You probably need this if…
Most companies don't need a full-time CISO yet. They need someone who's done the job to guide the plan and help answer the hard questions.
A customer sent a security questionnaire
And nobody owns the answers — or the gaps they expose.
An audit or insurance renewal is coming
You need a credible program and evidence, not a last-minute scramble.
You run plants or industrial systems
OT/ICS risk looks different from IT risk, and your plan should too.
Your teams are adopting AI fast
You need governance and guardrails before sensitive data walks out the door.
Real risk first. Everything else second.
A security program shouldn't be a checklist you bought. It should be built around what could actually hurt your business, and change as your business does.
Assess
Map your environment, your data, and the threats that realistically apply — IT, cloud, OT, and the people in between.
Prioritize
Rank the fixes by risk reduced per dollar and hour spent, and turn them into a roadmap your team can execute.
Adjust
Reassess as conditions change — new customers, new tools, new threats — and report progress in plain language.
It's the same assess-prioritize-adjust discipline I bring to every engagement — applied to your business, not a template.
What I help your team own
I guide; your people own the program. The goal is a team that understands the why behind every control.
vCISO strategy & guidance
Guide your security strategy, policies, and roadmap. Your team owns the program; I help them build it right and keep it on course.
Security program assessment
A clear-eyed look at where you stand today, from a focused baseline to a full NIST CSF assessment, with a prioritized plan for what comes next.
Incident response & readiness
Guidance through a live incident and your next steps to remediate, plus plans, playbooks, and tabletop exercises so you're ready before one hits.
OT/ICS security
Practical guidance for protecting industrial and manufacturing environments without stopping production.
AI security governance
Help shaping AI acceptable-use policy, data controls, and risk review. Your team adopts and enforces them.
SOC & tooling review
Advice on getting more from the SIEM, SOAR, EDR, and DLP you already pay for, or choosing the right ones.
Board & executive reporting
Guidance on presenting security risk in business terms leadership can act on.
Customer & audit support
I walk your team through questionnaires and audits and teach the reasoning behind each answer, so you can own it next time.
Ways to work together
Every engagement starts with a free 30-minute conversation.
- ~10 hours / month
- Security strategy & roadmap guidance
- Policy guidance
- Monthly check-in call
- ~20 hours / month
- Everything in Essentials
- Vendor & customer security review guidance
- Quarterly executive reporting support
- Annual tabletop exercise
- ~32 hours / month
- Everything in Standard
- Compliance or OT/ICS program guidance
- Board reporting preparation
Scored against a focused set of high-impact IT and OT practices, with gaps ranked and a 90-day action plan. Best for small and mid-sized businesses and manufacturers getting started.
Start with a baselineFull current- and target-state profiles across all six CSF functions, rated risks, and a 12-month roadmap with a leadership readout. Best for regulated, audited, or board-reporting organizations.
Scope a NIST assessmentA senior second opinion for a decision, architecture review, or board presentation. Or pre-buy a 10-hour block for $3,000.
Book advisory timeGuidance through containment, coordination, and your next steps to remediate during a live incident. Business hours, with best-effort support after hours.
Get incident helpRetainers: 3-month minimum, billed monthly in advance · Hours beyond your tier: $325/hr
Assessments: 50% to start, 50% on delivery · Fee credited, up to one month's retainer, toward a retainer signed within 30 days
On-site visits available · Travel billed at cost with prior approval
I've sat in the chair you're trying to fill.
I'm a CISSP-certified security leader with more than a decade across SOC operations, security architecture, incident response, and OT/ICS environments.
I've also sat on the buying side. As a security manager, I brought in an outside firm to run a NIST risk assessment and get the program back on course, and chose a partner whose bid came in $20,000 under the competition. I know what a good engagement looks like from your chair.
I've led security at the director and manager level, built programs around SIEM, SOAR, EDR, and DLP platforms, and helped shape AI governance policy.
I'm also a professional speaker and a charter member of my Toastmasters club, which matters more than it sounds: a security program only works if the board, the plant floor, and the help desk all understand why it exists.
Outside of security, I coach ultrarunners with the same risk-first approach at jcady.org.
- Based in
- Goodyear, Arizona
- Works
- Remotely, with on-site visits available
- Also
- Professional speaker · Toastmasters charter member