Independent Security & EHS Counsel · Seattle

Managed security and EHS services, tailored for your business.

One firm. Every layer. One accountable senior team.

Senior-led security and EHS consulting for organizations facing real threats, regulatory pressure, and operational safety risk, without the cost and delay of building a full-time function.

1
Integrated team
Security, EHS, and incident response under one accountable senior advisory model.
3
Ways to engage
Diagnose, Build, or Operate, depending on your risk maturity and urgency.
24h
Senior response
A senior consultant responds within one business day for qualified inquiries.
Proven impact
Across tech, government, R&D, and industrial industries.
What we solve

The problems clients already feel, and need solved fast.

Clients don't come to Highlander Six because they're curious about risk. They come because something has surfaced (an incident, a near-miss, a regulator letter, an executive feeling) and the next 90 days matter.

Security

Workplace violence & threat risk

Something feels off, but the organization has no defensible assessment.

An employee, termination, or threat concern needs structure before it escalates into an incident, reputational event, or legal exposure.

EHS

OSHA audit readiness

A citation, complaint, or near-miss exposes weak documentation and readiness.

Logs, programs, and records often break down under scrutiny when no senior owner has hardened the system.

Security

Insider threat blind spots

DLP catches the obvious; coercion, collusion, and intent often go unseen.

Clients need behavioral indicators, case intake, and cross-functional response before months of silent loss become a crisis.

EHS

Workers' comp loss pressure

EMR, claims patterns, and premiums start hurting growth and bid competitiveness.

Improvement requires more than policy language. It needs claims review, return-to-work design, and behavior-based safety follow-through.

Security

Physical security uncertainty

Cameras, access control, and guards exist, but coverage and response logic may be weak.

Clients need validated coverage maps, tested controls, and site-by-site risk comparison rather than vendor assumptions.

EHS

No senior EHS continuity

Operations cannot pause, but turnover or growth leaves risk uncovered.

Recordables, training, and program ownership continue to matter even while the client is recruiting or restructuring.

Capabilities in depth

What clients actually get when they engage Highlander Six.

A full advisory practice across security, EHS, and the cross-cutting work that lives between them. Every line is delivered by a senior practitioner. Never offshored, never templated.

Security

Insider threat program

  • Behavioral indicator framework
  • Detection rules and triage workflow
  • Investigations and interviews
  • Case management and evidence handling
  • HR, Legal, and Security integration

Threat & violence assessment

  • WAVR-21 structured assessment
  • High-risk termination support
  • Tabletop exercises and drills
  • Active assailant response planning
  • Behavioral threat assessment team support

Physical security program

  • Facility and perimeter assessment
  • Access control review and gap analysis
  • CCTV coverage mapping
  • Guard force protocol evaluation
  • Visitor and badging review
EHS

OSHA readiness

  • Mock inspections and log review
  • OSHA 300/300A support
  • Risk assessments and citation defense
  • Written program completeness audit
  • Industrial hygiene screening & monitoring

Programs & documentation

  • Lockout / Tagout
  • Hazard communication
  • Confined space entry
  • Respiratory protection
  • Emergency action and fire prevention

Metrics & culture

  • Workers' comp and claims review
  • Modified duty / return-to-work
  • Behavior-based safety programs
  • Contractor safety oversight
  • Leading-indicator dashboards
Cross-cutting

Investigations & response

  • Root-cause analysis
  • Witness interviews and documentation
  • Corrective action planning
  • Privileged investigation support
  • Post-incident program review

Cyber defense posture

  • NIST CSF policy review
  • Endpoint and network gap analysis
  • Phishing and credential exposure review
  • Incident response plan review
  • Security and IT alignment briefing

Embedded leadership

  • Interim EHS manager placement
  • Fractional security advisor
  • Board-ready quarterly reporting
  • Annual strategy and KPI development
  • Executive leadership coaching
How we engage

Three ways to engage. Clients choose speed, build depth, or continuity.

Most engagements start with Diagnose. Some clients move to Build to close the highest-risk gaps. Others stay with Highlander Six through Operate as their fractional senior security and EHS function.

— 01

Diagnose

Assess

A scoped, senior-led assessment of where the client stands and what to fix first.

Use Diagnose when:
  • A trigger event has just happened
  • The board, insurer, or regulator needs an answer
  • There is a suspected gap but no clear priority list
  • The client is comparing vendors or program directions
— 02

Build

Design & deploy

A complete, documented program that the client team can own and operate with confidence.

Use Build when:
  • There is no internal function or it needs tuning
  • A regulatory deadline is approaching
  • Post-incident remediation is required
  • Growth or M&A has outpaced the program
— 03

Operate

Embed

A fractional senior EHS and security function embedded in the organization for continuity and executive visibility.

Use Operate when:
  • The client doesn't yet need a full-time CSO or EHS manager
  • Senior on-call guidance is needed for active issues
  • Build is complete and continuity matters
  • Operations are scaling across multiple sites
What's included

What each phase includes, so buyers can compare quickly.

01 · Diagnose 02 · Build 03 · Operate
Assessment Physical security & facility assessment. OSHA gap assessment. Workplace violence threat assessment. Insider threat review. Everything in Diagnose, plus quarterly on-site audits and sector benchmarking. Everything in Build, plus monthly on-site walkthroughs and an annual board-ready risk review.
Programs Findings report only. No program build. Program conception, planning, strategy, documentation, and deployment. All Build programs maintained, plus quality control, workers' comp loss control, and contractor safety oversight.
On-site Typically 1–2 days on site for assessment. Quarterly on-site visits; training delivered remote or on site. 1–4 days per month senior on site, plus same-day support for active threats.
Incident support Not included by default; available through scoped response work. Initial incident response plan and first 30 days of post-program support. Full incident investigation, root-cause support, on-call threat assessment, and high-risk termination support.
Deliverable Written report, prioritized roadmap, and executive briefing. Full program documentation, training package, and case-management framework. Ongoing management cadence, monthly reviews, and quarterly reporting.
An anonymized engagement
99.9%
reduction in monthly internal fraud events, achieved inside a single four-month sprint.

Situation. The client suspected internal fraud was occurring inside the organization but had no defensible way to scope it. A senior consultant team was brought in to validate the suspicion and quantify the exposure.

Engagement. The team uncovered that internal fraud events were occurring at a rate of roughly 20,000 per month. Over a four-month sprint, the consultants ran structured investigations, designed engineering and control improvements, and rebuilt the surrounding process.

Result. Monthly fraud events dropped from approximately 20,000 to fewer than 3. The new control environment held under continued monitoring, and the engineering changes have remained in production since.

Insider threat · Investigations · Process & engineering controls
Held by our practitioners
CPPPSPWAVR-21CSPSMPCIHActive TS
Sectors served
HealthcareHigher EdLogisticsManufacturingTechFamily Office
The next step

Tell us what you're facing. A senior consultant responds within one business day.

No sales representative. No proposal pressure. Just a focused 30-minute discovery conversation to identify the highest-priority gaps, and determine honestly whether Highlander Six is the right fit.