Home / About
About
A specialist security practice, operating from Finland and working internationally.
The practice
Cipherworks Digital Security Agency
The company is Cipherworks Digital Security Agency Oy, registered in Finland. It operates under the cipherpunks.fi name, which came first and stayed.
The practice is led personally by Arimo Koivisto. Engagements are delivered by the person who scopes them rather than passed to a delivery team, which keeps the work small, direct and accountable.
Where a programme needs capability beyond one person — specialist engineering, national-scale delivery, product development — it is brought in through established partnerships rather than hired to fill a bench. That is a deliberate choice about how the practice stays useful rather than how fast it grows.
Arimo Koivisto · Founder
Background
From collection to protection
Arimo Koivisto came to security from intelligence rather than from IT. He is a Master of Military Sciences from the National Defence University and a Major in the Finnish reserve. In 2005–2006 he served with the Finnish contingent in NATO’s Kosovo Force as second in command of the Intelligence, Surveillance and Reconnaissance company, and afterwards as second in command of a reconnaissance company at the Reserve Officer School.
That work was about collection — how information is obtained from systems and from people who would prefer it were not. Most of the two decades since have been spent on the other side of the same problem: building and delivering secure communications and secure computing for national security customers internationally, including secure voice and messaging, cryptographic key generation and distribution, hardened endpoints, and the operational practices that surround them. Later, cross-domain separation for defence and government, where separation has to be enforced by hardware rather than by configuration.
Most security work is done where an adversary has to break in, and where standard, certified, widely adopted technology is the correct answer. A smaller amount is done where neither of those things holds — where capability can be designed into what you buy through standards participation, ownership and jurisdiction, and where “widely adopted and certified” may describe an adversary’s reach rather than your protection. That is a matter of public record rather than speculation, and it is set out in more detail in threat tiers and assurance.
The two situations look alike on paper and are defeated by entirely different controls. Most organisations are in the first, and we say so plainly. This practice exists because some are not.
Areas of practice
Where the experience actually sits
Assessment & standards
ISO 27001 maturity and gap work, NIS2 readiness, ISO 42001 and AI governance, security due diligence.
Threat modelling
Structured analysis of specific services and systems, including public-sector digital services and AI deployments.
Identity & authentication
Passwordless and phishing-resistant authentication, FIDO2 and smart card architecture, IAM and IGA target-state design.
Network separation
Segmentation architecture and cross-domain solutions where separation must be enforced by hardware rather than configuration.
Secure communications
High-assurance voice and messaging, cryptographic key management, and architecture where confidentiality cannot depend on the supplier.
Mobile threat & forensics
Detection and analysis of compromise on mobile endpoints, including targeted intrusion against high-value users.
Programme architecture
Acting as security architect and technical lead across multi-vendor programmes, including national-scale and safe-city concepts.
Technology evaluation
Vendor-neutral selection and integration of security technology, and the testing platforms used to validate it.
Training & OPSEC
Operational security and cyber hygiene work for teams whose exposure is higher than their organisation’s average.
Sectors
Who this work has been for
We do not publish client names. Most of this work is covered by confidentiality, and in several sectors naming a customer would itself be a disclosure.
Public authorities
National agencies and public-sector digital services.
Defence & national security
Defence-adjacent environments, without being defence-exclusive.
Critical infrastructure
Operators of essential services, energy and industrial estates.
International organisations
Humanitarian and cross-border bodies operating in difficult environments.
Regulated enterprise
Organisations with formal obligations over data and resilience.
Technology companies
Product and platform businesses building security into what they ship.
Executive protection
Leadership and board communications under elevated exposure.
Emerging markets
National capability programmes, delivered with local partners.
Working with us
Three things worth knowing
We work under NDA as standard. Specific references can be discussed directly, under agreement. They are not published, and we would treat your engagement the same way.
Advice is separated from supply. Assessment and architecture work is available entirely independently of any product. Where a commercial relationship exists with a technology we recommend, it is stated before the recommendation.
Engagements start small. A defined piece of work with a clear deliverable tells both sides whether the fit is real, faster than any proposal.
The company
