Bastion Policy Partners

Better Decisions.
High-Stakes Environments.

Boutique advisory firm. Two practices: cyber and technology risk, and maternal and child health policy. Nick and Jessica Ashley lead every engagement.

Our Thesis

The domain changes.
The problem doesn't.

Cyber risk and health policy are different fields with different buyers, regulators, and failure modes. The underlying challenge is the same: making a call when the information is incomplete, the stakes are real, and getting it wrong costs more than getting it right.

You work with the person whose expertise you engaged. Nick leads every cyber engagement. Jessica leads every health policy engagement.

About the firm →

Proprietary Frameworks

Frameworks built for the problem,
not borrowed from an adjacent one.

ATLAS, CCTM, and SENTINEL came out of live deployments at MISO Energy and U.S. Cyber Command, environments where a wrong model produces a $1M/day regulatory penalty or a failed operation, not a missed KPI.

ATLAS Enterprise technology risk and decision support
CCTM / Cognitive Kill Chain Human-layer and adversarial risk modelling
SENTINEL Executive risk reporting
View all frameworks →

The Team

Two advisors. No associates.

N
Nick Ashley
Principal Advisor, Cyber & Technology Risk
Bio →
J
Jessica Ashley
Principal Advisor, Health Policy
Bio →
Full team profiles →

Latest Insights

All insights →
Cyber & Technology Risk

The Human Layer Is the Attack Surface

Adversaries exploit attention, trust, and the decision shortcuts that govern behaviour under pressure. Standard threat models don't account for it.

Cyber & Technology Risk

NERC CIP Compliance Is Not Grid Security

Passing the audit and securing the grid are different objectives. The gap between them is where breaches happen.

Cyber & Technology Risk

Executive Risk Reporting Should Drive Decisions, Not Document Risk

Boards act on financial exposure and operational consequence. Vulnerability counts and severity ratings don't give them that.