Carl Heaton, founder of Steelwise

Carl has spent over 22 years working across security, web infrastructure, data, and AI. He has served as CTO, CISO, and DPO for a web hosting company working in regulated sectors including fintech, edtech, healthcare, and SaaS. He built Steelwise because he kept seeing the same problem: businesses getting complexity instead of clarity.

That breadth is unusual. Most advisors specialise in one lane. Carl deals with all of it, because that is what running a real technology business actually requires. The security industry defaults to jargon and fear, MSPs want to sell a contract, and consultancies send juniors. Steelwise exists to be the alternative to all three.

Experience

Twenty two years in technology, spanning hands-on delivery and board-level responsibility:

  • Chief Technology Officer, setting technical direction and platform strategy for a web hosting company.
  • Chief Information Security Officer, accountable for security posture in regulated environments.
  • Data Protection Officer, responsible for data protection compliance and practice.
  • Founder of Steelwise, a vendor-neutral technology advisory practice in Sheffield.

Sectors worked in include fintech, edtech, healthcare, and SaaS, all of which carry regulatory obligations that shape how technology decisions get made.

Areas of expertise

  • Information security, including Cyber Essentials and ISO 27001 readiness
  • Security posture assessment and incident preparedness
  • Web and hosting infrastructure, architecture, and reliability
  • AI strategy, readiness, risk, and governance
  • Data protection and technology governance

How he works

Steelwise runs on a partnership model: a small, trusted team backed by a network of specialists. Clients get senior people who have done the work. No juniors, no handoffs, no learning on the client's time.

Steelwise is not tied to any product or vendor, takes no commissions, and everything it delivers belongs to the client. If you want a second opinion on what your IT provider is telling you, that is exactly the kind of conversation Carl is there for.

Elsewhere

Recent filings

  • Your supplier's docs now tell your AI what to install · AI Security

    Researchers scanned 6,214 corporate domains and found 120 published documentation files pointing at software packages nobody owned. They registered some. A Fortune 500 company's coding agent installed one within the hour.

  • Work out the number before your insurer does · Security Commentary

    Only 22% of UK business leaders think their insurance would cover an attack, and one in five have never worked out what an attack would cost them. The second number is why the first one is so low.

  • The repo someone sent you can run code before you read it · Security AI

    Eight flaws across seven command-line coding agents let a repository's own Git config run commands on the developer's machine, outside the sandbox and before any approval prompt. Four were unpatched at disclosure.

  • Nobody was told to switch the account off · Security

    HR thought IT would do it. IT was waiting for HR. The former employee logged back in and deleted files, locked accounts, and corrupted a database. Offboarding fails on ownership, not on tooling.

  • The admin key was in the page source · Security

    Attackers took data on 8.7 million airport customers after finding admin keys for a marketing platform sitting in the JavaScript of three public websites. Anyone could have right-clicked and read them. Here is how to check your own site in ten minutes.

All filings

Get in touch

The first conversation is always free. Email [email protected], call 0114 376 7987, or see the contact page for more ways to reach us.