Home  /  About

About

A specialist security practice, operating from Finland and working internationally.

Arimo KoivistoHelsinki, Finland

The practice

Cipherworks Digital Security Agency

The company is Cipherworks Digital Security Agency Oy, registered in Finland. It operates under the cipherpunks.fi name, which came first and stayed.

The practice is led personally by Arimo Koivisto. Engagements are delivered by the person who scopes them rather than passed to a delivery team, which keeps the work small, direct and accountable.

Where a programme needs capability beyond one person — specialist engineering, national-scale delivery, product development — it is brought in through established partnerships rather than hired to fill a bench. That is a deliberate choice about how the practice stays useful rather than how fast it grows.


Arimo Koivisto · Founder

Background

From collection to protection

Arimo Koivisto came to security from intelligence rather than from IT. He is a Master of Military Sciences from the National Defence University and a Major in the Finnish reserve. In 2005–2006 he served with the Finnish contingent in NATO’s Kosovo Force as second in command of the Intelligence, Surveillance and Reconnaissance company, and afterwards as second in command of a reconnaissance company at the Reserve Officer School.

That work was about collection — how information is obtained from systems and from people who would prefer it were not. Most of the two decades since have been spent on the other side of the same problem: building and delivering secure communications and secure computing for national security customers internationally, including secure voice and messaging, cryptographic key generation and distribution, hardened endpoints, and the operational practices that surround them. Later, cross-domain separation for defence and government, where separation has to be enforced by hardware rather than by configuration.


Most security work is done where an adversary has to break in, and where standard, certified, widely adopted technology is the correct answer. A smaller amount is done where neither of those things holds — where capability can be designed into what you buy through standards participation, ownership and jurisdiction, and where “widely adopted and certified” may describe an adversary’s reach rather than your protection. That is a matter of public record rather than speculation, and it is set out in more detail in threat tiers and assurance.

The two situations look alike on paper and are defeated by entirely different controls. Most organisations are in the first, and we say so plainly. This practice exists because some are not.

Areas of practice

Where the experience actually sits

Assessment & standards

ISO 27001 maturity and gap work, NIS2 readiness, ISO 42001 and AI governance, security due diligence.

Threat modelling

Structured analysis of specific services and systems, including public-sector digital services and AI deployments.

Identity & authentication

Passwordless and phishing-resistant authentication, FIDO2 and smart card architecture, IAM and IGA target-state design.

Network separation

Segmentation architecture and cross-domain solutions where separation must be enforced by hardware rather than configuration.

Secure communications

High-assurance voice and messaging, cryptographic key management, and architecture where confidentiality cannot depend on the supplier.

Mobile threat & forensics

Detection and analysis of compromise on mobile endpoints, including targeted intrusion against high-value users.

Programme architecture

Acting as security architect and technical lead across multi-vendor programmes, including national-scale and safe-city concepts.

Technology evaluation

Vendor-neutral selection and integration of security technology, and the testing platforms used to validate it.

Training & OPSEC

Operational security and cyber hygiene work for teams whose exposure is higher than their organisation’s average.

Sectors

Who this work has been for

We do not publish client names. Most of this work is covered by confidentiality, and in several sectors naming a customer would itself be a disclosure.

Public authorities

National agencies and public-sector digital services.

Defence & national security

Defence-adjacent environments, without being defence-exclusive.

Critical infrastructure

Operators of essential services, energy and industrial estates.

International organisations

Humanitarian and cross-border bodies operating in difficult environments.

Regulated enterprise

Organisations with formal obligations over data and resilience.

Technology companies

Product and platform businesses building security into what they ship.

Executive protection

Leadership and board communications under elevated exposure.

Emerging markets

National capability programmes, delivered with local partners.

Working with us

Three things worth knowing

We work under NDA as standard. Specific references can be discussed directly, under agreement. They are not published, and we would treat your engagement the same way.

Advice is separated from supply. Assessment and architecture work is available entirely independently of any product. Where a commercial relationship exists with a technology we recommend, it is stated before the recommendation.

Engagements start small. A defined piece of work with a clear deliverable tells both sides whether the fit is real, faster than any proposal.

The company

Legal nameCipherworks Digital Security Agency Oy
Business ID3563371-3
RegisteredHelsinki, Finland
OperatingInternationally
Led byArimo Koivisto