Skip to content

Governance · Risk · Compliance

Know your risk. Prove your controls.

CyberIO builds security governance that holds up. To auditors, to clients, and to regulators.

What I do

Two things I do best.

Governance, Risk & Compliance

You need policies people actually follow. You also need evidence you can hand an auditor.

  • Policy and standards authoring
  • Risk register design and upkeep
  • Control mapping to NIST CSF, ISO 27001, SOC 2 and HIPAA
  • Audit preparation and evidence collection
  • Security awareness program design

Assessments & Advisory

Find out where you stand before a customer or an attacker tells you first.

  • Security posture assessment
  • Gap analysis against the framework you're held to
  • Third-party and vendor risk review
  • Tabletop exercises for your team
  • A remediation roadmap ranked by real risk

Security Architecture & Design

Design it right the first time. Or fix what's already running in production.

vCISO / Fractional CISO

You get security leadership without paying for a full-time hire.

See what each engagement includes →

Coming soon

NetGuardian

Scam texts and shady sites, blocked before your parents see them.

We're building an iPhone app that filters scam texts and blocks malicious websites. It runs on the device. We don't track anyone.

Let's talk about where you stand.

Tell me what you're working on. I'll tell you honestly whether I can help.