HomeServices
Security first. Everything else follows from it.
Four practice areas, one engineer accountable for all of them. Compliance work leads because that's what brings regulated organizations to the table. The rest exists to keep them compliant after the auditor leaves.
Security & Compliance
Audit and examination remediation. You have a findings letter. I turn it into a closed one. Each finding gets mapped to the underlying infrastructure gap, remediated, and documented with the evidence your examiner expects at the follow-up: configurations, logs, screenshots, and change records.
Security assessments with verified findings. No questionnaire-driven reports. Assessments pull directly from your firewalls, switches, servers, and identity systems, so every finding is backed by actual device output. Findings are collected over VIRP, a cryptographically verified protocol I authored as an IETF draft — which means the evidence chain itself is defensible.
Framework implementation. CMMC 2.0 Level 2 and the 110 controls of NIST 800-171. GLBA safeguards for financial institutions. HIPAA Security Rule infrastructure. I implement the technical controls — segmentation, encryption, MFA, logging, backup — and produce the System Security Plan and POA&M artifacts to match.
OT and control-system security. Segmentation and secure remote access for water utilities and industrial environments, built on Fortinet's OT security line. IT/OT boundary design that operators can actually live with.
Fractional CTO & Strategic Advisory
Some clients need more than a project. They need someone accountable for technology at the executive level: answering the board's risk questions, standing behind the exam response, negotiating with vendors who sense a soft target.
A fractional CTO retainer gives you that person for a fraction of a full-time executive hire. The scope is set to your situation, but typically covers:
- Technology and security roadmaps with real budgets attached
- Examination and audit readiness, year-round instead of the panic quarter
- Vendor and MSP oversight — I read the contracts and the configs
- Board and committee reporting in plain language
- Incident leadership when something goes wrong
This is a working role, not a slide-deck role. I stay hands-on in the infrastructure, which is why the advice holds up.
Managed Infrastructure
Compliance decays. Firmware ages, rules drift, backups silently fail, and the posture you paid for erodes until the next audit finds it. Managed infrastructure keeps the environment in the state the framework requires.
- 24/7 infrastructure monitoring with automated alert correlation
- Security monitoring through Wazuh SIEM, with retention set to your framework's requirements
- Proactive patching for firewalls, switches, hypervisors, and servers
- Backup and recovery verification — tested restores, not green dashboards
- Incident response by the engineer who built the network
- Quarterly reporting written for your board and your examiner
This is infrastructure operations, not an end-user help desk. If you need password resets at scale, I'm not your vendor — and I'll say so up front.
Private Cloud Hosting
Some workloads shouldn't share hardware with strangers. I run dedicated infrastructure at the 123NET colocation facility in Southfield, Michigan — built for CMMC enclaves, regulated financial workloads, and organizations that want to know exactly where their data lives and who can touch it.
- Facility123NET Southfield — Tier III data center, 20 minutes from most of Metro Detroit
- ComputeDedicated Dell PowerEdge servers on Proxmox virtualization — your workloads, your hardware
- NetworkIsolated segments behind FortiGate next-generation firewalls, Cisco Catalyst switching
- AccessEncrypted site-to-site and client VPN, MFA enforced, privileged access logged
- ComplianceArchitected for CMMC and HIPAA workloads; evidence and diagrams provided for your assessor
- ContinuityReplication and disaster recovery options with tested restore procedures
Not sure which of these you need?
Most engagements start with an assessment. Tell me what prompted the call — a finding, a contract clause, a bad feeling — and I'll tell you where to start.