richardsuls.com · alternate render · tty1
login: guest
access granted · loading site.map

CYBERSECURITY ADVISORY · DIGITAL FORENSICS · EXPERT WITNESS

JOHNSTON, RHODE ISLAND · SERVING STATE & FEDERAL COURTS
────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
site.map: [about] [practice] [services] [response] [experience] [speaking] [publications] [contact]
"I work at the intersection of the boardroom, the crisis room, and the courtroom."

I help attorneys, corporations, and investigators make sense of complex digital evidence and cyber risk. From live incident response and cloud forensics to board-level crisis advisory and regulatory compliance, the work is clear, defensible, and built to hold up under scrutiny.

INCIDENT RESPONSE CYBERSECURITY ADVISORY GRC & REGULATORY COMPLIANCE DIGITAL FORENSICS TABLETOP & CRISIS EXERCISES EXPERT TESTIMONY E-DISCOVERY & ESI
[ ▲ ACTIVE INCIDENT? RESPOND NOW ] [ REQUEST EXPERT ANALYSIS ] [ VIEW SERVICES ]
20+YEARS EXPERIENCE
100+EXPERT MATTERS
2007COURT-QUALIFIED SINCE
80+MEDIA FILES ENHANCED
24/7EMERGENCY RESPONSE

guest@richardsuls:~$ cat about.txt

A CAREER BUILT ON HIGH-STAKES WORK

[ self.png ]
rendering self.png ...

Richard Suls is the US Lead for Security Advisory Consulting at Reversec and the founder of Suls & Co., a boutique cybersecurity consultancy he has operated since 2009. With more than two decades of hands-on experience spanning financial services, critical infrastructure, healthcare, and government, he works at the intersection most practitioners never reach, advising CEOs, CISOs, and General Counsel on enterprise risk strategy while also serving as a court-qualified expert witness in state and federal proceedings.

Since being first qualified as an Expert Witness in 2007, Richard has brought the same discipline to the courtroom that he brings to every client engagement: precision, clarity, and accountability. He has provided forensic analysis and testimony in state and federal matters ranging from violent crime and financial fraud to divorce proceedings and destruction of digital evidence, translating technically complex evidence into language that holds up under cross-examination.

On the advisory side, his work is deliberately broad. Threats don't respect functional boundaries, and neither does his practice. He designs and facilitates executive crisis simulations, leads regulatory compliance programs aligned to NYDFS Part 500, NIST CSF, ISO 27001, DORA, NIS2, and the EU Cyber Resilience Act, and advises boards and leadership teams on the risk decisions that matter most, before and after an incident.

A frequent speaker at international security conferences including Disobey, BSides CT, BSides Denmark, and Teknologia, Richard brings practitioner depth to every engagement, whether that's testifying under oath, running a breach simulation for a board, or helping an organization build the security architecture it should have had before the call came in.

"The boardroom, the crisis room, and the courtroom. I've operated credibly in all three."
REVERSEC ........
US Lead, Security Advisory Consulting · Current · Multinational Firm
SULS & CO. ......
Principal Consultant & Expert Witness · Founder · Est. 2009
COURT-QUALIFIED .
State & Federal · Expert Witness · Since 2007
EDUCATION .......
B.S., University of Rhode Island · Management Information Systems

guest@richardsuls:~$ cat practice.txt

TWO PRACTICES. ONE ADVISOR.

Whether you're a Fortune 500 firm, a regulated financial institution, or a solo attorney with a complex matter, there's a path to working with me directly.

[ REVERSEC · MULTINATIONAL FIRM ]

US Lead, Security Advisory Consulting

At Reversec, I lead the US security advisory practice for a global cybersecurity firm with deep roots in offensive security research. My engagements here serve enterprise clients across financial services, critical infrastructure, and technology, advising boards, CISOs, and General Counsel on risk strategy, regulatory compliance, and crisis readiness.

