GRC·LABS
Tailored Information Security

GRC·LABS

A private cybersecurity, governance and privacy practice run by a working CISO — not a brochure. Two decades of building, breaking and defending systems, distilled into a small set of services for organizations that can't afford to get security wrong.

20+ years across security & engineering Government & enterprise grade Hands-on, end to end
Portrait illustration of Yaniv Dadon Portrait illustration of Yaniv Dadon
SUBJECT // Y.DADONCISO
CISSP certification badge, ISC2 CISM certification badge, ISACA
CISSP · CISMISO 27001 LA · DPO
01 //

Capabilities

What we actually do. Every line below is backed by real engagements — security leadership, regulated environments, and live incidents handled under pressure.

Tailored — every service measured to your actual risk, never a template.
SEC · 01

Security Leadership

CISO-as-a-Service: security programs, policies and annual plans built around your real risk profile, with senior ownership rather than a checklist.

CISOstrategygovernance
GRC · 02

GRC & Compliance

Risk management, business impact analysis and regulatory alignment. ISO 27001 / 27035 / 22301 — taken all the way to certification.

ISO 27001riskaudit
IR · 03

Incident Response

Real-time handling of cyber incidents and crises: investigation, forensics, coordination and remediation — led personally, not delegated.

forensicscrisisresponse
DPO · 04

Privacy & DPO

Data protection governance and DPO services under both Israeli privacy law and the GDPR, with direct experience working alongside national privacy authorities.

DPOGDPRprivacy
ARC · 05

Secure Architecture

Security-by-design across servers, networks and applications — bridging R&D, DevOps and operations instead of bolting security on at the end.

designdevsecopsreview
OT · 06

IoT / OT / Embedded

Security for connected devices, control systems and embedded platforms — from the perspective of someone who has built them, not just audited them.

IoTOTembedded
ADV · 07

Tech & Digital Transformation

Technology advisory grounded in a CTO background — architecture, modernization and digital transformation guided by security from day one.

advisorytransformationcto
AI · 08

AI, Securely

Bringing AI into the organization without opening new attack surface — applied use, governance and the risks most teams discover too late.

aigovernancerisk
TLK · 09

Talks & Lectures

Speaking on cybersecurity, risk and the reality of the CISO seat — for teams, leadership and professional audiences. Technical when it needs to be.

speakingtrainingworkshops
// CREDENTIALS

Certified, audited, accountable.

The letters behind the work — held, not borrowed. Tailored security still has to stand up to standards.

CISSP
Certified Information Systems Security Professional(ISC)² · verified
CISM
Certified Information Security ManagerISACA · verified
ISO 27001
Lead Auditor · ISO/IEC 27001:2022IQC · 2024
DPO
Data Protection OfficerBar-Ilan Univ. · 2025
CISO
Chief Information Security Officer ProgramTechnion · 2018
CLOUD
Cloud EssentialsAWS · Google Cloud

CISSP and CISM are independently verifiable on Credly.

02 //

The Labs

Tailored — each one built for a specific problem, not pulled off a shelf.
RESTRICTED

We don't only advise. We build.

Behind the practice sits applied research — tools and systems we develop for the security, automation and connected-device problems we keep running into. Some becomes client work. Some stays in the lab a while longer.

// SENTINEL
Connected-device monitoring

Real-time telemetry and monitoring for IoT fleets — eyes on devices that usually run unwatched.

STATUS: ACTIVE
// BEDROCK
Resilient architecture & anomaly detection

High-availability system design with anomaly detection tuned to each environment, not a generic baseline.

STATUS: ACTIVE
// VAULT
Medical data registry portal

A management portal for sensitive medical registries — built where privacy and uptime both matter.

STATUS: IN PROGRESS
// REFORGE
CRM & portal rebuild automation

Automation that analyzes existing portals and CRM systems and rebuilds them, tailored to the organization.

STATUS: IN PROGRESS
// BEACON
GPS & LoRa positioning

Location and long-range telemetry over GPS and LoRa — tracking and sensing where conventional networks don't reach.

STATUS: ACTIVE
// ECHO
Acoustic source localization

Pinpointing the origin of a sound from sensor arrays — turning raw audio into a position on a map.

STATUS: CLASSIFIED
// ONGOING R&D
More in the lab — multidisciplinary work we can't show yet.
03 //

The Challenge

// ACCESS_CHALLENGE

For those who like to look closer.

A series of cyber puzzles is on the way — for the curious, the stubborn, and anyone who reads the things most people scroll past. Solve them, and you'll find your way in.

U2VjdXJpdHkgaXMgYSBwcm9jZXNzLCBub3QgYSBwcm9kdWN0Lg==
// first one's free — what's it hiding?
Establish contact

We tailor security to fit.

Great technology and sharp cyber, measured to your needs and cut to fit your organization — never off-the-rack. We take on a small number of clients at a time; tell us what you're protecting.