Skip to content
View pethers's full-sized avatar

Organizations

@Hack23

Block or report pethers

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
pethers/README.md

CEO/Founder Hack23 | Security & Open Source Expert | Cloud Security Specialist | Information Security Professional

Website LinkedIn GitHub OpenHub

CEO/Founder of Hack23 | committers.top badge

Strong advocate for transparency in organizations, secure software development practices, and innovative open source solutions. Experienced security professional with over 30 years in information technology, specializing in security architecture, cloud security, and compliance. Prior roles including Application Security Officer at Stena, Information Security Officer at Polestar and Senior Security Architect at WirelessCar.


🔐 Commitment to Transparency and Security

At Hack23 AB, we believe that true security comes through transparency and demonstrable practices. Our Information Security Management System (ISMS) is publicly available, showcasing our commitment to open security practices.

📋 Public ISMS Repository

Complete Information Security Management System documentation

ISMS Public Repository

🔒 Information Security Policy

Enterprise-grade security framework and governance

Information Security Policy

🏆 Security Through Transparency

Our approach to cybersecurity consulting is built on a foundation of transparent practices:

  • 🔍 Open Documentation: Complete ISMS framework available for review
  • 📋 Policy Transparency: Detailed security policies and procedures publicly accessible
  • 🎯 Demonstrable Expertise: Our own security implementation serves as a live demonstration
  • 🔄 Continuous Improvement: Public documentation enables community feedback and enhancement

"Our commitment to transparency extends to our security practices - demonstrating that true security comes from robust processes, continuous improvement, and a culture where security considerations are integrated from the start."

— James Pether Sörling, CEO/Founder


Professional Certifications

CISSP CISM AWS Security AWS Solutions Architect

🔒 Hack23 AB

Swedish innovation hub specializing in creating immersive and precise game experiences alongside expert cybersecurity consulting and solutions.


🚀 Featured Projects

🔥 Black Trigram (흑괘)

Black Trigram Logo

Realistic 2D precision combat simulator inspired by traditional Korean martial arts, focusing on precise anatomical targeting, authentic combat techniques, and detailed physics modeling.

OpenSSF Scorecard CII Best Practices SLSA 3 Quality Gate Status Security Rating


🔐 CIA Compliance Manager

CIA Compliance Manager Logo

Security assessment platform for the CIA triad (Confidentiality, Integrity, Availability) with business impact analysis and compliance mapping to regulatory frameworks like NIS2, ISO 27001, and GDPR.

CII Best Practices OpenSSF Scorecard Quality Gate Status Security Rating


🔍 Citizen Intelligence Agency

CIA Logo

Political transparency platform monitoring Swedish political activity with data-driven insights, analytics, dashboard visualizations, and accountability metrics.

CII Best Practices OpenSSF Scorecard Quality Gate Status


☁️ Lambda in Private VPC

AWS Lambda

Enterprise-grade multi-region active/active architecture with near-zero recovery time, comprehensive DNS failover, and AWS Resilience Hub policy compliance for mission-critical workloads.


🧪 Sonar-CloudFormation-Plugin

SonarQube Plugin

SonarQube plugin for analyzing AWS CloudFormation templates with security best practices based on NIST, CWE, and ISO standards.


🗳️ Riksdagsmonitor

Riksdagsmonitor

Swedish Parliament Intelligence Platform monitoring political activity in Sweden's Riksdag with systematic transparency through real-time analysis and 50+ years of historical data (1971-2024).


🎮 Game Template

Game Template

Secure game development template with React, TypeScript, Three.js, and Vite - built with security-first principles, comprehensive SBOM generation, and automated security testing aligned with Hack23 AB ISMS policies.


🔑 Security Services

Professional cybersecurity consulting services delivered remotely or in-person in Gothenburg. Drawing from over three decades of experience in software development and security architecture, we deliver practical, implementable security solutions.

📋 Service Overview

🌐 Availability Remote or in-person (Gothenburg)
💰 Pricing Contact for pricing
🏢 Company Hack23 AB (Org.nr 5595347807)
📧 Contact LinkedIn

🎯 Core Service Areas

Area Services Ideal for
🏗️ Security Architecture & Strategy Enterprise Security Architecture, Risk Assessment & Management, Security Strategy Development, Governance Framework Design Organizations needing strategic security leadership and architectural guidance
☁️ Cloud Security & DevSecOps Secure Cloud Solutions (AWS), DevSecOps Integration, Infrastructure as Code Security, Container & Serverless Security Development teams transitioning to cloud-native architectures with security focus
🔧 Secure Development & Code Quality Secure SDLC Implementation, CI/CD Security Integration, Code Quality & Security Analysis, Supply Chain Security (SLSA Level 3) Development teams seeking to embed security without slowing innovation

🏆 Specialized Expertise

Category Services Value
📋 Compliance & Regulatory GDPR, NIS2, ISO 27001 implementation, ISMS Design, AI Governance, Audit Preparation Navigate complex regulatory landscapes with confidence
🌐 Open Source Security OSPO establishment, Vulnerability Management, Security Tool Development, Community Engagement Leverage open source securely while contributing to security transparency
🎓 Security Culture & Training Security Awareness Programs, Developer Security Training, Leadership Briefings, Incident Response Training Transform security from barrier to enabler through education and culture