Work at this level spans executive tabletop design and facilitation, cyber maturity assessments, NYDFS Part 500 and CRI Cyber Profile compliance advisory, third-party risk program redesign, and enterprise incident response strategy. For complex, multi-stakeholder engagements that require the backing of a multinational firm, this is the right door.

[ SULS & CO. · BOUTIQUE · EST. 2009 ]

Founder & Principal Consultant

Suls & Co. was founded on a simple premise: smaller organizations and independent legal matters deserve an advisor who will tell them the truth, prepare them for the worst, and stand beside them when it arrives.

This practice handles expert witness and forensic engagements, advisory work for SMBs and nonprofits, primarily in Southern New England, and select matters that benefit from an independent voice rather than a multinational firm. If you're an attorney, a small organization, or need litigation support, this is where to start.

Suls & Co. is a d/b/a of Curiosity Inked, LLC.

guest@richardsuls:~$ ls -la services/

SERVICES

Comprehensive advisory, investigation, multimedia enhancement, and expert testimony for legal and corporate clients.

[ 01 · INCIDENT RESPONSE & BREACH INVESTIGATION · RAPID RESPONSE ]
[ 02 · CYBERSECURITY ADVISORY & GRC ]
  • Enterprise risk strategy and program development
  • Regulatory compliance: NYDFS Part 500, NIST CSF, ISO 27001, DORA, NIS2, CRA
  • vCISO advisory for organizations without a full-time security leader
  • Third-party and supply chain risk management
  • Threat modeling and risk quantification
  • Board and C-suite advisory and reporting
[ 03 · TABLETOP & CRISIS EXERCISE DESIGN ]
  • Executive-level crisis management exercises
  • Regulatory-aligned tabletop exercises (DORA, NYDFS, NIS2)
  • Board and C-suite breach simulations
  • First-responder and IR team training scenarios
  • Multi-day crisis program design and facilitation
  • Post-exercise gap analysis and remediation planning
[ 04 · DIGITAL FORENSICS ]

Evidence acquisition and analysis wherever the data lives, from a seized laptop to a cloud tenant to a vehicle's onboard systems. Every domain is worked to the same evidentiary standard: sound acquisition, documented chain of custody, findings that survive cross-examination.

[ 04.1 · HOST, SERVER & PHYSICAL MEDIA ]
  • Desktops, laptops, and servers across Windows, macOS, Linux
  • Disk imaging, dead-box and live acquisition
  • Deleted-file, artifact, and memory recovery
  • Timeline reconstruction and user-activity analysis
[ 04.2 · MOBILE DEVICES ]
  • Cell phone and tablet extraction and preservation
  • Text message and chat authentication
  • Call log and location analysis
  • Deleted data and app-data examination
[ 04.3 · CLOUD & SAAS ]
  • AWS and cloud-platform evidence acquisition
  • Control-plane and audit-log analysis (e.g., CloudTrail)
  • Email, collaboration, and SaaS account data
  • Account-compromise and access reconstruction
[ 04.4 · AUTOMOTIVE ]
  • Infotainment and telematics extraction
  • Event data recorder (EDR) analysis
  • Connected-vehicle and navigation artifacts
  • Paired-device and sync data recovery
[ 04.5 · CRYPTOCURRENCY & BLOCKCHAIN ]
  • Wallet identification, triage, and recovery support
  • Transaction tracing and fund-flow analysis
  • Exchange and custodial account records analysis
  • Evidence packages for counsel and law enforcement
[ 04.6 · SOCIAL MEDIA & ONLINE ACCOUNTS ]
  • Account attribution and content authentication
  • Preservation of posts, messages, and profiles
  • Platform data export analysis (takeouts and archives)
  • Impersonation, harassment, and defamation matters
[ 05 · VIDEO ENHANCEMENT & ANALYSIS ]
  • Security and body camera footage clarification
  • License plate and object detail recovery
  • Facial detail and scene enhancement
  • Low-light and poor-quality video improvement
  • Motion blur reduction and stabilization
  • Frame-by-frame analysis and timeline creation
  • Court-admissible processing and exports
[ 06 · AUDIO ENHANCEMENT & ANALYSIS ]
  • Voice and conversation clarification
  • Background noise reduction and filtering
  • Audio authentication and tampering analysis
  • Speech intelligibility improvement
  • Multi-speaker separation and identification
  • 911 call and law enforcement recording enhancement
  • Courtroom-ready audio presentation
[ 07 · EXPERT WITNESS & LITIGATION SUPPORT ]
  • Court testimony and deposition support
  • Expert reports and affidavits (Rule 26-compliant)
  • Evidence authentication and validation
  • Technical strategy for complex digital evidence
  • Attorney and investigator consultation
  • Support for civil and criminal matters
[ 08 · E-DISCOVERY MANAGEMENT ]
  • Data collection and preservation (ESI)
  • Document review and processing workflows
  • ESI production management and quality control
  • Federal and state case e-discovery support
  • Relativity and review platform expertise
  • Defensible deletion and retention protocols
  • Meet & confer and discovery conference prep
[ 09 · SPECIALIZED CASE ANALYSIS ]

