Bricole Security Advisory
JA EN

Security Advisory — Tokyo

A seasoned counterpart
for security decisions.

For leaders covering security alongside another role — and for those building the function from scratch — we put the material for a decision on the table together. Yuki Shigeiwa — Managing Executive Officer and CISO at freee, and founder of DeNA's security department — works with you directly, with no account manager in between.

Advisor

茂岩 祐樹

Yuki Shigeiwa

Representative Director, Bricole Inc.
Managing Executive Officer & CISO, freee K.K. (2022–2026)
Founding member of DeNA; founded its Security Dept. (1999–2022)

View full profile →

30 yrs

In IT & security practice

100+

Conference talks

3

Books published

4 yrs

As CISO of a listed company

01 — Your challenges

When clients
bring us in

01

Security sits with you on top of another role, and there is no one to test a judgement against

There is no precedent inside the company, and asking a vendor returns whatever they are selling. We provide a place to check your thinking with someone who has nothing to sell you.

02

You are standing up — or scaling — a security organisation

What the first hire should own, and in what order to widen the scope. Having done this twice from zero, we can tell you a realistic sequence.

03

You cannot settle on the right altitude for board-level reporting

A technically correct explanation rarely lands with management as-is. We work out together what to turn into numbers and what to leave out.

04

You want to decide how far to invest, and where to stop

Drawing a line that is neither excessive nor insufficient for your business stage. This is a frequent request from startup CTOs and CIOs.

02 — Client cases

Engagements across growth stages

From listed companies and pre-IPO businesses to early-stage startups, we shape the engagement around the organisation and the problem in front of it.

Listed Company

Listed company

Challenge

A dedicated security function was in place, but among many competing issues, questions about priority and the right level of response never stopped.

Support

Regular sessions to test day-to-day judgements and open issues, plus a continuous supply of industry movements and current intelligence as decision input.

Pre-IPO Company

Pre-IPO company

Challenge

A small team wearing several hats handled daily issues well, but the path to listing called for a medium-to-long-term security plan.

Support

Advice on investment, organisation and sequencing that uses frameworks without collapsing into box-ticking, supporting the drafting of a multi-year plan.

Startup

Startup

Challenge

Security was recognised as critical for a B2B service, but no one in-house held the expertise.

Support

Security input into service design, plus drafting and review of security policies and personal-data-related internal rules.

Cases are anonymised; client names and quantitative outcomes are withheld. The scope of each engagement is set by individual contract.

03 — Services

Two ways to work together

A continuing engagement that supports everyday judgement, and project work for themes with a defined deliverable and deadline.

Ongoing Advisory

Ongoing security advisory

Through regular dialogue, we support day-to-day judgement, the prioritisation of initiatives, communication with management, and the growth of the team.

  • A sounding board for security leads, CTOs and CIOs
  • Prioritising initiatives and investment
  • Setting the level of response that fits your company
  • Structuring reporting to the executive team and board
  • Review of medium-to-long-term plans
  • Developing security leads and their teams
  • Decision input informed by industry movements

Monthly (excl. tax)

From JPY 200,000

Base engagement: one 60-minute standing session per month, plus ongoing consultation over Slack. Fees scale with the frequency of the standing session; we will quote against the rhythm you need.

Focused Project

Programme & project support

For themes with a defined scope or deadline, we support planning and the production of deliverables as a discrete project.

  • Security strategy and multi-year roadmap
  • Standing up a security function or CSIRT
  • Drafting and reviewing security policies and related rules
  • Security input into service and system design
  • Responding to customer security assessments and audits
  • Adjacent support on engineering organisation and IT/DX strategy

By scope and duration

On quotation

Quoted per engagement. Where useful, project work can run alongside an ongoing advisory retainer.

Capacity

To keep the quality of each engagement, we cap the number of companies supported at any one time. Depending on when you get in touch, there may be a wait — and we would rather tell you that than take on work we cannot do properly.

All figures are guide prices excluding tax. We quote against the scope and rhythm of the engagement.

04 — Profile

About the principal

茂岩祐樹

茂岩 祐樹

Yuki Shigeiwa

Bricole Inc.
Representative Director

I supported a company as an engineer from founding through to listing, then built its security department from nothing.

