Skip to content
Crypto Security Advisor Request an assessment

Crypto Security Advisor

You have secured your crypto. How do you know it is enough?

A security assessment for people holding meaningful crypto in self-custody. You get a score across six functions, a ranked list of what to fix first, and a baseline to measure against next year.

No access to your wallets, keys or accounts is ever needed. Fixed fee from $2,000 USD, quoted after the call.

The problem is not that you have done nothing

You have done the obvious parts

Hardware wallet. Seed backed up, maybe on metal. Two-factor on the exchange. That covers some of the risk. It is the parts you have not thought about that decide whether you keep it.

There is no scoreboard

You cannot tell whether your setup is strong, adequate, or one bad afternoon away from a total loss. There is no number to check, and nothing to compare against next year.

The weak point is rarely the wallet

The wallet is the part you have already thought about. The gap is somewhere else: a recovery email, a phone number, a backup only you can find, or nobody else who knows enough to act if you cannot.

The service

The Crypto Security Assessment

One engagement, a fixed scope, and a written result you own. It is built for people who would rather know where they stand than assume.

The assessment uses The Citadel Crypto Security Framework: NIST CSF 2.0, rewritten for one person holding crypto. Six functions, 106 controls, and a plain-English action for each. Every control that applies to you gets a rating for where you are now and where you should be. The gaps are what I build your roadmap from.

What you receive

  • A score for each of the six functions, and one overall
  • A current and a target rating for every control that applies to you, and the gap between them
  • A written assessment of what each score means for your setup
  • A ranked 12-month roadmap: what to fix first, and what each fix takes
  • A one-page summary, safe to keep with your recovery materials because it holds no locations, keys or balances
  • A walkthrough session to go through the findings and the plan
  • A re-assessment next year, if you want it, scored on the same controls

What gets scored

Six functions, 106 controls

NIST CSF 2.0 is the framework organisations use to structure their security. The Citadel Crypto Security Framework rewrites it for one person holding crypto. Scoring each function separately shows where you are strong and where you are exposed.

  1. Govern

    31 controls

    Your objectives, your risk appetite, and the rules you actually follow. Which exchanges and wallets you depend on, how you vet them, and what you do if one is breached.

  2. Identify

    21 controls

    An inventory of every device, wallet, exchange and app that touches your crypto, ranked by what matters most. The threats that apply to you, and a written plan for the ones that would hurt.

  3. Protect

    22 controls

    Credentials, second factors and device access. How seed phrases and keys are stored, backed up and tested - the method, never the phrase or the place. Cold versus hot storage, network hygiene, firmware, and the physical security of the hardware.

  4. Detect

    11 controls

    Whether you would notice. Alerts for unusual logins and transactions, monitoring of the devices you use for crypto, and the point at which a strange event becomes an incident.

  5. Respond

    13 controls

    What you do in the first hour: contain it, move what you still can to somewhere the attacker has never seen, alert the exchange, keep the evidence, and work out what happened. Written down before it is needed.

  6. Recover

    8 controls

    Getting back to normal: a rehearsed recovery plan, backups checked before you rely on them, and the point at which you declare it over and fix whatever let it happen.

The score

What the score is, and what it is not

What it is

  • A rating from 0 to 5 for every control that applies to you, from a control that does not exist, through one done informally, to one that is written down, followed, measured and improved
  • A current and a target rating for each control, and the gap between them, rolled up into a score per function and one overall. Each function counts equally in the overall score
  • The gaps ranked, so you close the right one first
  • A private baseline for you, scored the same way next year

What it is not

  • Not a certificate, and not proof to show anyone else
  • Not a guarantee. No assessment makes theft impossible, and anyone who tells you otherwise is selling something else
  • Not a benchmark against other people. It measures your setup against good practice

How it works

Four steps, and then a year

  1. A 15-minute qualifying call

    Roughly what you hold and how it is held. Enough to tell you whether an assessment is worth your money, and to quote a fixed fee. No obligation either way. Book the call.

  2. The review

    About ten hours, in sittings that suit you, walking through your setup control by control. You describe how things are arranged, not where they are: "a metal backup in a second location" is enough. Nothing is accessed and nothing is moved.

  3. Scoring and report

    Every control gets a current and a target rating, and the scores come from that. I write up the findings, build and rank the roadmap, and walk you through it.

  4. The year, then again

    You work through the roadmap at your own pace. Twelve months on, if you want it, we re-score on the same controls and see what moved. That second number is the one that tells you what actually changed.

Year two and after

Why this is worth doing again next year

Not because the report expires. Because your setup drifts.

  • You add things. New chains, wallets, devices and accounts arrive one at a time, and none of them arrives with a security review.
  • Your life changes. A move, a marriage, a child, a business, a new country. Each one changes who needs access and how.
  • Your backups age. Media degrades, hiding places stop being sensible, and the person you nominated three years ago may no longer be the right one.
  • Attack patterns change. What worked against holders two years ago is not what is working now.
  • Last year's roadmap needs checking. Intending to do something and having done it are different, and only one of them moves your score.

The line that does not move

What I never ask for

  • Your seed phrase, private keys, or wallet passwords. Not once, not partially, not for a test.
  • Access to your wallets, exchange accounts, or devices.
  • A transfer of any asset, to any address, for any reason.
  • Your exact balances. A range is enough to size the risk, and a range is all I want.
  • Your wallet addresses or transaction history.
  • Where your backups or devices are kept. How they are arranged is enough; where is your business.

If anyone offering crypto security help asks for any of the above, that is the end of the conversation. Including me.

