Carl Heaton
Founder of Steelwise, a technology advisory practice based in Sheffield. He writes every filing on this site.
Carl has spent over 22 years working across security, web infrastructure, data, and AI. He has served as CTO, CISO, and DPO for a web hosting company working in regulated sectors including fintech, edtech, healthcare, and SaaS. He built Steelwise because he kept seeing the same problem: businesses getting complexity instead of clarity.
That breadth is unusual. Most advisors specialise in one lane. Carl deals with all of it, because that is what running a real technology business actually requires. The security industry defaults to jargon and fear, MSPs want to sell a contract, and consultancies send juniors. Steelwise exists to be the alternative to all three.
Experience
Twenty two years in technology, spanning hands-on delivery and board-level responsibility:
- Chief Technology Officer, setting technical direction and platform strategy for a web hosting company.
- Chief Information Security Officer, accountable for security posture in regulated environments.
- Data Protection Officer, responsible for data protection compliance and practice.
- Founder of Steelwise, a vendor-neutral technology advisory practice in Sheffield.
Sectors worked in include fintech, edtech, healthcare, and SaaS, all of which carry regulatory obligations that shape how technology decisions get made.
Areas of expertise
- Information security, including Cyber Essentials and ISO 27001 readiness
- Security posture assessment and incident preparedness
- Web and hosting infrastructure, architecture, and reliability
- AI strategy, readiness, risk, and governance
- Data protection and technology governance
How he works
Steelwise runs on a partnership model: a small, trusted team backed by a network of specialists. Clients get senior people who have done the work. No juniors, no handoffs, no learning on the client's time.
Steelwise is not tied to any product or vendor, takes no commissions, and everything it delivers belongs to the client. If you want a second opinion on what your IT provider is telling you, that is exactly the kind of conversation Carl is there for.
Elsewhere
- Carl Heaton on LinkedIn
- Steelwise on LinkedIn
- Steelwise on Bluesky
- Technical Director Ltd at Companies House (company number 08512222)
Recent filings
-
The backup that saved the data and lost the evidence
· Security Infrastructure
An NHS Trust reused a script, pointed it at the wrong database, and overwrote 11 years of maternity records. The clinical data came back. The record of who had looked at it did not, and that is the part most businesses never back up either.
-
One borrowed login turned the ASOS app into the ransom note
· Security
ASOS says an attacker talked one employee out of their login, then used it on outside platforms the retailer relies on to reach its customers. Nobody broke into the shop. The question for every business is which outside services can message your customers or read your customer list, and whose login opens them.
-
Why AI defence will not cancel out AI attackers
· Security AI
Attackers can point AI at a purely technical problem and let it run. Defence is held up by budget, change approval, and the fear of breaking production, which no product fixes. Why the answer to AI-assisted attacks is not an AI security product.
-
The test site that holds your real customers
· Security
Somebody needed to test a change, so they copied the live customer database into a test site. That was months ago. The test site is still running, still reachable, and still full of real people. Nobody owns it, because it was never meant to exist this long.
-
What September's Microsoft updates broke, and how to fix each one
· Infrastructure
September's Microsoft updates stopped backups, broke VPN connections, deactivated older copies of Office, and sent saved PDFs to the wrong place. Five problems, the workaround for each, and why the answer is still not to stop updating.
Get in touch
The first conversation is always free. Email contact@steelwise.uk, call 0114 376 7987, or see the contact page for more ways to reach us.