Johnston, Rhode Island · Serving State & Federal Courts

Cybersecurity Advisory · Digital Forensics · Expert Witness

"I work at the intersection of the boardroom, the crisis room, and the courtroom."

I help attorneys, corporations, and investigators make sense of complex digital evidence and cyber risk. From live incident response and cloud forensics to board-level crisis advisory and regulatory compliance, the work is clear, defensible, and built to hold up under scrutiny.

Incident Response Cybersecurity Advisory GRC & Regulatory Compliance Digital Forensics Tabletop & Crisis Exercises Expert Testimony E-Discovery & ESI
20+ Years Experience
100+ Expert Matters
2007 Court-Qualified Since
80+ Media Files Enhanced
24/7 Emergency Response

About

A Career Built on High-Stakes Work

Richard Suls is the US Lead for Security Advisory Consulting at Reversec and the founder of Suls & Co., a boutique cybersecurity consultancy he has operated since 2009. With more than two decades of hands-on experience spanning financial services, critical infrastructure, healthcare, and government, he works at the intersection most practitioners never reach, advising CEOs, CISOs, and General Counsel on enterprise risk strategy while also serving as a court-qualified expert witness in state and federal proceedings.

Since being first qualified as an Expert Witness in 2007, Richard has brought the same discipline to the courtroom that he brings to every client engagement: precision, clarity, and accountability. He has provided forensic analysis and testimony in state and federal matters ranging from violent crime and financial fraud to divorce proceedings and destruction of digital evidence, translating technically complex evidence into language that holds up under cross-examination.

On the advisory side, his work is deliberately broad. Threats don't respect functional boundaries, and neither does his practice. He designs and facilitates executive crisis simulations, leads regulatory compliance programs aligned to NYDFS Part 500, NIST CSF, ISO 27001, DORA, NIS2, and the EU Cyber Resilience Act, and advises boards and leadership teams on the risk decisions that matter most, before and after an incident.

A frequent speaker at international security conferences including Disobey, BSides CT, BSides Denmark, and Teknologia, Richard brings practitioner depth to every engagement, whether that's testifying under oath, running a breach simulation for a board, or helping an organization build the security architecture it should have had before the call came in.

"The boardroom, the crisis room, and the courtroom. I've operated credibly in all three."

Current · Multinational Firm
US Lead, Security Advisory Consulting
Reversec
Founder · Est. 2009
Principal Consultant & Expert Witness
Suls & Co.
Expert Witness · Since 2007
Court-Qualified
State & Federal
Education
B.S., University of Rhode Island
Management Information Systems

Two Practices. One Advisor.

How I Work

Whether you're a Fortune 500 firm, a regulated financial institution, or a solo attorney with a complex matter, there's a path to working with me directly.

Multinational Firm

Reversec

US Lead, Security Advisory Consulting

At Reversec, I lead the US security advisory practice for a global cybersecurity firm with deep roots in offensive security research. My engagements here serve enterprise clients across financial services, critical infrastructure, and technology, advising boards, CISOs, and General Counsel on risk strategy, regulatory compliance, and crisis readiness.

Work at this level spans executive tabletop design and facilitation, cyber maturity assessments, NYDFS Part 500 and CRI Cyber Profile compliance advisory, third-party risk program redesign, and enterprise incident response strategy. For complex, multi-stakeholder engagements that require the backing of a multinational firm, this is the right door.

Boutique Consultancy · Est. 2009

Suls & Co.

Founder & Principal Consultant

Suls & Co. was founded on a simple premise: smaller organizations and independent legal matters deserve an advisor who will tell them the truth, prepare them for the worst, and stand beside them when it arrives.

This practice handles expert witness and forensic engagements, advisory work for SMBs and nonprofits, primarily in Southern New England, and select matters that benefit from an independent voice rather than a multinational firm. If you're an attorney, a small organization, or need litigation support, this is where to start.

Suls & Co. is a d/b/a of Curiosity Inked, LLC.

Practice Areas

Services

Comprehensive advisory, investigation, multimedia enhancement, and expert testimony for legal and corporate clients.

