Regis Lance

Founder

Enterprise security executive and program builder with nearly two decades translating high-consequence architecture into investment priorities, accountable execution, and defensible decisions.

Biography

Executive judgment grounded in systems where failure has consequences.

Regis Lance founded Foldspan after seeing the same executive problem across national security, Big Tech, cloud, and other high-consequence environments. Leaders were allocating capital, approving launches, and accepting risk from partial views that were individually credible but did not explain the whole system or support one accountable decision.

His experience spans cyber warfare and signals intelligence supporting the NSA while serving on active duty in the U.S. Navy, followed by work across Big Tech and cloud providers, satellite network engineering, and the public-safety and defense industries.

His approach connects technical reality to the choices leadership owns. Show what can move forward, where money and engineering time should go, which assumptions need proof, what must change, and what evidence supports the remaining risk.

Technical depth in service of executive judgment.

Each chapter reflects a different part of the same practice: understand the architecture, model the adversary and failure paths, test assumptions, preserve evidence, and make remediation executable.

National security

Make decisions when evidence is incomplete and consequence is real.

Regis spent eleven years on active duty in the U.S. Navy working across cryptologic warfare, signals intelligence, electronic warfare, cyber and electromagnetic operations, information systems, and network operations supporting NSA mission objectives. The work required multidisciplinary teams to understand advanced adversary capabilities, operate through constrained communications, preserve readiness, and make time-sensitive decisions with real mission consequence.

That experience established the discipline behind Foldspan: understand the adversary, follow the complete system, distinguish assertion from evidence, and test whether controls still work under pressure.

Offensive assurance

Find the exposure that falls between ownership boundaries.

In Big Tech and hyperscale-cloud environments, Regis built and led an international offensive-security program spanning cloud services, datacenters, wired and wireless networks, physical Layer 1, mobile applications, edge systems, vendors, and globally deployed infrastructure. He scoped penetration and non-cooperative testing, developed repeatable playbooks and operating models, and translated technical findings into engineering remediation and executive risk decisions.

The work repeatedly exposed risks that sit between conventional review domains: a vendor connected to an internal network, a mobile workflow crossing an API, physical infrastructure governed by cloud identity, or an urgent delivery assumption that had never been tested.

Connected systems

Balance security with availability, privacy, and operations.

In public safety, Regis worked across body-worn and in-vehicle systems, LTE routers, edge video and audio, APIs, SaaS evidence platforms, mobile workflows, and field deployments. Security had to coexist with privacy, availability, chain of custody, supportability, and the realities of systems used by law-enforcement agencies and first responders.

He later worked across terrestrial and aerospace architecture for a low-Earth-orbit satellite constellation. That system joined software-defined networking, datacenter and cloud services, control and data planes, points of presence, customer terminals, radio behavior, terminal software, and FPGA and ASIC dependencies. Assurance reached into cryptographic key lifecycle, artifact signing, build and update integrity, supply-chain risk, hardware-layer testing, and offensive exercises.

Cloud, application, and AI security

Turn architecture risk into portfolio priorities and funded execution.

Across enterprise cloud and regulated-technology programs, Regis has led architecture and posture reviews across identity and access control, workload identity, segmentation, secrets, service-to-service trust, telemetry, data protection, application security, secure delivery pipelines, vulnerability management, and post-acquisition integration. He has also built maturity assessments, portfolio priorities, operating models, and implementation roadmaps that connect findings to accountable owners, funding, and delivery.

His AI work focuses on governance and system security rather than model research. It includes threat modeling for AI and agentic systems, prompt injection, tool misuse, nonhuman identity, data-access and exfiltration risk, model and software supply chains, human approval boundaries, and the evidence required for a responsible deployment decision.

Enterprise leadership and technical depth

His work has included STRIDE and ATT&CK/ATLAS threat modeling, secure-design and code review, penetration-test scoping, IAM and access-control analysis, segmentation and workload identity, SAST, DAST, SCA, and fuzzing programs, cryptographic lifecycle and release-integrity review, vulnerability remediation, and Python-based policy and CI/CD automation. The tools matter only when they connect architecture, evidence, ownership, and a decision.

Connect technical reality to investment, ownership, and evidence.

Regis brings an adversary-informed systems view to architecture decisions. He connects technical reality to the business outcome, the material conditions that can change it, the investment required, accountable ownership, and the evidence behind the decision.

Foldspan turns that approach into a bounded assurance method, then maintains the decision basis as the system changes or extends it across a portfolio.

Why Foldspan

Leaders need more than another partial risk view. They need to know what can move, where money and time should go, what can wait, which risk they are accepting, and what evidence will demonstrate completion.

Public boundary

Experience without borrowed secrets.

Some work behind this experience remains classified, customer-confidential, employer-confidential, proprietary, or export-controlled. Foldspan does not use restricted material as marketing proof, product content, training data, or customer evidence. The value comes from disciplined judgment and public-safe patterns, not privileged access.

Bring the consequential decision into view.

Start with the commitment, business outcome, accountable owner, and date due. Sensitive evidence is not required for an initial conversation.

Discuss a Solution

Please do not send sensitive system details. A protected channel will be established before technical discovery.