Dean Kastelic
Former Enterprise CISO & Director of Cyber Defence, KPMG.
Author of the Vyfority Cyber Program Playbook.
As a trusted advisor to executives across federal government and complex national enterprises, my focus is on translating intricate security challenges into clear, actionable business strategy.
I am sought out to architect defensible, resilient programs for critical national infrastructure, leading high-stakes initiatives where security is a core enabler of business objectives.
The Philosophy & Frameworks
“I created Vyfority to fix the broken consulting model. We don’t bring an army of junior consultants—we provide a specialist-led, high-impact diagnosis to give you the truth and the plan, without the waste.”
The Vyfority Cyber Program Playbook
The Threat-Anchored Model
The foundational text for building effective, defensible cybersecurity programs. It deliberately shifts the focus away from generic, checklist-based compliance frameworks and anchors every architectural and financial decision directly to the specific threat actors targeting your business.
Read the methodology →Vyfority Antifragile Architecture
Beyond Resilience
Resilience is simply surviving a shock; antifragility is improving because of it. Currently detailed in our foundational whitepaper (and evolving into a published book and technical PoC), the Antifragile Threat Model dictates how to engineer environments that adapt, learn, and harden dynamically under stress.
Explore the Whitepaper →Vyfority TVRM
Threat → Value → Resilience
The backbone of our antifragile architecture doctrine. TVRM fuses three critical domains: Threat modelling (adversary and system), Value modelling (what the organisation actually depends on), and Resilience modelling (behaviour under stress).
- 1. Identify what creates value (CVOs).
- 2. Map threats to those value pathways.
- 3. Expose fragility and failure patterns.
- 4. Engineer targeted resilience mechanisms.
- 5. Feed stress signals back to increase capability.
We Built This to Fix the “Big Four” Failures
The traditional enterprise consulting model is fundamentally misaligned with the speed and capital constraints of the mid-market. We eliminate these four traps.
The “Audit Treadmill”
An endless cycle of expensive assessments, maturity reviews, and gap analyses that result in massive reports but no meaningful operational improvement.
The “Compliance Fallacy”
The “Watermelon Effect”—treating frameworks as a finish line rather than a baseline. This creates a false sense of security that looks green to the board but is vulnerable underneath.
Over-Engineering
Building complex, gold-plated controls and purchasing overlapping tools that are completely misaligned with your actual threat landscape and business margins.
The Cyber Silo
Running cybersecurity as a standalone technical function, entirely disconnected from the broader IT roadmap, business strategy, and the CFO’s balance sheet.
Our Fixed-Price Diagnostic Services
This is the immediate answer to “what do we do next?”
The “Threat-Anchored” Strategy Review
Our fixed-price, 5-day intensive diagnostic. We find the “fatal flaws” in your program and deliver a board-ready, one-page roadmap. This is the low-risk first step to building a defensible budget.
Inquire about Review →The Program Activation Service
Our core, multi-week engagement to implement the full Vyfority system—from detailed architectural design and operational blueprinting through to execution and final handover to your internal team.
Discuss Activation →Built for the Business Leader.
Vyfority is the “above-average specialist” firm that CFOs, CROs, and PE Firms hire when they suspect their cyber budget is a financial black hole.
We work exclusively with these executive leaders because they are measured on EBITDA and ROI, not just “compliance activity.” We provide a proprietary system that ensures your cyber investments deliver measurable, board-ready outcomes.
The Financial Metrics Briefing
Read our specific briefing on how to measure the financial ROI of a defensible cyber program.
Read the Briefing