Practice · Engagements & specialties

Cybersecurity consulting, in writing.

Core practice areas, specialized engagements, and senior advisory by the hour. Every engagement starts with a one-page statement of work and ends with source files the client owns outright.

A modern open-plan workspace where senior practitioners deliver engagements
No. 01 · Start here

Start with the situation in front of you.

Most clients arrive with one of these six. Each links to the engagement built for it, with the deliverables and timeline named before any meter starts.

Compliance · SOC 2 A customer is asking for SOC 2

Readiness, evidence, and audit accompaniment that close the deal without hiring a compliance manager.

SOC 2 readiness →
Compliance · CMMC A DoD contract requires CMMC

NIST 800-171 controls, SSP and POA&M, SPRS scoring, and C3PAO liaison for contractors handling CUI.

CMMC readiness →
Risk The insurance renewal got harder

A risk assessment that answers the carrier's questionnaire honestly and fixes what it surfaces.

Risk assessment →
Response You think you have been breached

Same-day incident response: containment, forensics, breach-notification support, and recovery.

Incident response →
Leadership You need a security leader, not a hire

A virtual CISO on retainer: strategy, board reporting, vendor reviews, and architecture sign-off.

Virtual CISO →
Offensive You want proof the defenses hold

A penetration test with manual verification, an attack narrative, and a free retest of High and Critical findings.

Penetration testing →

Anything that does not fit a named engagement runs as security consulting by the hour or the project.

No. 02 · Practice areas

What we do.

01 · Posture

Risk Assessment

A posture review against NIST CSF 2.0 or ISO 27001. Written report, risk register, prioritized 90-day remediation plan, and executive readout.

See engagement →
02 · Compliance

Compliance & Audit Readiness

SOC 2, HIPAA, PCI-DSS, CMMC, and NIST 800-171. Gap analysis, policy library, evidence runbook, and audit accompaniment.

See engagement →
03 · Leadership

Virtual CISO

Senior security leadership on a monthly retainer. Strategy, board reporting, vendor reviews, architecture sign-off, and incident command.

See engagement →
04 · Response

Incident Response

Same-day response retainer. Containment, forensics, breach-notification support, and post-incident hardening.

See engagement →
05 · Offensive

Penetration Testing

External, internal, web application, and cloud testing to PTES and OWASP. Manual verification, an attack narrative, and a free retest of High and Critical findings.

See engagement →
06 · Resilience

Ransomware Readiness

The controls that decide a ransomware outcome: tested backups, identity hardening, segmentation, and a rehearsed response runbook. Mapped to NIST CSF and CISA guidance.

See engagement →
07 · Cloud

Microsoft 365 & Workspace Security

Hardening Microsoft 365 or Google Workspace to the CIS Benchmarks: identity and conditional access, email security, sharing and DLP, and audit logging, with a reusable baseline.

See engagement →
No. 03 · Consulting

Consulting.

Senior practitioners for the work that does not fit a standard retainer. Three tracks: security consulting, AI security and governance, and security engineering.

A senior practitioner working through a security decision with a client team
A · General

Security Consulting

A senior practitioner on call for the decision in front of you: a design to review, a vendor to choose, a board deck to prepare, a policy redline to turn around. You bring the question; we bring the experience.

  • Architecture and design review. An independent read on a cloud, network, or product-security design, with findings and a prioritized recommendation memo.
  • Vendor and tool selection. A side-by-side scorecard of technical fit, integration cost, and known weaknesses across the candidates.
  • Tabletop facilitation. A scripted ransomware, business email compromise, or insider-threat exercise for leadership, with a written after-action report.
  • Policy redlines. An auditor or customer redlined your policies; we turn the redline in writing, or author a new policy set to your environment.
  • Board and executive preparation. Coaching the security leader through a board presentation and drafting a one-page cyber risk dashboard.
See security consulting →
A processor on a circuit board, representing the AI systems and models under governance
B · AI

AI Security

Governance and security for the AI your business is already using or building. We map the risk, write the rules, and leave you a program you can show a customer or a regulator.

  • AI acceptable use policy. Plain-language rules for staff on approved tools, prohibited data, and review, authored to your environment.
  • NIST AI RMF profile. A risk profile against the AI Risk Management Framework: govern, map, measure, and manage.
  • OWASP LLM Top 10 review. An application-security review of an LLM or agentic feature against prompt injection, data leakage, and the OWASP LLM risks.
  • Model and vendor governance. A vendor risk matrix and contract appendix covering training rights, data residency, and incident notification.
  • AI incident readiness. A playbook for model leakage, harmful output, and audit or regulatory failure, with notification triggers.
See AI security →
Structured fiber and network cabling in a hardened infrastructure rack
C · Engineering

Security Engineering

Hands-on engineering for the controls that carry your posture: identity, network automation, and infrastructure hardening. Built to open standards, handed over as source files you own.

  • Identity management. Zero Trust identity, SSO and SCIM, IGA, PAM, and phishing-resistant MFA.
  • Network automation. Ansible and Python, config compliance as code, drift detection.
  • Infrastructure hardening. Cisco and Dell switching and routing, and Windows and RHEL servers, against CIS Benchmarks and DISA STIGs.
See security engineering →
No. 04 · Industries

Who we work with.

We focus on the industries where a security failure carries real regulatory and contractual weight. In each, we know the framework your auditors and customers expect, and we build the program to meet it.

HIPAA · ePHI Healthcare

Practices, digital health, and billing. HIPAA risk analyses, ePHI safeguards, and the policies a payer or partner will ask to see.

SOC 2 · ISO 27001 SaaS & Technology

The audits your enterprise customers gate the deal on. Readiness, evidence, and a security story that closes procurement faster.

GLBA · PCI DSS Financial Services

Advisors, fintech, and payment handlers. Controls that satisfy regulators and the banks and processors you depend on.

CMMC · NIST 800-171 Defense & GovCon

Contractors carrying CUI. The 800-171 controls and CMMC posture you need to stay eligible to bid and to deliver.

Confidentiality · Privilege Professional Services

Law, accounting, and consulting firms holding sensitive client data. Protection that holds up to a client security review.

IP · OT Security Manufacturing

Protecting trade secrets and the line itself, where IT and operational technology meet and downtime is measured in dollars.

No. 05 · FAQ

Common questions.

How are engagements priced?

Every engagement is scoped to a one-page statement of work that names the deliverables, the timeline, and the cost before any meter starts. Defined engagements run fixed-fee or on retainer; consulting runs by the hour or the project. Scope changes go in writing first.

Where do you work, and do you come on-site?

The firm is headquartered in Orlando, Florida. On-site work across the Orlando metro is included in the engagement price, statewide Florida visits are quoted per trip, and remote engagements run nationwide.

What do we receive when the work ends?

Source files, not platform exports: policies, runbooks, reports, risk registers, and diagrams in Word, Markdown, draw.io, or Visio. While the work runs, progress, findings, and documents are tracked in the client portal.

Who actually does the work?

Senior practitioners holding CISSP, CGRC, and CISA credentials, with backgrounds in federal cyber operations, enterprise security engineering, and Big Four audit. There is no offshore handoff on assessment or compliance work.

No. 06 · Engage

Not sure which engagement fits?

A thirty-minute call to understand your business and what's pushing the question. If we're not the right firm, we'll say so.