🔑 Security Focus Areas

mindmap
  root((🔐 CIA Triad<br>Security Focus))
    🔒 Confidentiality
      🏷️ Data Classification
        🌐 Public
        🛡️ Restricted
        🗝️ Confidential
        🔒 Secret
      🚪 Access Control
        👥 RBAC Implementation
        🔑 MFA Integration
        📉 Least Privilege
      🔑 Encryption
        🧬 AES-256
        🧿 Quantum-Safe Encryption
        🗝️ KMS Integration
    ✔️ Integrity
      🧪 Data Validation
        👁️ Manual Checks
        🤖 Automated Validation
        🔗 Blockchain Records
      🔄 Change Control
        📝 Audit Trails
        ♻️ Versioning
        🛡️ Non-Repudiation
      🏆 Quality Assurance
        🧑‍💻 Code Analysis
        🧩 Test Coverage
        🏅 SLSA Level 3
    ⏰ Availability
      🛡️ Resilience Levels
        💾 Backup/Restore
        🔥 Pilot Light
        ♨️ Warm Standby
        🌐 Multi-Site Active/Active
      📊 Recovery Metrics
        🕑 RTO Targets
        ⏳ RPO Objectives
        📈 Uptime SLAs
      👀 Monitoring
        ❤️ Health Checks
        🚨 Alerting
        💥 Chaos Testing
Loading

🌟 Featured in Press & Media

🗞️ Computer Sweden

Featured article on innovative use of technology for political transparency

Read Article

📰 Riksdag och Departement

Coverage on Citizen Intelligence Agency's monitoring capabilities

Read Article

📊 National Democratic Institute

Recognized in survey of parliamentary monitoring organizations

View Report

📰 Expressen

Eric Erfors credits Citizen Intelligence Agency for exposing politician voting attendance records

Read Article

🎤 Technical Talks & Presentations

🎙️ Javaforum Göteborg

Presentation on secure architecture patterns

Watch Presentation

🎙️ Shift Left Like A Boss

Security podcast guest appearance discussing DevSecOps

Listen to Podcast

🍎 Discordian Cybersecurity Insights

Explore information security, ISMS policies, and cybersecurity best practices through the unique Discordian lens inspired by the Illuminatus! trilogy. "Think for yourself, question authority."

📖 Security Blog: 30+ Posts

Everything You Know About Security Is a Lie — Nation-state capabilities, approved crypto paradox, and Chapel Perilous initiation. Complete ISMS coverage with radical transparency.

Discordian Security Blog

Featured Content:

  • 🎭 Discordian Manifesto - Everything You Know About Security Is a Lie
  • 📚 Complete ISMS Coverage - All 30 posts link directly to ISMS-PUBLIC repository
  • 🍎 Illuminatus! Style - FNORD detection, Chapel Perilous references, 23 FNORD 5 signatures

All hail Eris! All hail Discordia! 🍎


💼 About James Pether Sörling

mindmap
  root((👨‍💼 James Pether Sörling))
    🔐 Information & Security Leadership
      👨‍💼 CISO / ISO Roles
      🛡️ Security Architecture
      🧩 CIA Triad Implementation
      🛠️ Policy Development & Governance
      📊 Risk Management
      🔍 Audit & Compliance Oversight
      🤖 AI Governance
      🌐 Open Source Program Office
    🏛️ Frameworks & Compliance
      📄 ISO 27001
      📄 NIST 800-53
      📄 VDA-ISA
      📄 CIS Controls
      🏷️ Data Protection / GDPR
      📋 ISMS Implementation
      🧪 Continuous Improvement
    ☁️ Cloud & Platform Security
      🌐 Multi-Cloud (AWS / Azure)
      🏗️ Enterprise & Reference Architectures
      🔒 Secure Cloud Services
      🧱 Network & VPC Security
      🔑 IAM / Least Privilege
    🛠️ Infrastructure as Code
      🧾 CloudFormation
      🛠️ Terraform
      🔄 GitOps / Pipelines
      📦 Supply Chain (SLSA Level 3)
    💻 Software Engineering
      ☕ Java / Spring
      ⚛️ React / TypeScript
      🐘 PostgreSQL
      🔄 CI/CD Automation
      🧵 Secure SDLC (SSDLC)
      📈 Code Quality (SonarQube)
    🔬 Security Operations & Assurance
      🚨 Incident Response
      🕵️ Vulnerability Management
      📈 Security Monitoring
      🧪 Threat Modeling
    🌍 Open Source Leadership
      📋 CIA Compliance Manager
      🏛️ Citizen Intelligence Agency
      🧩 Sonar-CloudFormation-Plugin
      🔧 cfn-nag Contributions
      🤝 Community Engagement
    🏆 Certifications & Recognition
      🎓 CISSP
      🎓 CISM
      🥇 AWS Security Specialty
      🥇 AWS Solutions Architect Professional
      🛡️ SLSA Level 3 Attestations
    🚀 Strategic Impact
      🔓 Transparency Advocacy
      🧭 Security-by-Design Enablement
      🧠 Knowledge Sharing / Speaking
      📢 Public Policy & Civic Tech
Loading

Experienced technology professional specializing in information security and delivery of secure cloud systems. Strong advocate for transparency in organizations and committed to ensuring robust security through open practices.


