Carl Heaton
Founder of Steelwise, a technology advisory practice based in Sheffield. He writes every filing on this site.
Carl has spent over 22 years working across security, web infrastructure, data, and AI. He has served as CTO, CISO, and DPO for a web hosting company working in regulated sectors including fintech, edtech, healthcare, and SaaS. He built Steelwise because he kept seeing the same problem: businesses getting complexity instead of clarity.
That breadth is unusual. Most advisors specialise in one lane. Carl deals with all of it, because that is what running a real technology business actually requires. The security industry defaults to jargon and fear, MSPs want to sell a contract, and consultancies send juniors. Steelwise exists to be the alternative to all three.
Experience
Twenty two years in technology, spanning hands-on delivery and board-level responsibility:
- Chief Technology Officer, setting technical direction and platform strategy for a web hosting company.
- Chief Information Security Officer, accountable for security posture in regulated environments.
- Data Protection Officer, responsible for data protection compliance and practice.
- Founder of Steelwise, a vendor-neutral technology advisory practice in Sheffield.
Sectors worked in include fintech, edtech, healthcare, and SaaS, all of which carry regulatory obligations that shape how technology decisions get made.
Areas of expertise
- Information security, including Cyber Essentials and ISO 27001 readiness
- Security posture assessment and incident preparedness
- Web and hosting infrastructure, architecture, and reliability
- AI strategy, readiness, risk, and governance
- Data protection and technology governance
How he works
Steelwise runs on a partnership model: a small, trusted team backed by a network of specialists. Clients get senior people who have done the work. No juniors, no handoffs, no learning on the client's time.
Steelwise is not tied to any product or vendor, takes no commissions, and everything it delivers belongs to the client. If you want a second opinion on what your IT provider is telling you, that is exactly the kind of conversation Carl is there for.
Elsewhere
- Carl Heaton on LinkedIn
- Steelwise on LinkedIn
- Steelwise on Bluesky
- Technical Director Ltd at Companies House (company number 08512222)
Recent filings
-
Two answers now fail Cyber Essentials outright
· Security
Since April 2026, missing multi-factor authentication on any cloud service, or missing the 14-day window for high-risk updates, fails the whole Cyber Essentials assessment automatically. Here is what else changed, and why a stricter certificate is good news for the business holding one.
-
Test your backups before an attacker does
· Security
Nine in 10 organisations are confident they could recover from an attack. Fewer than one in three ransomware victims actually got all their data back. The difference is testing, and a restore test costs an afternoon.
-
Nobody knew whose job the patching was
· Security Commentary
Ask your IT provider who watches for security updates on your website, then ask yourself the same question. If the two answers do not match, you have the gap that the ICO has just reprimanded a national police unit for. Its website ran the same unpatched version for three and a half years because each side thought the other was looking.
-
The people attackers pick are not the ones you protect
· Security Commentary
Security spending goes on the accounts with technical power: administrators, IT, the server logins. New research into who actually gets compromised at the start of a ransomware attack found three quarters of victims worked in finance, sales, operations, HR, or marketing. What made them worth picking was signing authority, not system access.
-
The plugin that changed without changing
· Security Infrastructure
Seven WordPress plugins were used to create hidden administrator accounts on live sites without a single plugin file being altered. Every update check passed, every version number was correct, and the sites were still compromised. Here is why checking for updates was never going to catch it.
Get in touch
The first conversation is always free. Email contact@steelwise.uk, call 0114 376 7987, or see the contact page for more ways to reach us.