent, with nothing to sell you but the advice.
Talk through a decisionFractional CISO and vCISO
Retained, part-time security leadership for organizations without a full-time CISO. Strategy, board reporting, program ownership, risk, and incident oversight.
Strategic security and technology
Independent strategy for the decisions that are expensive to reverse. Roadmaps, architecture direction, platform selection, and due diligence. Project-based and vendor-neutral.
CMMC and CPCSC readiness
Scoping, gap assessment, and attestation support for Canadian and cross-border defence suppliers. NIST 800-171 since 2019, not a framework Hans is reading up on.
OT/IT convergence security
The physical, OT, and IT boundary, assessed and secured by someone who reads both sides. Where a lot of real exposure hides.
Security assessments and reviews
Independent program and gap assessments against NIST 800-171, NERC CIP, ISO 27001, and CIS Controls, plus architecture, hardening, and project oversight.
Not sure which fits?
A scoping call sorts out whether this is advisory, consulting, or both.
Book a scoping call
Sectors
Where this work usually lands.
Different sectors fail in different ways. What an airport needs from a security network is not what a water utility needs, and neither looks like a defence supplier under audit. These are the environments the practice works in most.
About Hans Study
Technical depth across multiple disciplines.
I started the way a lot of people in this field do. Fixing computers for friends and family, then picking up work installing small business networks and CCTV systems. By 2010 that had grown into independent network and security work full time. The 15+ years since are where the depth comes from.
01
Technical depth across 3 disciplines
Enterprise networks, cybersecurity, and physical security. Each understood well enough to advise on, and to see how decisions in one affect the others.
02
15+ years of real experience
Across sectors and project types, including the ones that went sideways before Hans helped fix them. That is how the risks get caught early.
03
The read is candid
Recommendations do not change based on who is selling. Where a vendor got something right, that gets said; where they did not, that gets said too.
04
Advice that follows through
A recommendation that ends at the design phase is a document, not advice. Engagements are scoped to carry through delivery and the first weeks of real-world operation.
15+Years in the field
3Disciplines, one consultant
2019NIST 800-171 work since
0License or resale revenue
Genetec Security Center
Independent Genetec Security Center work, in depth.
Architecture review, sizing, federation, hardening, and post-deployment troubleshooting on Security Center. Not a Genetec partner. No license revenue. Start with a structured Health Check, or read the field writing first.
StudyByt3s
Recent technical writing
physical-security
What a Drone Adds to a Perimeter Security Assessment
An RPAS pass produces evidence a walk-down cannot: true camera sightlines, fence-line condition in sequence, and mountin...
compliance
The Flat Network Problem: Level 1 From Inside a 30-Person Shop
CAD, CNC controllers, office PCs, and the owner's laptop on one flat network behind a home router. Getting from there to...
compliance
Flow-Down Is Coming: What Your Prime Will Ask Before They Can Bid
CPCSC will not stop at the prime. Allied programs already cascade cyber requirements down every subcontract tier. What l...
- IndependentNo resale
- OntarioCanada
- RemoteCanada and US
// Next step
Bring the problem. Start with a conversation.
A scoping call first, then a written scope and quote before any billable work.
Start a conversation Contact
Most engagements start with a conversation about what the organization is trying to accomplish.
If you have a project coming up, a system that is not performing the way it should, or an upcoming procurement that needs independent technical input, reach out directly. Project work is scoped and quoted up front. Managed care and fractional CISO run monthly.
- Emailcontact@hans.study
- Based inOntario, Canada
What does Hans Study do?
Hans Study is an independent network and security consultant based in Ontario, Canada. The work is boutique: enterprise networks, OT and ICS, controls and security systems, and the infrastructure underneath them. Hardening and tuning specialist. Primary stacks are Microsoft Windows, Cisco, Aruba, and Genetec Security Center, with regular work across Axis, Bosch, Milestone, Avigilon, C-CURE, Fortinet, Palo Alto, Juniper, and Alcatel-Lucent. Vendor agnostic. No equipment sales, no margin on what is specified, and no commission tied to platform selection.
What does "independent" actually mean here?
No commissions. No product margin. No financial stake in what gets specified. No margin on equipment. If Cisco is the right answer for the environment, that is the recommendation. If the right answer is Aruba, ALE, or Juniper, that is the recommendation. Hans has direct hands-on experience across the major platforms in each category and selects on fit for the deployment, not on which vendor pays a commission.
What is the minimum project size?
Engagements range from a half-day technical second opinion on a vendor proposal to multi-month owner's representative engagements on complex builds. Project work is scoped and quoted per engagement; managed care and fractional CISO run on monthly retainers. Reach out with what the project looks like and the right scope of involvement gets worked out from there.