Identity and Access Management is rarely a tooling problem

Most IAM failures aren’t caused by weak technology. They fail because of poor decisions, unclear ownership, unrealistic delivery models, and a lack of experienced judgement at the points where it matters most. Arcalis Services exists to address those failures.

One practice.
One senior practitioner.

Arcalis is deliberately structured differently from traditional consultancies.

There are no delivery teams, junior analysts, or account layers. Every engagement is led and delivered end‑to‑end by the founding practitioner.

This model exists for one reason: to reduce risk.

IAM programmes accumulate risk fastest at hand‑off points — between strategy and delivery, between design and implementation, and between advisory guidance and real‑world constraints. Removing those hand‑offs significantly reduces architectural erosion, rework, and control failure.

Clients work directly with the person accountable for decisions, outcomes, and advice — from initial scoping through to final delivery.

Led by experience, not process

Arcalis is founded and led by Andrew Cant CITP FBCS, a senior IAM and cybersecurity consultant with:

  • 25 years in enterprise IT and security
  • Over a decade specialising in IAM delivery, architecture, and advisory
  • Board‑level and executive advisory experience
  • Deep exposure to regulated and security‑critical environments

Andrew’s background spans the full IAM lifecycle — from strategy and operating model design, through platform selection and delivery oversight, to programme rescue and post‑incident remediation.

This is not theoretical IAM. It is experience gained where failure is visible and consequences are real.

Chartered Fellow - CITP FBCS
CISSP
CISM
CIAM
AZ-500
ITIL4 Specialist
Andrew Cant CITP FBCS

Senior Accountability

Andrew Cant acts as design authority, risk advisor, and escalation point on every Arcalis engagement. All strategic, architectural, and governance decisions are made or reviewed directly by him, ensuring continuity of judgement and clear accountability from start to finish.

Adversary‑tested identity security

In 2021, Arcalis led the defence and remediation of a state‑sponsored intrusion (APT29) targeting enterprise infrastructure. That experience fundamentally shapes how identity security is approached:

  • Controls are assessed for how they fail under pressure — not how they appear in policy
  • Privileged access, identity governance, and authentication are treated as attack surfaces
  • Risk is evaluated through adversary behaviour, not platform checklists

This directly informs Arcalis’ work in identity security, risk reduction, and IAM programme assurance.

Independent by design

Arcalis has no vendor affiliations, resale agreements, or delivery quotas.

That independence enables:

  • Objective architectural decisions
  • Honest risk assessments — even when uncomfortable
  • Platform‑agnostic advice driven by context, threat, and regulation
  • The freedom to recommend slower, safer approaches when required

Clients receive recommendations shaped solely by what reduces identity risk — not by partner commitments or roadmap alignment.