Information Is Everywhere. Is your data Safe?
Our services are based on industry accepted best practices and years of experience. While we can remediate and minimize your risks, there is rarely a "quick fix". Our recommendation is not to throw money or tools at a problem but to strategically outline a plan that includes, quantifies and analyzes all areas of risk.
In our experience, the companies that we have investigated or responded to, either lacked, tested or managed their IT Risk Management Plans. In many cases they had the right intentions but the necessary experience was missing. By creating a long term strategy, we help minimize and justify costs associated with you plans.
Our industry experience runs the gambit. Through our experience withfinancial institutions we have worked closely with FDIC, NCUA and NACHA. Between the various banks, credit unions, credit card companies, mortgage, processing agencies, wire transfers and ATM providers-we have experience.
In the insurance industry we have worked in many realms as well. NAIC audits, for private mortgage, auto insurance, private client and benefits.
We have extensive experience in the public accounting realm. We utilize AICPA best practices as well as the PCAOB. We work with partners (when attestation is needed) to deliver SAS 70 work, internal audit, valuation and forensic accounting. We staff augment several local CPA firms when the need for an IT specialist in their risk based approach is needed.
We have extensive expertise within legal and law enforcement, healthcare, state and local government, federal government and manufacturing.
In each of these areas we have referenced work and will disclose on an as needed basis.
Unlike many out there we do not base our experience on a "one and done" mantra. We are familiar with the needs in the above organizations and work our solutions to keep governance, regulatory and business needs as our foundation.
Our Team
Our IT Team consists of dedicated and experienced security architects and engineers, IT audit professionals and digital forensics experts who possess several of the major certifications available to IT professionals including, the Certified Public Accountant (CPA), Certified Information System Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Ethical Hacker (CEH), Licensed Penetration Tester (LPT), Microsoft Certified System Engineer (MCSE), Cisco Certified Network Associate (CCNA), Certified Novell Engineer (CNE), Certified Data Processor (CDP), Certified Internal Auditor (CIA), Certified Information System Auditor (CISA), GIAC Security Essentials Certified Professional (GSEC), Certified Information Technology Professional (CITP), Master Certified Novell Engineer (MCNE), Cisco Certified Network Engineer (CCNE), Certified HIPAA Professional (HIPAA CHP), Certified HIPAA Security Specialist (CHSS), and Certified Fraud Examiner (CFE), Information Technology Infrastructure Library (ITIL), Citrix Certified Enterprise Administrator (CCEA), and Certified Computer Examiner (CCE). Our team has also been trained and certified by vendor personnel in the use of numerous software tool and hardware technologies
Our goal is 100% based reference-able clients.
Our Core Services Include
IT Risk Management
Information Security
Digital Forensics
Regulatory and Governance
Virtual CSO
Training

Encryption is not the Holy Grail.
Encryption is very crucial to an organization. But too many times it offers a false sense of security and 9 times out of 10 its implemented incorrectly. Encryption only protects against stolen data. Its viewed as clear text when a user is logged in and depending how and where encrypted, will leave clear text fragments. Do you know the difference between VPN Tunnels? SSH and SSL? Using products like Citrix or Secure ICA? Whole Disk Encryption? What about your backups and archives? What about data in a non Microsoft world? And for users opening an encrypted document and then saving to a USB or sending via email encryption is useless. Is encryption left to a user or centrally managed? And for the really bad guys, print outs or cell phone cameras bypass 99% of your precautions. Encryption however when used in a complete strategy is bullet proof (unless you have a couple hundred years)