guest@richardsuls:~$ tail -f /var/log/incident-response.log

WHEN THE BREACH IS LIVE, EVIDENCE IS THE FIRST CASUALTY.

Cloud and enterprise breach response that contains the intrusion without destroying the record you will need afterward.

Most response work quietly destroys the record you will need later. Logs rotate. Systems get rebuilt. The attacker covers their tracks, and so, sometimes, does a rushed responder. I work the other way around.

Every step is taken to do two things at once: stop the intrusion and preserve exactly what happened. That means the same engagement that gets you back to business also produces evidence a court or a regulator will accept. From the exposed endpoint to the last exfiltrated record, the timeline is reconstructed, hashed, and documented so it does not fall apart under scrutiny.

[ RESPONSE CAPABILITIES · ● CHAIN OF CUSTODY ]
24/7 ACTIVATION .
Emergency engagement for active intrusions, with scoping and containment underway from the first call.
CLOUD/CTRL-PLANE
AWS and cloud-native investigations: credential abuse, account takeover, hostile infrastructure, and configuration tampering.
EVIDENCE INTEG. .
Forensically sound acquisition, cryptographic hashing, and documented chain of custody at every hand-off.
REGULATORY-READY
Findings and timelines mapped to breach-notification, PCI, and sector obligations, written to survive review.
[ ▲ ACTIVE INCIDENT? RESPOND NOW ]

guest@richardsuls:~$ cat frameworks.txt

REGULATORY & FRAMEWORK EXPERTISE

Deep, first-mover fluency across the compliance frameworks that matter most to regulated industries, U.S. and international.

NYDFS PART 500 ..
23 NYCRR 500 cybersecurity regulation for NY-regulated financial institutions
NIST CSF ........
Cybersecurity Framework: maturity assessment, gap analysis, and roadmap development
ISO 27001/27005 .
Information security management systems and risk management
CRI PROFILE v2.2
Cyber Risk Institute profile for financial services institutions
DORA ............
EU Digital Operational Resilience Act: compliance advisory and crisis exercise design
NIS2 DIRECTIVE ..
EU network and information security regulation for critical and important entities
CRA .............
EU Cyber Resilience Act: product security regulation for connected hardware and software products
NIST 800-53 .....
Security and privacy controls for information systems and organizations

guest@richardsuls:~$ cat experience.txt

PROVEN COURT EXPERIENCE

First qualified in Rhode Island Superior Court, with subsequent qualifications across State and Federal Courts.

First qualified as an Expert Witness in Rhode Island Superior Court, with subsequent qualifications in multiple State and Federal Courts. Extensive experience providing testimony in both state and federal cases.

Case types include murder, conspiracy, destruction of digital property, divorce proceedings, and white collar crimes including embezzlement.

