Virtual CISO
Fractional security leadership. Board reporting, policy development, risk management, vendor reviews, and strategic planning, delivered with the discipline of someone who has operated where failure isn't abstract.
Managed Perimeter & Alert Monitoring
Hardware firewall deployment with configurations mapped to your actual architecture, then held to that standard under a monitoring retainer: every alert triaged, investigated, and answered. Not a SOC ticket queue. The engineer who built your perimeter is the one watching it.
Architecture Review
Deep technical assessment of infrastructure, cloud posture, application security, and network segmentation. Prioritized remediation mapped to CIS Benchmarks and NIST CSF with maturity scoring.
AI Security & Governance
Threat modeling for LLM and multi-agent deployments, adversarial red-team validation, data governance, and alignment with the EU AI Act and NIST AI RMF. Informed by building production AI systems, not just advising on them.
Incident Response
Pre-negotiated retainer with guaranteed response SLAs. IR plan development, tabletop exercises, and the assurance that experienced crisis management is one call away when it matters.
NIST & CIS Assessment
Where your program actually stands, scored against the framework your board or your clients recognize. NIST Cybersecurity Framework 2.0 across all six functions including Govern, CIS Controls v8.1 by implementation group, CIS Benchmark hardening, and formal risk assessment to NIST 800-30. Maturity scoring, a target profile, and a roadmap ordered by what reduces risk first, not what is easiest to close.
Control Baselines & Authorization
NIST 800-53 baseline selection and tailoring, system security plan authoring, and Risk Management Framework support through assessment, POA&M, and the authorization package. Built by someone who has held a clearance and worked inside the standard, not only advised on it.
Compliance & Regulatory
Regulatory programs end to end: gap analysis, SSP and POA&M generation, evidence collection, and audit preparation. Regulation S-P and SEC cybersecurity readiness for registered advisers, SOC 2 readiness, NIST 800-171 and 800-171A with SPRS scoring, and CMMC, currently including a full CMMC program for a Fortune 500 infrastructure technology company.
Security Training
Custom security awareness programs and phishing simulations designed to change behavior, not check a box. Role-based content and security culture assessment for teams that handle sensitive work.