MarkoTuiskContact

About

Marko Tuisk

Director, TSCM Partners Ltd. Born in Tallinn, based in Reading. I work where physical security meets technical security, and I write the software that measures it.

I was born in Tallinn and I live in Reading, England. The work I do now — technical surveillance countermeasures, speech privacy, and the software that measures both — sits at the end of a longer journey into business, not at the start of a security origin story.

I began in operations: hospitality supervision in Pennsylvania, then nine years at Swedbank Estonia in corporate factoring, trade finance and corporate lending, including through the 2008 crisis. That is credit-side work — portfolios, restructuring, and the discipline of saying yes or no when money is real. I later served as group CFO at Eesti Metsnik. Boards and their advisers often trust that background more readily than an ex-military claim I do not have.

I founded Tark Composit to build fibre composite structures for subsea use. We raised angel capital, built a prototype and tested it in Norway. The business did not succeed. What remained was the habit of owning the outcome.

From there the technical half of the practice formed. I worked hands-on in technical surveillance countermeasures under the Whiterock Privacy name — engineer, then technical operations lead, then technology leadership. That name was the security practice line in a wider Cope Whiterock context: as I understand it, lines broke out as the owner moved toward arts and away from security. Companies House shows Cope Whiterock Limited (03063360, incorporated June 1995, still Active) with Crispin Edward Sturrock as sole current director; no company named Whiterock Privacy on the register; and Whiterock First Limited (15016256, July 2023) as a separate filing where I am a director and a person with significant control — not a filed subsidiary of Cope Whiterock. Trading names and group stories often diverge from what the register records.

In September 2017 I joined Mobilewatch Limited as a director, on indoor positioning and radio-frequency detection of mobile devices in controlled environments. Mobilewatch was previously registered as Whiterock Confidential Limited; it has since stopped trading and its Companies House record is public. I remain an Active director on that record.

Alongside that I built and still run operating companies: Goyoga Estonia OÜ from 2014, and MedCare OÜ (WeCare) from 2022. I developed the PASM framework at Security and Privacy Partners Ltd, which I set up with Raili Maripuu in February 2025 and which was dissolved in August 2026. From mid-2024 I began building the practice systems and software I use today. I incorporated TSCM Partners Ltd on 10 November 2025; that is the company that now holds the technical security practice. The mid-2024 date is software and practice build work, not the Ltd's incorporation.

In 2026 I applied pure analytical skills to a turnaround at GoYoga — the studio whose technical systems I have built since 2014 — and made my way into SEO and digital sales. The live platform is the proof of engineering capability; the 2026 work was analytical and commercial. SEO Studio Estonia is the commercial expression of that search and digital-sales path.

I have used large language models, agents and automated workflows since the first public OpenAI models, and I keep rebuilding how I work as the tools change. For a maker who grows with the stack rather than performing expertise about it — and who does most of the work through writing and systems rather than rooms full of people — that tooling is leverage.

The part that is genuinely unusual is the combination of three things, not two. Almost everyone in technical surveillance countermeasures comes from a police or military background and buys their tooling. Almost everyone who builds security software has never physically searched a boardroom. The third uncommon piece is credit-side corporate experience — which is why scoping and reports tend to sound commercial rather than theatrical. I publish the methods because an industry that cannot be measured cannot be held to a standard.

I am not a conference speaker and I do not sell through fear. If you want to know whether I am any good, read the frameworks, check the registers, and ask me the questions in the buyer's standard.

What the credit years give clients

What that gives clients is transferable professional judgement, not colour for a CV: credit risk judgement; reading a balance sheet and an exposure; stakeholder and board-level communication; working through crisis and restructuring; and saying no when the risk is wrong. Boards, founders, family offices and their advisers buy TSCM and speech privacy from someone who already understands money, risk and how organisations behave under stress.

Journey

In date order, most recent first. Practice systems and software from mid-2024; TSCM Partners Ltd from November 2025. Company appointments link to the register that confirms them. Employer and venture entries without a link are career history, not implied filings.

  1. Director, TSCM Partners Ltd

    Nov 2025 — present

    Technical surveillance countermeasures, inspections and speech privacy for organisations and individuals in the UK and Europe. Sole director, and the only person with significant control, holding 75% or more of the shares and voting rights. Incorporated on 10 November 2025, so it has not yet reached its first accounts deadline and has no filed accounts to inspect. That is a fact worth knowing before you engage it. Practice systems and software work began earlier (mid-2024); that is not the Ltd's start date.

    Companies House 16842743
  2. Director and co-founder, Security and Privacy Partners Ltd (SAPP Security)

    Feb 2025 — Aug 2026

    Set up with Raili Maripuu to address the physical and proximity attack surface that cyber security controls do not reach. I developed the PASM framework and the accompanying maturity score here. The company filed no accounts and was dissolved on 25 August 2026 following compulsory strike-off. The framework outlived it and is published on this site under my own name.