Recognized for presentations to FBI InfraGard on advanced cybersecurity threats. Expert in video and audio forensics, voice identification, and multimedia evidence authentication. Skilled in demystifying technical evidence and e-discovery processes for legal professionals and corporate executives.

Extensive background in digital forensic acquisition, evidence preservation, and chain-of-custody standards that meet litigation-grade requirements across both civil and criminal matters.

[ REPRESENTATIVE MATTERS ]

Case details are anonymized to protect confidentiality. CV, testimony history, and references available on request: to qualified counsel for litigation matters, and to prospective clients for advisory, investigative, and incident response engagements.

guest@richardsuls:~$ cat speaking.txt

SPEAKING ENGAGEMENTS

Practical lessons from investigations, incident response, and expert witness work, delivered to security, legal, and executive audiences on two continents: from the Mobile World Congress floor in Las Vegas to hacker conferences in Helsinki and Copenhagen.

2026 ............
Blue Team Con · Chicago, USA
2025 ............
Disobey · Helsinki, Finland
2025 ............
BSides Connecticut · Connecticut, USA
2025 ............
BSides Denmark · Denmark
2025 ............
Teknologia · Finland
PRIOR ...........
Mobile World Congress · Las Vegas, USA
PRIOR ...........
FBI InfraGard · Featured presenter on advanced cybersecurity threats
PRIOR ...........
Rhode Island Office of the Attorney General · Continuing legal education (CLE) training
PODCAST .........
Cyber Security Sauna · WithSecure · Episode #076 · Featured guest
[ INVITE ME TO SPEAK ]
[ TOPICS ]
01 ..............
How digital forensics and ESI really work in litigation
02 ..............
Turning complex technical evidence into clear narratives for judges and juries
03 ..............
What incident response looks like from inside the investigation
04 ..............
Lessons learned from real-world multimedia (video/audio) evidence
05 ..............
Tabletop exercises and crisis preparedness for executives and boards
06 ..............
Regulatory complexity: NYDFS, DORA, NIS2, and the EU Cyber Resilience Act
07 ..............
LLM psychology, prompt injection patterns, and adversarial AI behavior

guest@richardsuls:~$ ls -la publications/

IN THE NEWS & IN PRINT

Featured expertise across digital forensics, cybersecurity regulation, and crisis preparedness.

[ WHITEPAPERS · REVERSEC ]

Mandatory Cyber Crisis and Tabletop Exercises in Financial Services
Regulatory requirements for crisis and tabletop exercises across U.S. and EU financial services, including NYDFS, DORA, and NIS2. · March 2026

NY DFS Part 500 Cybersecurity Enforcement
An in-depth look at NYDFS enforcement trends, compliance obligations, and what regulated financial institutions need to know. · October 2025

[ OPEN STANDARDS ]

EPIR / dfirctl · Independent · Open RFC Series
An open RFC series for producing forensically defensible incident response records: the same evidentiary discipline applied in the courtroom, written into how IR work is documented from the first hour. · In Development · 2026

[ PRESS COVERAGE ]

US News & World Report: Digital Forensics, Multimedia Evidence & Cybersecurity (PDF)
Expert insights on digital forensics, multimedia evidence, and cybersecurity trends in one of America's leading news publications.

VMblog: Virtualization Security & Digital Evidence (PDF)
Expert commentary on virtualization security, digital evidence in virtual environments, and multimedia forensics.

guest@richardsuls:~$ ./contact.sh

REQUEST EXPERT ANALYSIS

Available for consultation, investigation, incident response, multimedia analysis, and speaking engagements.

LOCATION ........
Johnston, Rhode Island · Serving State and Federal Courts
EMAIL & PHONE ...
Available on reveal, 24/7 for active incidents
AVAILABILITY ....
24/7 for emergencies · Regular hours: Mon–Fri 9AM–6PM
LINKEDIN ........
linkedin.com/in/richardsuls
[ transmit.form ]

I typically respond within one business day. Your details are used only to respond to your inquiry and are never sold or shared.