Security Leadership & Program
Someone senior who owns the outcome.
Virtual CISOAdvisory CIOSecurity program development
Multi-year roadmap & budget planningBoard & cabinet reporting
Interim coverage during a vacancySecurity tool rationalization
M&A and investment cyber diligencePost-close portfolio remediation
Security staffing advisory
Governance, Risk & Compliance
Written down, current, followed, and defensible.
Cyber risk assessmentRisk quantificationFramework gap assessment
Policy & standards developmentAudit preparation & evidence
Third-party risk managementSupply chain risk
Cyber insurance readinessBusiness impact analysis
Continuity & disaster recovery planningRecords retention & data minimization
Regulatory reporting readiness
Somebody watching while you sleep, and a plan for the bad day.
24/7 SOC monitoringManaged detection & response (MDR)
Endpoint detection & response (EDR / XDR)Identity threat detection (ITDR)
SIEM & log managementThreat huntingThreat intelligence
Incident response retainerDigital forensics
Ransomware containment & recoveryBreach notification support
Post-incident review
Every laptop, phone, and Chromebook you're responsible for.
Endpoint protection deploymentMobile device management
Patch & vulnerability managementHardening baselines
1:1 device fleet managementSecure enterprise browser
Removable media controlSecure disposal & data sanitization
Who can reach what, and how you'd know if that changed.
Single sign-on & federationMulti-factor authentication rollout
Conditional access designPrivileged access management
Identity governance & administrationIdentity security posture management
Machine & non-human identityJoiner / mover / leaver automation
Dark web credential monitoringSecrets management
The plumbing, including the parts nobody has looked at in five years.
Next-generation & AI-assisted firewallsFirewall management & tuning
Network segmentation & microsegmentationZero trust architecture
Secure access service edge (SASE / SSE)DNS & web content filtering
Network access controlIntrusion detection & prevention
Wired & wireless infrastructure auditRemote access & VPN
OT, IoT & building systemsCamera & access control security
Cloud, SaaS & Application
Where the work actually happens now.
Microsoft 365 hardeningGoogle Workspace hardening
Cloud security posture managementCloud-native application protection
SaaS security posture managementShadow IT discovery
Application security posture managementSecure configuration baselines
API security reviewContainer & Kubernetes security
Cloud entitlement management
Data Protection & Resilience
Getting back on your feet, and keeping data where it belongs.
Backup design & immutabilityRestore testing
Disaster recovery engineeringData loss prevention
Data security posture managementData discovery & classification
Encryption at rest & in transitEmail security & anti-phishing
Secure file transferPost-quantum readiness assessment
Offensive Security & Exposure
Finding your gaps before somebody less friendly does.
External & internal penetration testingWeb & mobile application testing
Wireless penetration testingSocial engineering assessment
Physical security assessmentRed team & purple team exercises
Vulnerability assessment & scanningExternal attack surface management
Continuous threat exposure managementAdversarial exposure validation
The fastest-moving risk on this page, and the one most organizations haven't touched.
AI runtime defense (AI gateway + guardrails)Prompt injection & jailbreak mitigation
AI acceptable use policyAI governance program build
NIST AI RMF & ISO/IEC 42001 alignmentShadow AI discovery
AI security posture managementAI data loss prevention
Copilot & Gemini tenant oversharing remediationAI access control & least privilege
Agentic AI governanceAI agent identity & credentials
MCP server security reviewAI browser & extension risk
AI red teaming & adversarial testingModel scanning & provenance
AI-BOM / ML-BOMAI supply chain security
Deepfake & voice-clone process defensesAI vendor & feature risk review
AI incident response & tabletopsAI literacy & staff training
AI-assisted detection & triageAssessment redesign for academic integrity
Your people will be the target long before your firewall is.
Security awareness trainingPhishing simulation
Role-based training for finance, HR & executivesAI & deepfake awareness
Tabletop exercisesExecutive & board briefings
Onboarding & offboarding securityHuman risk management program
The work general providers don't do, because it only exists in schools.
Student data privacy agreements & DPA registryEd-tech app vetting workflow
COPPA compliance programCIPA filtering & certification records
Student safety & self-harm alert monitoringFERPA program review
HECVAT 4 completion & inbound triageGLBA & Safeguards for financial aid
Research data security & CUI enclavesE-Rate & FCC Pilot support
MS-ISAC transition advisoryBoard reporting written for public record