Who this is for, and who it is not

This is for you if

  • You hold meaningful value in self-custody and want to know where you actually stand
  • You have already read the guides and want your own setup reviewed, not another checklist
  • Nobody else could pick up your setup if you could not
  • You want a documented baseline you can improve on year over year

This is not for you if

  • You want investment, trading or tax advice. That is not what this is, and I do not do it.
  • You think you are being attacked right now. Stop reading and act. Assessment work comes after an incident, not during one.
  • You want a certificate to show someone else.
  • You want someone to hold keys, run wallets or manage custody. I do not take custody of anything, ever.
  • You are not sure yet whether this is worth it. Take the free self-check first, or book the 15-minute call. Both cost nothing.
John Kwisses, Crypto Security Advisor

Who you would be working with

John Kwisses, CISSP

I am the author of The Citadel, a book on securing crypto. I am a Certified Information Systems Security Professional, or CISSP, which is a widely recognised certification in information security, and I advise individuals on keeping their crypto safe.

My background is broader than security: a music degree from the University of Alberta, an honours diploma in software development from the Southern Alberta Institute of Technology, and a Udacity nanodegree in self-driving cars. I have written software for a living, which is why the assessment looks at how your setup actually works rather than how it is supposed to. The assessment is done by me. Outside of work I am a musician who enjoys a good cup of coffee.

Questions people ask before booking

Do you need access to my wallets?

No. Nothing in the assessment requires access to a wallet, an exchange account, or a device. The review works on how your setup is structured, not on what is inside it.

What is the assessment based on?

The Citadel Crypto Security Framework, which I wrote and use for every assessment. It takes NIST CSF 2.0 and rewrites it for one person holding crypto: six functions, 106 controls, a plain-English action for each, a Bronze, Silver or Gold level, and a rating from 0 to 5.

I already use a hardware wallet. Is there anything left to look at?

Yes. A hardware wallet covers a handful of the 106 controls, mostly under Protect. The rest is about everything around it: an inventory of what touches your crypto, recovery paths that have been tested, backups that have been checked, and a written plan for who else needs to know.

Can I not just read about this?

Much of it is public, and some of it is in my book. If you want a quick sense of where you stand, the free self-check rates you on ten of the controls in about four minutes. What you are paying for is a review of your setup, a score you can measure against, and an ordered list of what to fix first. Reading gives you options. This gives you a plan.

How much does it cost?

A fixed fee from $2,000 USD, quoted after the 15-minute call. It depends on how many wallets, chains, devices and people are involved. You know the number before any work starts, and it does not change unless the scope does.

How long does it take?

The review is about ten hours, scheduled in sittings that suit you. The report follows the review, and I give you an expected date when I quote the fee. The roadmap is built to be worked through over the following twelve months.

Is this financial advice?

No. I do not advise on what to buy, hold or sell, and I do not give tax advice. If a security recommendation has a financial or tax consequence, I will say so and tell you to take it to the right professional.

What if you find something serious?

I tell you plainly, and it goes to the top of the roadmap with the fastest available fix. You are paying for findings, not reassurance.

Do I have to do everything on the list?

No. The roadmap is ranked so that you can stop at any point and still have done the items that mattered most.

What if I think I have already been compromised?

Then this is the wrong service today. Act now: move what you can to a wallet the attacker has never seen, from a device they have never touched, and get help with the incident itself. Come back for the assessment afterwards.

How do I book?

Pick a time for the 15-minute call on Calendly, from the button at the bottom of this page. If you would rather write first, email me and we will go from there. The one-hour consultation books the same way, from the list above.

What happens to my information?

This site sets no cookies and runs no trackers, and the free self-check sends nothing anywhere. Booking a call goes through Calendly, and what you tell me during an engagement stays between us. The Privacy Policy spells it out, and the Terms of Service cover the rest.

Where to start

Four ways to work with me

In order of how much they do for you. Start at the top if you can. Every rung below it still moves you forward.

  1. The Crypto Security Assessment

    Fixed fee from $2,000 USD

    The full review: a score across six functions and 106 controls, a ranked 12-month roadmap, and a baseline to measure against next year. If you hold meaningful crypto, this is the one to do.

  2. A consultation

    $200 USD per hour

    An hour of my time on a specific question about your setup, or hands-on help getting your crypto tools set up. Useful when you already know what you want to ask. Not financial or tax advice.

    Book an hour on Calendly

  3. The Citadel: How to Secure Your Crypto

    The book

    The same thinking as the assessment, written so you can apply it yourself. It explains, in plain language, how to think about protecting your crypto and what to put in place, so you can work through your own setup at your own pace. If you want to do the work on your own, start here. If you would rather have it done for you, or want a second set of eyes afterwards, the assessment is the next step.

    Get the book on Amazon

  4. Free resources

    No cost

    Cyber Soldier: plain-language articles on passwords, phishing, malware and staying safe online, for you and your family.

    Crypto Security Alerts: a crypto news feed that surfaces the stories that are about security.

    Mini-Crypto Security Assessment: a short self-check on 10 controls. Runs in your browser and sends nothing anywhere.

Next step

Start with a 15-minute call

Tell me roughly what you hold and how it is held. I will tell you whether an assessment is worth your money, and what it would cost. If it is not worth it, I will say so.

Pick a time below. If you would rather write first, email cryptosecurityadvisorofficial@proton.me with a first name and a sentence or two about your setup. A pseudonym is fine. Do not include seed phrases, keys, addresses or balances in the email; none of that is needed to start.

Crypto Security Advisor is a service of Kwistech. It provides security assessment and advisory only. It is not financial, investment, legal or tax advice, and it does not take custody of any asset.