    Companies House 16271231
  3. Practice systems and software development, Technical security practice (pre-incorporation)

    Mid-2024 — Nov 2025

    Began building the practice systems and software used in the work today. This is career narrative for the build period, not a UK Ltd directorship. TSCM Partners Ltd was incorporated later, on 10 November 2025.

  4. Director, Whiterock First Limited

    Jul 2023 — present

    Registered for private security activities. I am a director and a person with significant control. It does not contract for or deliver any of the work described on this site. As I understand the group story, it sits among lines that broke out from the Cope Whiterock security context as the owner moved toward arts; the register shows a separate company (no corporate parent PSC filed as Cope Whiterock Limited), with overlapping historic officers and the same Great Portland Street registered office as Cope Whiterock. It is not the vehicle for the earlier Whiterock Privacy practice work from 2016. Its filing record is on the register and that is the accurate source for legal facts.

    Companies House 15016256
  5. Management board member, MedCare OÜ (WeCare)

    Nov 2022 — present

    Estonian care services company, held equally with Merike Adamson. The public brand is WeCare. I cover technology, information security and business operations — ownership of an operating company, not only a security practice.

    e-Äriregister 16617122
  6. Director, Rockfort Technology Limited

    Feb 2022 — Nov 2023

    A company I set up as sole director, registered for wholesale and retail of audio and video equipment. It never really traded, filed no accounts, and was dissolved on 14 November 2023 following compulsory strike-off. It is on the register under my name, so it is on this page.

    Companies House 13899475
  7. TSCM engineer → technical operations lead → technology leadership, Whiterock Privacy (practice / security line)

    Feb 2016 — Jun 2025

    Hands-on technical surveillance countermeasures, then technical operations, then technology leadership for client work delivered under the Whiterock Privacy name. As I understand it: the security practice line inside a Cope Whiterock group breakup as the owner moved into arts and away from security — alongside related breakouts such as Whiterock First, not inventing a Whiterock Privacy Ltd from 2016. Register check (Sep 2026): no company named Whiterock Privacy; Cope Whiterock Limited 03063360 (Active, inc. 1 Jun 1995; I am not an officer); Whiterock First Limited is a separate 2023 company. Related RF company on overlapping years: Mobilewatch Limited (ex-Whiterock Confidential Limited). Titles and the June 2025 end date are not on a public register.

  8. Director, Mobilewatch Limited

    Sep 2017 — present

    Indoor positioning and detection of mobile devices in controlled environments: sensor work, radio-frequency analysis, and the compliance question of what happens when someone brings a personal phone into a restricted room. Appointed director on 20 September 2017; still Active on Companies House. This is where my radio-frequency grounding comes from. The company has stopped trading and the register shows a proposal to strike off. Day-to-day operations ceased earlier; the directorship did not.

    Companies House 09161428
  9. Co-founder and board member, Goyoga Estonia OÜ

    2014 — present

    Co-founded with Raili Maripuu. I run the technical side: the website, the booking and payment flows, the teacher portal, and the search architecture. In 2026 I applied pure analytical skills to a turnaround of the business and made my way into SEO and digital sales. Registered in January 2014. LinkedIn shows August 2016, which may be when studio operations under the GoYoga brand matured; the register date is the one used here.

    e-Äriregister 12595429
  10. Group CFO, Eesti Metsnik

    Jan 2014 — Jan 2016

    Group finance for an Estonian forestry business: reporting, control and the asset side of the operation. Employer role — part of the journey from credit into ownership, not a company on the UK register under my name.

  11. Founder, Tark Composit

    Jan 2013 — Oct 2016

    Fibre composite structures for subsea energy and communications. Raised angel investment, arranged production capacity, designed and built a prototype tested in Norway. The business did not succeed. Stated here because failure is part of learning to own a company, not something to edit out of a verification-first biography.

  12. Corporate factoring → trade finance → senior corporate client executive, Swedbank Estonia

    Dec 2004 — Dec 2013

    Nine years on the credit side of a bank: corporate factoring, trade finance through the 2008 crisis and restructuring, then senior corporate client work. This is why board-level buyers can talk credit, risk and judgement with me without translating from a military CV. Specific lending limits and portfolio sizes are omitted here until confirmed for publication; they belong on LinkedIn once Marko has checked them.

  13. Operations supervisor, Standford Hotel Management (Pennsylvania, United States)

    Dec 2002 — Jan 2004

    Hospitality operations in the United States. The start of the arc: running a floor before running a loan book, then a company.

The short version

Marko Tuisk is a technical security practitioner and software engineer based in Reading, England. He is the director of TSCM Partners Ltd and the author of the PASM framework.