🚨 Rapid Response

Incident Response & Breach Investigation

  • Rapid response to active intrusions across cloud, on-premises, and hybrid environments
  • Cloud and control-plane compromise investigation, including AWS account takeover
  • Payment-card, ACH, and personal-data breach response
  • Evidence preservation while an attacker is still moving
  • Web-shell, skimmer, and backdoor identification and eradication support
  • Court-ready deliverables: chain-of-custody records, evidence registers, remediation runbooks
🛡️

Cybersecurity Advisory & GRC

  • Enterprise risk strategy and program development
  • Regulatory compliance: NYDFS Part 500, NIST CSF, ISO 27001, DORA, NIS2, CRA
  • vCISO advisory for organizations without a full-time security leader
  • Third-party and supply chain risk management
  • Threat modeling and risk quantification
  • Board and C-suite advisory and reporting
🔥

Tabletop & Crisis Exercise Design

  • Executive-level crisis management exercises
  • Regulatory-aligned tabletop exercises (DORA, NYDFS, NIS2)
  • Board and C-suite breach simulations
  • First-responder and IR team training scenarios
  • Multi-day crisis program design and facilitation
  • Post-exercise gap analysis and remediation planning
🔬

Digital Forensics

Evidence acquisition and analysis wherever the data lives, from a seized laptop to a cloud tenant to a vehicle's onboard systems. Every domain is worked to the same evidentiary standard: sound acquisition, documented chain of custody, findings that survive cross-examination.

01 Host, Server & Physical Media
  • Desktops, laptops, and servers across Windows, macOS, Linux
  • Disk imaging, dead-box and live acquisition
  • Deleted-file, artifact, and memory recovery
  • Timeline reconstruction and user-activity analysis
02 Mobile Devices
  • Cell phone and tablet extraction and preservation
  • Text message and chat authentication
  • Call log and location analysis
  • Deleted data and app-data examination
03 Cloud & SaaS
  • AWS and cloud-platform evidence acquisition
  • Control-plane and audit-log analysis (e.g., CloudTrail)
  • Email, collaboration, and SaaS account data
  • Account-compromise and access reconstruction
04 Automotive
  • Infotainment and telematics extraction
  • Event data recorder (EDR) analysis
  • Connected-vehicle and navigation artifacts
  • Paired-device and sync data recovery
🎥

Video Enhancement & Analysis

  • Security and body camera footage clarification
  • License plate and object detail recovery
  • Facial detail and scene enhancement
  • Low-light and poor-quality video improvement
  • Motion blur reduction and stabilization
  • Frame-by-frame analysis and timeline creation
  • Court-admissible processing and exports
🎧

Audio Enhancement & Analysis

  • Voice and conversation clarification
  • Background noise reduction and filtering
  • Audio authentication and tampering analysis
  • Speech intelligibility improvement
  • Multi-speaker separation and identification
  • 911 call and law enforcement recording enhancement
  • Courtroom-ready audio presentation
⚖️

Expert Witness & Litigation Support

  • Court testimony and deposition support
  • Expert reports and affidavits (Rule 26-compliant)
  • Evidence authentication and validation
  • Technical strategy for complex digital evidence
  • Attorney and investigator consultation
  • Support for civil and criminal matters
🔍

E-Discovery Management

  • Data collection and preservation (ESI)
  • Document review and processing workflows
  • ESI production management and quality control
  • Federal and state case e-discovery support
  • Relativity and review platform expertise
  • Defensible deletion and retention protocols
  • Meet & confer and discovery conference prep
📊

Specialized Case Analysis

  • White collar and financial crime investigations
  • Embezzlement and fraud cases
  • Divorce and family law digital evidence
  • Conspiracy and organized crime investigations
  • Digital property destruction and spoliation analysis

Incident Response

When the breach is live, evidence is the first casualty.

Cloud and enterprise breach response that contains the intrusion without destroying the record you will need afterward.

Most response work quietly destroys the record you will need later. Logs rotate. Systems get rebuilt. The attacker covers their tracks, and so, sometimes, does a rushed responder. I work the other way around.

Every step is taken to do two things at once: stop the intrusion and preserve exactly what happened. That means the same engagement that gets you back to business also produces evidence a court or a regulator will accept. From the exposed endpoint to the last exfiltrated record, the timeline is reconstructed, hashed, and documented so it does not fall apart under scrutiny.

Active Incident? Respond Now
Response Capabilities● chain of custody
24 / 7 Activation Emergency engagement for active intrusions, with scoping and containment underway from the first call.
Cloud & Control-Plane AWS and cloud-native investigations: credential abuse, account takeover, hostile infrastructure, and configuration tampering.
Evidence Integrity Forensically sound acquisition, cryptographic hashing, and documented chain of custody at every hand-off.
Regulatory-Ready Findings and timelines mapped to breach-notification, PCI, and sector obligations, written to survive review.

Standards & Frameworks

Regulatory & Framework Expertise

Deep, first-mover fluency across the compliance frameworks that matter most to regulated industries, U.S. and international.