📚 Project Documentation

🏛️ CIA Compliance Manager Documentation

Current Architecture

Future Vision

🏛️ Citizen Intelligence Agency Documentation

Current Architecture

Future Vision & Operations


🛠️ Technology & Skills

Security & Compliance

Security Architecture Risk Management ISO 27001 NIST 800-53 GDPR CIS Controls Vulnerability Management Incident Response SSDLC AI Governance

Cloud & Infrastructure

AWS CloudFormation Azure Terraform Docker Linux

Development & Languages

Java Spring TypeScript React PostgreSQL

DevOps & Tools

SonarQube GitHub Actions SLSA


📅 Career Highlights

%%{init: {'theme': 'base', 'themeVariables': { 'primaryColor': '#d1c4e9', 'primaryTextColor': '#1a1a1a', 'primaryBorderColor': '#9575cd', 'lineColor': '#9575cd', 'secondaryColor': '#bbdefb', 'tertiaryColor': '#c8e6c9'}}}%%
timeline
    title Professional Journey
    section Enterprise Security
      2024 : Application Security Officer, Stena Group IT
            : Risk Assessment, Cloud Security, Microsoft Azure, AI Governance
      2022 - 2024 : Information Security Officer, Polestar
            : ISMS Implementation, Security Compliance, Risk Management, OSPO Lead
      2018 - 2022 : Senior Security Architect, WirelessCar
            : Security Architecture, AWS Security, Secure Development Practices
    section Cloud & Security Engineering
      2017 - 2018 : Consultant, Consid AB
            : Open Source Development, CI/CD, Docker, AWS
      2010 - 2017 : Cloud Architect, Keypasco
            : Cloud Security Solutions, Multi-Tier Architecture, AWS Infrastructure
    section Software Development
      2008 - 2009 : Consultant, Redpill Linpro
            : Technical Support, System Administration, Development
      2006 - 2007 : System Developer, Sky
            : J2EE Projects, Agile Development, Test-Driven Development
      2003 - 2005 : J2EE Developer, Glu Mobile
            : Mobile Services, Integration
      2000 - 2002 : Software Engineer, Volantis Systems
            : Multi-Channel Server Product Development
Loading

🏆 Notable Contributions & Appearances

  • Information Security Officer at Polestar, leading security practices and the Open Source Program Office
  • Senior Security Architect at WirelessCar, supporting secure delivery practices and security risk management
  • Open source contributor for cfn-nag, developing integration with SonarQube for CloudFormation security analysis
  • Speaker at Javaforum Göteborg on secure architecture patterns
  • Guest on Shift Left Like A Boss security podcast
  • Featured in Computer Sweden and Riksdag och Departement for political transparency work
  • Mentioned in National Democratic Institute survey on parliamentary monitoring organizations
  • Operated Equal Rites BBS in the 1990s, part of Fidonet (Node 2:203/454)
  • committers.top badge

🗺️ Site Map Overview

Hack23.com is a static, multi-language HTML/CSS site deployed to AWS S3 + CloudFront.
For the authoritative, always up-to-date sitemap, use the live page:

🏠 Home & Company

🔑 Security Services

🚀 Projects

🌐 Languages

🔧 Technical Resources


📫 Connect

LinkedIn GitHub Blog Tech Talks

Profile Views

Pinned Loading

  1. Hack23/ISMS-PUBLIC Hack23/ISMS-PUBLIC Public

    Hack23 Public Information Security Management System:Security Through Transparency and Open Documentation Demonstrating Security Excellence Through Public ISMS Disclosure

    22 6

  2. Hack23/cia Hack23/cia Public

    Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government institutions, and parliamentary…

    Java 205 51

  3. Hack23/riksdagsmonitor Hack23/riksdagsmonitor Public

    Riksdagsmonitor is a comprehensive intelligence platform for monitoring political activity in Sweden's Riksdag (Parliament). Built on the Citizen Intelligence Agency (CIA) platform, we provide syst…

    HTML 2 1

  4. Hack23/cia-compliance-manager Hack23/cia-compliance-manager Public

    The CIA Compliance Manager is an application that helps organizations assess and manage the availability, integrity, and confidentiality of their systems and data based on customizable security lev…

    TypeScript 15 6

  5. Hack23/blacktrigram Hack23/blacktrigram Public

    Black Trigram is a realistic combat simulator that teaches authentic Korean martial arts through precise anatomical targeting. Master traditional vital point techniques through modern 3D combat mec…

    TypeScript 5 2

  6. Hack23/game Hack23/game Public template

    A clean, minimal template for building games with React, TypeScript, Three.js, and Vite - built with security-first principles.

    TypeScript 10 5