Carl Heaton, founder of Steelwise

Carl has spent over 22 years working across security, web infrastructure, data, and AI. He has served as CTO, CISO, and DPO for a web hosting company working in regulated sectors including fintech, edtech, healthcare, and SaaS. He built Steelwise because he kept seeing the same problem: businesses getting complexity instead of clarity.

That breadth is unusual. Most advisors specialise in one lane. Carl deals with all of it, because that is what running a real technology business actually requires. The security industry defaults to jargon and fear, MSPs want to sell a contract, and consultancies send juniors. Steelwise exists to be the alternative to all three.

Experience

Twenty two years in technology, spanning hands-on delivery and board-level responsibility:

  • Chief Technology Officer, setting technical direction and platform strategy for a web hosting company.
  • Chief Information Security Officer, accountable for security posture in regulated environments.
  • Data Protection Officer, responsible for data protection compliance and practice.
  • Founder of Steelwise, a vendor-neutral technology advisory practice in Sheffield.

Sectors worked in include fintech, edtech, healthcare, and SaaS, all of which carry regulatory obligations that shape how technology decisions get made.

Areas of expertise

  • Information security, including Cyber Essentials and ISO 27001 readiness
  • Security posture assessment and incident preparedness
  • Web and hosting infrastructure, architecture, and reliability
  • AI strategy, readiness, risk, and governance
  • Data protection and technology governance

How he works

Steelwise runs on a partnership model: a small, trusted team backed by a network of specialists. Clients get senior people who have done the work. No juniors, no handoffs, no learning on the client's time.

Steelwise is not tied to any product or vendor, takes no commissions, and everything it delivers belongs to the client. If you want a second opinion on what your IT provider is telling you, that is exactly the kind of conversation Carl is there for.

Elsewhere

Recent filings

  • 14,000 charities lost online banking to someone else's flaw · Security

    CAF Bank pulled its online banking on 24 July over a vulnerability in third-party software, and it is still down. Some charities could not run payroll. Nobody's own security failed. The question this raises about your continuity plan is uncomfortable.

  • NCSC has written down how to recover, and the hard part is not the plan · Security

    New NCSC guidance walks through a serious incident in three stages: the first hours, getting back to minimum viable operations, and the longer rebuild. The most useful idea in it has nothing to do with technology, and most firms are skipping it.

  • The phishing page that screenshots your own website · Security

    The advice to look out for a dodgy-looking login page has quietly stopped working. A phishing kit now builds a fresh page for each victim, taking a live screenshot of that person's real company website to use as the background. What still defeats it.

  • They didn't hack the Department for Education, they rang the helpdesk · Security

    More than 600,000 records went out of the Department for Education through its helpdesk, not through a vulnerability. The people who answer your phone can hand over more than your firewall ever will, and almost nobody has written down what they are allowed to do.

  • The malware your browser builds for itself · Security

    The old advice was simple: block the bad download and you are safe. A malvertising campaign has just retired it. There is no bad file to block, because the malware does not exist as a file until your own browser assembles it, piece by piece, in memory. Here is how it dodges the defences that scan for known-bad downloads, and what still stops it.

All filings

Get in touch

The first conversation is always free. Email [email protected], call 0114 376 7987, or see the contact page for more ways to reach us.