$ cat services.md

Fractional Security Advisory & IT Infrastructure Consulting

I help small and mid-sized organizations — law firms, medical & dental practices, nonprofits, and small financial firms — get enterprise-grade security without hiring a full in-house security team. From a one-time infrastructure audit to ongoing advisory, I bring the same hands-on network and endpoint security experience I apply daily supporting 150+ client environments.

01offerings

IT Security Assessment

One-time infrastructure audit

A comprehensive review of your network, endpoints, and cloud environment to uncover vulnerabilities before attackers do.

  • Network architecture & firewall configuration review
  • Vulnerability scan across servers, endpoints, and cloud assets
  • Endpoint security posture audit (patching, EDR, encryption)
  • Policy & compliance gap analysis
  • Prioritized remediation roadmap with a scored report

Fractional Security Advisory

vCISO-style guidance, without the full-time hire

A monthly retainer for organizations that need CISO-level security thinking but aren't ready for — or don't need — a full-time hire.

  • Security policy development & review
  • Incident response planning
  • Vendor & third-party risk review
  • Leadership-level security reporting
  • Ongoing advisory access

Compliance Readiness

HIPAA · PCI-DSS · SOC 2 · GDPR

Understand exactly where you stand against the framework that matters to your business, with a clear path to close the gaps.

  • Framework-specific gap analysis
  • Documentation & policy templates
  • Remediation checklist with priority ranking
  • Audit preparation support

Cloud & M365/Azure Hardening

Lock down your cloud tenant

A focused review of identity, access, and backup/DR posture across Microsoft 365 and Azure environments.

  • MFA & conditional access policy review
  • M365/Exchange tenant security configuration
  • Backup & disaster recovery posture check
  • Identity & access management review

Security Awareness Training

Your people are the first line of defense

Phishing simulations and staff training to reduce your organization's largest attack surface — human error.

  • Simulated phishing campaigns
  • Staff training sessions
  • Organizational risk trend reporting

Incident Response Retainer

A direct line when something goes wrong

A pre-arranged response contact with defined response times, so you're not searching for help during an active incident.

  • Defined response SLA
  • Incident triage & containment guidance
  • Post-incident report & lessons learned

02testimonials

$ cat testimonials.md

No client testimonials yet — this section fills in as engagements wrap up.

Worked with me? Share your feedback and I'll ask permission before publishing anything.

03contact

$ echo $NEXT_STEP

Let's talk about your security posture

Reach out with a bit about your organization and what prompted the inquiry — I'll follow up to set up a call.