Diego Borghgraef · Belgium

Security built for clear decisions.

Senior Cyber Security Consultant at EY focused on Defensive Security, Cyberfootprinting and M&A Cyber Assessments. Practical experience across cloud, SOC, OT and authorised offensive testing.

  • 4 years at EY
  • Defensive · Cyberfootprinting · M&A
  • NL · FR · EN
Diego Borghgraef

01 / Selected work

Security tooling built for the work itself.

Purpose-built applications that replace fragmented fieldwork with structured, repeatable workflows.

Internal security platform Attack-surface intelligence

Attack Surface Management Platform

A platform that maps an organisation’s internet-facing footprint, enriches it with external intelligence and turns scattered signals into prioritised exposure.

The platform builds an evidence-led view across domains, infrastructure, identity leakage, public data and observed technology. Automated collection establishes breadth; analyst validation confirms ownership, removes noise and adds the context required for useful risk decisions.

  • Domains, subdomains & certificates
  • Ports, services & applicable CVEs
  • DNS, mail & cloud posture
  • Breach & credential exposure
  • Public files, metadata & PII
  • Typosquatting & brand risk
How the platform works

Discovery starts with known domains and expands through subdomains, certificates, DNS records, exposed ports and services, technology fingerprints and cloud indicators. These assets are enriched with vulnerability intelligence, mail-security checks, breach and leak sources, public documents, metadata, OCR-assisted PII analysis and lookalike-domain monitoring.

Signals are normalised into a single review layer, linked back to the affected asset and weighted by confidence and potential impact. The output highlights verified exposure, recurring risk themes and remediation priorities while retaining the evidence trail behind each observation.

The visualization is illustrative. Sensitive organisation data, collection sources and operational metrics are intentionally omitted.

Purpose-built web application Cybersecurity M&A

M&A Fieldwork Application

A purpose-built workspace that turns fragmented technical and organisational evidence into a clear cybersecurity view for M&A due diligence.

The assessment brings together the asset landscape, on-premise and cloud identity, vulnerability exposure, CVE intelligence, workshops and security observations. Evidence is normalised and cross-referenced so isolated data points become defensible risk statements, priorities and practical remediation themes.

  • Asset & site inventory
  • AD & Entra identity posture
  • Vulnerability & CVE correlation
  • Workshops & governance evidence
  • Physical & operational observations
  • Prioritised remediation roadmap
What the assessment composes

Technical sources establish what exists and where exposure concentrates: systems, identities, privileged access, unsupported technology, external attack surface, vulnerabilities and applicable CVEs. Interviews, workshops and site observations add the control, process and operational context needed to interpret that evidence correctly.

The resulting assessment distinguishes immediate risk from longer-term maturity gaps, records the supporting evidence and organises recommendations into deal priorities, Day 1 actions and a sequenced post-transaction roadmap.

The visual model is illustrative. No identifying, transaction-specific or confidential assessment data is shown.

Beyond the builds

Technical delivery across the security lifecycle.

  • 01Microsoft Sentinel & SOCImplementation, detection, SOAR and operations
  • 02Incident response24/7 support, threat hunting and ransomware forensics
  • 03Cloud & KubernetesArchitecture, IAM, benchmarks and platform reviews
  • 04Authorised assessmentsWeb, infrastructure, mobile and purple teaming

Interactive profile

Query the operator.

Use the terminal to explore my experience, work and technical focus. Type help to see every available command.

visitor@hsky:~

HSKY PROFILE TERMINAL / SESSION READY

Welcome. Run help to list commands or choose a shortcut.

Enter a command. Use the up and down arrow keys for command history and Tab for autocomplete.

02 / Expertise

Broad enough to see the system. Technical enough to go deep.

01

Defensive security

SIEM and SOC implementation, threat hunting, detection engineering, SOAR, incident response and forensic analysis.

  • Sentinel
  • Splunk
  • CrowdStrike
  • KQL
02

Cloud security

Azure, IAM, networking, CIS benchmarks, Kubernetes, Intune and DevSecOps reviews.

03

OT security

Asset discovery, vulnerability assessment and security posture reviews for industrial environments.

04

Cyberfootprinting

External exposure discovery, OSINT, breach intelligence, metadata analysis and automation.

05

Offensive security

Authorised penetration testing for web applications, infrastructure and mobile platforms, plus purple-team and physical-security exercises.

  • Burp Suite
  • Nmap
  • Kali
  • OWASP
06

Governance & M&A

ISMS, ISO 27001, NIS2/CyFun, risk management and cybersecurity due diligence.

03 / Profile

Security should survive contact with reality.

I work where technical depth, business pressure and real operational constraints meet.

Over four years at EY, my experience has spanned government, transport, pharmaceutical, food and critical-infrastructure environments. I enjoy moving between architecture, investigation and hands-on testing—then translating the result into action that teams can actually own.

Every offensive, phishing, physical-security or acquisition assessment referenced on this site was performed as authorised professional work.

Certifications

  • SC-200Microsoft Security Operations Analyst
  • AZ-900Microsoft Azure Fundamentals
  • CCNACisco Certified Network Associate

Languages

Dutch
French
English

Sectors

Government
Transport
Pharma
Critical infrastructure

Open themed CV dossier

04 / Contact

Have a difficult security problem?

Let’s discuss the system, the constraints and what a useful outcome looks like.