Contact
Cybersecurity Consulting

Find the gaps. Close them for good.

Most small businesses don't need a security executive, and they don't need another binder of recommendations. They need the gaps found and closed before a phishing email or a reused password turns into a very expensive week. I find where you're actually exposed and I fix it: controls put in place and proven working, the routine parts automated, and your people trained on the rest.

  • Hands-on implementation
  • Bank-grade standards
  • Fixed-price packages
  • Vendor-neutral advice
What I do

Practical security, built and implemented

I work across the whole security stack: assessing where you stand, implementing the controls that matter, and making them stick with automation, guides, and training. Vendor-neutral, and focused on outcomes you can see, not a binder that sits on a shelf.

01

Assessments & gap analysis

A clear-eyed review of where you actually stand against NIST CSF and CIS Controls. I surface the real gaps, rank them by risk, and give you a prioritized, budget-aware plan to close them, written in plain English you can hand to your insurer, your bank, or your biggest customer.

02

Control implementation & automation

The part most consultants leave to you. I stand up and configure the controls that matter, from MFA and logging to backups and endpoint and email defenses, automated wherever it can be so protection runs without adding to your team's workload.

03

Security architecture reviews

Building something in-house or weighing a third-party solution? I review or design the architecture with you, vendor-neutral, so you invest in what fits and integrate it securely instead of bolting on risk.

04

Identity & access management

Who can reach what, and how it's protected. Single sign-on, multi-factor, least-privilege access, and clean joiner, mover, and leaver processes so the right people get in and no one else does.

05

Vulnerability & application security

I set up scanning that finds the weak points in your systems before attackers do. If your team builds software, I add automated checks that review your code for security flaws before they ship (the industry calls this SAST). Either way, you get a short list of what matters, in order, and help fixing it.

06

Policies, governance & vendor risk

Practical policies people actually follow, sensible governance sized to your business, and a real handle on the vendors and third parties who touch your data.

From the founder's career

Systems like these, already built

Client names stay confidential, but the work is real. Two examples of security systems Michael designed and shipped inside global financial institutions, the same disciplines this page offers you.

Identity & access management

Segregation-of-duties scanner for a large organization

Every employee transfer was automatically screened for high-risk access combinations, like an operations employee moving to a trading desk, or a technology worker with elevated system access moving into operations, so permissions were reviewed before they became a finding.

Architecture review

Enterprise Salesforce integration security review

A full integration risk review for one of the world's largest financial enterprises: API endpoints, data classification, entitlements, revocation, encryption, and architecture, working directly with the vendor until every risk was documented and formally dispositioned.

Fixed-scope packages

Four jobs with a clear scope and a price up front

Not every security problem needs an open-ended engagement. These four are the ones small businesses ask about most, and each has a defined scope, a fixed price, and a deliverable you can hand to an insurer, an auditor, or your own peace of mind.

Cyber-Insurance Readiness

Pass your cyber-insurance renewal the first time

Carriers now require enforced MFA, endpoint detection, tested backups, a written incident plan, and awareness training. Miss one and the risk is not a higher premium, it is a denied claim.

  • Line-by-line review of your carrier's questionnaire against what is actually in place
  • The gaps closed: MFA everywhere, endpoint protection, tested backups, incident plan, training
  • An evidence pack your broker can send to the underwriter
  • Renewal support each year, so the answers stay true
Get insurance-ready
Microsoft 365 & Google Workspace Hardening

Your email is running on defaults. Fix that in two days.

Business email compromise is the most expensive attack a small business faces, and most tenants still run the settings the vendor shipped. This is the baseline that stops it.

  • MFA enforced for everyone, conditional access, legacy sign-in switched off
  • DMARC, SPF, and DKIM aligned so your domain cannot be spoofed
  • Forwarding rules, app permissions, and admin roles reviewed and locked down
  • Audit logging on and a backup of the tenant itself, then a plain-English report
Harden my tenant
Compliance Readiness

HIPAA, PCI DSS, NY SHIELD: ready, without the consultant binder

Medical and dental practices, firms that hold client data, and any business taking card payments online all have obligations. Most owners know that and dread it. This turns dread into a checklist.

  • A gap assessment in plain English against the framework that applies to you
  • The written policies you are required to have, drafted for your business, not templated
  • A prioritized fix list that respects your budget and your calendar
  • The documentation an auditor, an insurer, or a big customer will ask for
Start the gap assessment
Backup & Recovery Assurance

Backups you have actually tested

Ransomware turns into a bad week or a closed business depending on one thing: whether the backup restores. Most small businesses have never checked. We check, and keep checking.

  • Backups designed the way insurers now expect: offsite, immutable, and covering the cloud too
  • A restore drill each quarter, timed and documented
  • Recovery steps written down so anyone can follow them under pressure
  • The evidence your insurer accepts, refreshed at every renewal
Test my backups
How I work

Engagements that fit the problem

The assessment is the right starting point for almost every business: it tells you exactly what you need before you spend anything on fixes. Implementation and advisory build on what it finds. And when an engagement calls for extra capacity, I draw on a trusted network of local cybersecurity professionals, while staying accountable for every deliverable myself.

Assessment & roadmap

Defined scope, defined outcome

  • Security posture assessment
  • Gap analysis vs NIST CSF & CIS Controls
  • Prioritized, budget-aware roadmap
  • Clear findings in plain English
  • Zero disruption: I look, I don't touch, until you approve the plan

Ongoing advisory

A security expert on call

  • On-call guidance for security decisions
  • Architecture and vendor reviews
  • Periodic posture check-ins
  • Cyber-insurance application support

Not sure which engagement fits? Ask in a free consultation.

Proof, not promises

Inspect our armor

This very page ships hardened. The panel below fetches this page's own response headers in your browser, right now, and translates them. Nothing is hardcoded: if a header stopped shipping, its row would vanish.

Or ask a referee we don't control:

Every link points their scanner at this site. We don't get to edit the result.

Not sure where your security actually stands?

Start with an assessment. In a couple of weeks you'll have a clear picture of where you're exposed, what to fix first, and a plan to close the gaps. No jargon, no scare tactics. And if a cyber insurance renewal or a customer security questionnaire sent you here, bring it: those forms are exactly what an assessment is built to answer.

Get Your Gap Assessment

Prefer to talk to a person first? Call us