Portræt af Jens Christian Høy Monrad
Jens Christian Høy Monrad
STRATEGIC ADVISOR, Arx Insight
Independent advisory on cyber strategy, geopolitical risk, and technological change.
Independent advisory
Cyber · geopolitics · regulation

Understand the exposure before it becomes an incident.

The cost is rarely limited to the incident itself. It lies in the decisions that were never made along the way.

01 · What I see
Structural exposure

The asymmetric breakdown and cognitive debt.

Cyber threats, technology, and exposure are changing faster than an organization’s understanding and capacity to act can keep pace.

Cognitive debt

An incident rarely happens without a buildup. It exposes dependencies and unresolved questions accumulated over time—decisions leadership never actively made. The debt comes due at the worst possible moment.

Capability collapse

Technological innovation becomes offensive capability more quickly than it creates defensive effect. AI makes the gap clear: attackers can put the technology to use immediately, while defenders must contend with governance, compliance, and implementation.

Compressed time

Cyberattacks are typically detected after the fact. As the pace accelerates, the time between detection and action becomes decisive in determining the consequences.

Cyberattacks have their greatest impact where an organization’s own structural weaknesses meet an overlooked exposure.

02 · Peacetime
The Board & Executive Team

Three questions that test an organization’s understanding of its own risk.

01

Who are your real adversaries?

Not whoever appears at the top of the latest threat report. Who actually has the intent and capability—and represents a material business risk to your organization?

02

Where is your greatest structural exposure?

In your technology? Your supply chain? Geopolitical dependencies? Regulation? Or in assumptions the organization no longer challenges?

03

Who holds the mandate when time compresses?

When hours turn into minutes, unclear ownership is no longer just a governance issue. It becomes part of the risk itself.

03 · Method
From signal to mandate

From signal to decision.

I turn external conditions into action.

01

Signal

What is beginning to change? A new capability, a geopolitical shift, or a regulatory change.

02

Translation

What does it mean for your organization? Where does the development intersect with your technology and dependencies?

03

Dilemma

What needs to be decided? Complexity is distilled into clear choices or questions about risk acceptance.

04

Beslutning

Who owns it—and when? Analysis creates value only when it enables action.

04 · Working together
Independent capacity

Some questions require an outside perspective.

Security organizations rarely lack data; they often lack the translation into business reality.

01

A specific question

A deeper analysis of what has changed, what it means for you, and what you need to decide.

02

A leadership forum that needs to be challenged.

A shared starting point for a board or executive team—from NIS2 and DORA to concrete questions about the organization’s risk and threat landscape.

03

An ongoing need

Some needs cannot be defined as a single assignment. In these cases, I work continuously and closely with the CISO or board on strategic objectives, concrete issues, and the decisions that arise along the way.

05 · My work
Analysis · op-eds · briefing

Selected analysis and perspectives

I contribute regularly to the public conversation on the forces shaping cyber risk, technology, and geopolitics.

Børsen · Op-ed

When Everything Is on Fire

On the structural gap between Danish companies’ need for rapid support during serious cyber incidents and the national incident-response framework.

Read the op-ed →
Altinget · Op-ed

Digital sovereignty must not be reduced to simply replacing software

On how geopolitical uncertainty is changing the conditions for European technology choices—and why the question is not merely which technology is best, but which dependency and political exposure leaders are willing to accept.

Read the op-ed →
Perspective · Analysis

The threat level has been VERY HIGH for 10 years. That is why it cannot tell you what to do.

On the difference between the national threat environment and an individual organization’s exposure—and who actually owns the translation between the two.

Read the analysis →
Arx Insight Briefing

The Geopolitical License to Operate

Frontier AI is no longer just software organizations buy. Access has also become a geopolitical dependency—and therefore a governance issue.

Read the BRIEFING →

Speaking engagements & expert conversations

I regularly give talks and take part in expert conversations about cyber risk, geopolitics, and the strategic questions that arise when conditions change—at professional networks, closed forums, and industry events.

Inquiries about speaking engagements and briefings →
06 · Arx Insight Briefing
Monthly analysis

Arx Insight Briefing

One development. One dilemma. No noise.

Arx Insight Briefing is my free monthly analysis of one structural shift in cyber, geopolitics, technology, or regulation.

I analyze one signal, examine the mechanism behind it, and follow its implications through to the question leadership needs to decide.

Monthly · Free · Independent
Get the Briefing →
07 · Contact
Independent perspective

Contact

Are you facing a decision that requires an independent perspective?

It does not need to be a defined assignment.

If something has changed, an assumption no longer holds, or you need to pressure-test your reading of a situation, get in touch.