NYDFS Part 500
23 NYCRR 500 cybersecurity regulation for NY-regulated financial institutions
NIST CSF
Cybersecurity Framework: maturity assessment, gap analysis, and roadmap development
ISO 27001 / 27005
Information security management systems and risk management
CRI Cyber Profile v2.1
Cyber Risk Institute profile for financial services institutions
DORA
EU Digital Operational Resilience Act: compliance advisory and crisis exercise design
NIS2 Directive
EU network and information security regulation for critical and important entities
Cyber Resilience Act (CRA)
EU product security regulation for connected hardware and software products
NIST 800-53
Security and privacy controls for information systems and organizations

Track Record

Proven Court Experience

First qualified in Rhode Island Superior Court, with subsequent qualifications across State and Federal Courts.

First qualified as an Expert Witness in Rhode Island Superior Court, with subsequent qualifications in multiple State and Federal Courts. Extensive experience providing testimony in both state and federal cases.

Case types include murder, conspiracy, destruction of digital property, divorce proceedings, and white collar crimes including embezzlement.

Recognized for presentations to FBI InfraGard on advanced cybersecurity threats. Expert in video and audio forensics, voice identification, and multimedia evidence authentication. Skilled in demystifying technical evidence and e-discovery processes for legal professionals and corporate executives.

Extensive background in digital forensic acquisition, evidence preservation, and chain-of-custody standards that meet litigation-grade requirements across both civil and criminal matters.

Supported homicide and violent crime cases with mobile device forensics, video enhancement, and clear courtroom testimony.

Led forensic and e-discovery work in multi-million-dollar embezzlement and complex financial fraud investigations.

Preserved and analyzed digital evidence in contentious divorce and family law matters involving contested electronic communications.

Assisted counsel in conspiracy and organized crime cases with timeline reconstruction from phones, computers, and cloud platforms.

Investigated destruction and spoliation of digital evidence, providing defensible explanation of what was deleted and when.

Case details are anonymized to protect confidentiality. References available to qualified counsel upon request.

Conference & Training

Speaking Engagements

Practical lessons from investigations, incident response, and expert witness work, shared with security, legal, and executive audiences internationally.

2026
Blue Team Con
Chicago, USA · Upcoming
2025
Disobey
Helsinki, Finland
2025
BSides Connecticut
Connecticut, USA
2025
BSides Denmark
Denmark
2025
Teknologia
Finland
Prior
Mobile World Congress
Las Vegas, USA
Prior
FBI InfraGard
Featured presenter on advanced cybersecurity threats
Prior
Rhode Island Office of the Attorney General
Continuing legal education (CLE) training
Invite Me to Speak
01

How digital forensics and ESI really work in litigation

02

Turning complex technical evidence into clear narratives for judges and juries

03

What incident response looks like from inside the investigation

04

Lessons learned from real-world multimedia (video/audio) evidence

05

Tabletop exercises and crisis preparedness for executives and boards

06

Regulatory complexity: NYDFS, DORA, NIS2, and the EU Cyber Resilience Act

07

LLM psychology, prompt injection patterns, and adversarial AI behavior

Press & Publications

In the News & In Print

Featured expertise across digital forensics, cybersecurity regulation, and crisis preparedness.

Whitepapers · Reversec
Reversec · Whitepaper

Mandatory Cyber Crisis and Tabletop Exercises in Financial Services

Regulatory requirements for crisis and tabletop exercises across U.S. and EU financial services, including NYDFS, DORA, and NIS2.

March 2026 Read Whitepaper →
Reversec · Whitepaper

NY DFS Part 500 Cybersecurity Enforcement

An in-depth look at NYDFS enforcement trends, compliance obligations, and what regulated financial institutions need to know.

October 2025 Read Whitepaper →
Open Standards
Independent · Open RFC Series

EPIR / dfirctl

An open RFC series for producing forensically defensible incident response records — the same evidentiary discipline applied in the courtroom, written into how IR work is documented from the first hour.

In Development · 2026
Press Coverage
US News & World Report

Digital Forensics, Multimedia Evidence & Cybersecurity

Expert insights on digital forensics, multimedia evidence, and cybersecurity trends in one of America's leading news publications.

Read Article (PDF) →
VMblog

Virtualization Security & Digital Evidence

Expert commentary on virtualization security, digital evidence in virtual environments, and multimedia forensics.

Read Article (PDF) →

Get in Touch

Request Expert Analysis

Available for consultation, investigation, incident response, multimedia analysis, and speaking engagements.

Location Johnston, Rhode Island Serving State and Federal Courts
Email richard [at] suls [dot] net
Availability 24/7 for emergencies Regular hours: Mon–Fri 9AM–6PM

I typically respond within one business day. Your details are used only to respond to your inquiry and are never sold or shared.

Message Sent
I'll be in touch within one business day.