Carl Heaton
Founder of Steelwise, a technology advisory practice based in Sheffield. He writes every filing on this site.
Carl has spent over 22 years working across security, web infrastructure, data, and AI. He has served as CTO, CISO, and DPO for a web hosting company working in regulated sectors including fintech, edtech, healthcare, and SaaS. He built Steelwise because he kept seeing the same problem: businesses getting complexity instead of clarity.
That breadth is unusual. Most advisors specialise in one lane. Carl deals with all of it, because that is what running a real technology business actually requires. The security industry defaults to jargon and fear, MSPs want to sell a contract, and consultancies send juniors. Steelwise exists to be the alternative to all three.
Experience
Twenty two years in technology, spanning hands-on delivery and board-level responsibility:
- Chief Technology Officer, setting technical direction and platform strategy for a web hosting company.
- Chief Information Security Officer, accountable for security posture in regulated environments.
- Data Protection Officer, responsible for data protection compliance and practice.
- Founder of Steelwise, a vendor-neutral technology advisory practice in Sheffield.
Sectors worked in include fintech, edtech, healthcare, and SaaS, all of which carry regulatory obligations that shape how technology decisions get made.
Areas of expertise
- Information security, including Cyber Essentials and ISO 27001 readiness
- Security posture assessment and incident preparedness
- Web and hosting infrastructure, architecture, and reliability
- AI strategy, readiness, risk, and governance
- Data protection and technology governance
How he works
Steelwise runs on a partnership model: a small, trusted team backed by a network of specialists. Clients get senior people who have done the work. No juniors, no handoffs, no learning on the client's time.
Steelwise is not tied to any product or vendor, takes no commissions, and everything it delivers belongs to the client. If you want a second opinion on what your IT provider is telling you, that is exactly the kind of conversation Carl is there for.
Elsewhere
- Carl Heaton on LinkedIn
- Steelwise on LinkedIn
- Steelwise on Bluesky
- Technical Director Ltd at Companies House (company number 08512222)
Recent filings
-
If you self-host GitLab, patch it today: this one is CVSS 10
· Security
CVE-2026-85706 lets an attacker read arbitrary files from a self-hosted GitLab server without logging in. It's rated CVSS 10, the maximum possible severity, and it's already being probed in the wild days after GitLab shipped the fix.
-
When the request looks official, check anyway
· Security
Revolut handed over customer passports, selfies, and financial records after a fraudster emailed from a genuine government domain. The email being real did not make the request real. Here is what to ask about your own process.
-
Your policy is why they went around you
· AI Security
NCSC says 71% of employees have used AI tools their employer never approved, and points at an uncomfortable cause: when security policy cannot meet what the job actually needs, staff route around it. The fix is not a firmer ban.
-
Your supplier's docs now tell your AI what to install
· AI Security
Researchers scanned 6,214 corporate domains and found 120 published documentation files pointing at software packages nobody owned. They registered some. A Fortune 500 company's coding agent installed one within the hour.
-
Work out the number before your insurer does
· Security Commentary
Only 22% of UK business leaders think their insurance would cover an attack, and one in five have never worked out what an attack would cost them. The second number is why the first one is so low.
Get in touch
The first conversation is always free. Email [email protected], call 0114 376 7987, or see the contact page for more ways to reach us.