Born 1971. Completed a master's degree in engineering at Tokyo Metropolitan University in 1995. After IBM Japan, joined the founding of DeNA in 1999 and led the infrastructure organisation. Launched the cyber security team in 2010 and became Head of the Security Department in 2014. Founded Bricole Inc. in 2019, and served as CISO of a listed company.

Having spent long stretches in both the engineering room and the boardroom, I can help you close the gap between what is technically right and what the company can actually carry.

Career

1995

Joined IBM Japan

Storage systems technical support. Engineer for UNIX storage systems.

1999

Joined the founding of DeNA

Led infrastructure: networking, server build and operations, performance. Carried the company from founding through to listing.

2010

Founded the cyber security team

Built the in-house security function from zero, alongside leading infrastructure.

2011

Head of Systems Division

Oversaw IT platform, corporate IT and QA.

2014

Founded the Security Department; Head of Department

DeNA CERT Representative and information security officer. Also built the function at US and China sites.

2019

Founded Bricole Inc.

Representative Director (present). Security advisory for companies.

2022

Managing Executive Officer & CISO, freee K.K.

Led company-wide security strategy (through July 2026).

Activities

  • 2018Programme Committee Chair, FIRST Osaka Technical Colloquium
  • 2019Instructor, CySecPRO Threat Hunter Course

05 — Record

Talks & media

Speaking and writing on building security organisations, the role of the CISO, and engineering.

Open the full talk archive (2024–2026)
2026
02.18 Security at freee Revival Management Forum
2025
11.12Security Nexus ConferenceSecurity Nexus Conference
11.07 What security ought to look likeWest-Sec
09.02 Cyber resilience strategy for an escalating threat landscape, 2025 edition Security Innovation Conference
07.17Findy Deep Security ConferenceFindy
07.15 Incident response: preparation, execution and mindsetWest-Sec
03.18 Kyushu Cyber Security SymposiumKYUSEC
2024
12.19NCA Annual ConferenceNippon CSIRT Association
11.13AMIYA Security Blaze 2024Amiya
10.10 Information Security Workshop in Echigo-YuzawaANISEC
05.31 Growing a security culture: ideals and reality, from the CISOs of scaling companiesITmedia
03.05 Security Strategy Seminar 2024Nikkei BP
02.21 Cyber security under growing complexity: crisis management and emerging technologies EY Digital Trust Webinar

A selection. Talks before 2024 and closed corporate sessions are not listed.

06 — FAQ

Frequently asked questions

Q1Can we talk to you even without a dedicated security team?

Yes. We act as a sounding board for people covering security alongside another role, and for CTOs and CIOs, and we support startups with no specialist in-house. We start by sorting out what should come first given the team you have today.

Q2What size and stage of company do you work with?

We have worked with startups, pre-IPO businesses and listed companies. Rather than headcount, we shape the engagement around your current problems and business stage.

Q3You work alone — is there a limit to how many companies you can take on?

Yes. To keep the quality of each engagement, we cap the number of companies supported at any one time, so depending on timing there may be a wait. If we are at capacity we will say so at the first conversation, rather than accepting work we cannot give proper attention to. Where an engagement is time-critical, we can also introduce you to trusted people in our network.

Q4Can you also help with explanations to the executive team or the board?

Yes. We translate technical points into business, financial and customer impact, and organise the information and level of detail a decision actually requires.

Q5Can we also raise IT and DX issues beyond security?

We have supported engineering organisation design and IT/DX strategy adjacent to security. Tell us the scope of the problem and we will say honestly whether it is a fit.

Q6Who will actually be doing the work?

Yuki Shigeiwa, the principal, works with you directly — from the first conversation through the ongoing engagement, with no account manager in between and no handover to someone else.

Q7Is there a charge for the first conversation?

No. We listen to where you are, then propose the involvement that fits. If we judge that you do not need support right now, we will tell you that plainly.

07 — Company profile

Company

Company name

Bricole Inc.

Location

Minato-ku, Tokyo, Japan

Founded

July 2019

Capital

JPY 3,000,000

Representative Director

Yuki Shigeiwa

Services

Security and IT consulting

Delivery

The principal works with you directly; no handover to another consultant

08 — Contact

Get in touch

We listen to where you are, then propose the involvement that fits. There is no charge for the initial conversation, and depending on what we hear we may tell you that you do not need us right now.

Mail

 

Tapping the address opens your mail client. Please include your company and name, and as much of your current situation as you are comfortable sharing.

Speaking and writing enquiries are welcome at the same address.