Pillar 03 · Advocate

Advocate for a
safer internet.

Technology moves faster than the law that governs it. Cipher & Counsel advances policy and legal literacy through original research, plain-language briefs, and open investigations — so a more accountable internet isn't reserved for those who can afford a lawyer.

Scales of justice beside bound volumes on cybersecurity, policy, and law
Where Security Meets Law

The rules are still being written.

Privacy, surveillance, data brokerage, and breach liability sit in a legal grey zone that most people never see. The decisions made there shape what companies can collect, what governments can demand, and what recourse you actually have.

We translate that landscape into language anyone can act on — because you can't defend a right you don't know you hold.

Artificial intelligence is the newest front. Systems that decide, draft, and publish are outpacing the frameworks meant to govern them — which is why every AI system Cipher & Counsel builds carries governance designed in from day one: human approval before publish, logged provenance for every output, and autonomy that is earned in writing, never assumed.

How We Advocate

Evidence first, always public.

Advocacy without proof is just opinion. Every position we take is grounded in primary-source research and published in the open for anyone to scrutinize, cite, or build on.

Practice 01
Policy Literacy
Plain-language explainers on the laws, rulings, and proposals that quietly reshape your digital rights — written for citizens, not committees.
Get the Briefs →
Practice 02
Original Research
OSINT-driven threat investigations and data-privacy studies — methodology shown, sources cited, conclusions you can verify yourself.
View Investigations →
Practice 03
Public Accountability
Holding platforms and institutions to their own stated standards — documenting the gap between privacy promises and practice.
Follow the Work →
Accountability

Holding power to account.

The same techniques used to track individuals can be turned outward — to investigate the actors, brokers, and institutions operating in the dark. Open-source intelligence makes that work transparent and repeatable.

"A more accountable internet shouldn't be reserved for those who can afford a lawyer."

Policy and counsel team in discussion before a global threat map
The Big Picture

From frameworks
to the courtroom.

Every breach ends the same way — not in a server room, but in front of regulators, auditors, and courts. Governance, risk, and compliance is the discipline that translates technical reality into the evidence those rooms run on.

That is the why behind a BBA in Cybersecurity with a minor in Public Policy and Law: business context to understand what is at stake, technical fluency to know what actually happened, and legal grounding to argue what should happen next. GRC analysis and consulting are the practice. Counsel is the destination.

GRC 01
Control Assessment
NIST SP 800-53 control evaluation and risk assessment — turning security posture into audit-ready evidence.
GRC 02
Resilience & Continuity
ISO 22301 and NIST framework benchmarking for enterprise continuity — published in original research.
GRC 03
Third-Party & Breach Risk
Vendor risk enrichment and breach-liability analysis — where compliance exposure becomes legal exposure.
Why It Matters

Rights you don't
use, you lose.

Regulation is reactive, enforcement is uneven, and the burden of understanding it all still falls on the individual. Knowing the rules is the first form of self-defense.

137
Countries with data privacy laws
75%
Of the world covered by privacy regulation
$5.9B
GDPR fines issued to date
100%
Of our research published openly

Advocacy isn't a one-time act.

It's a standard we hold, in public.

Join the Community

Follow @cipherandcounsel