Manage Your Cyber Risks With Confidence

Cyber security today requires an approach that is Top Down, Risk Based, and Business Focused.

Today’s cyber security efforts require more than a technical and tactical framework. Recent SEC guidance mandates Board of Directors oversight and similar regulations will go into effect in Europe soon. Cyber Incident Response Plans (CIRPs) and Chief Information Security Officers (CISOs) must address the entire cyber security spectrum from the strategic all the way down to the tactical.

Tap our proven solutions for cyber security. Take the first step by developing CIRP and TTXs that go beyond the technical and tactical.

Intro: In April 2025, NIST updated its primary guidance for cyber incident response plans (CIRPs), Special Publication 800-61 Revision 3. In 2023, the SEC also issued guidance on board cybersecurity oversight. Together, these developments significantly affect your current CIRP and…

Quick Summary: 2,250,000 reasons why you should have both your CIRP and your IR policy at least reviewed, and most likely updated. April 2025, NIST significantly upgraded the requirements for CIRPs. CIRPs need to integrate incident response into broader cybersecurity…

A recent Board of Director (BOD) level post from Victor Font (https://www.linkedin.com/pulse/premiums-exclusions-governance-blind-spot-victor-m-font-jr--lu3ie/) which I believe was “Spot On”, got me thinking about this topic further. (I have a previous post on cyber insurance here on this website from 3-4 years…

The SEC & NIST have issued new mandates regarding cybersecurity due diligence. This impacts the way you do Tabletop Exercises (TTX). Your TTXs are going to have to conform to the new mandates: “Strategic”, “Risk Based”, and “Business Aligned” beyond…

Last April (2025) the (US) NIST updated its 800-61 series documentation to Revision 3 which established new standards for CIRPs. My previous posts regarding the NIST 800-61r3 changes focused on “The NIST [800-61] Revision 3 integrating incident response into broader…

Summary: Public companies are now required to disclose their cyber risks and their Board of Director (BOD) cybersecurity risk oversight in their Annual Reports (SEC 10-K) These Cybersecurity disclosures incur fiduciary / due diligence obligations. Should any of these efforts…

What we do

Cyber Readiness Made Simple

Most organizations require a formal cyber incident response plan (CIRP) so they can pass an audit, remain compliant with current laws and regulations, and satisfy any cybersecurity requirements outlined by their Board of Directors (BOD). Plus, the CIRP must be actionable so that your IT team can use it in the event of a cyber incident.

services

Cyber Incident Readiness Services We Offer

Cyber Incident Response Plan (CIRP) Development

A CIRP must go beyond satisfying an audit requirement. Get a one-on-one coaching experience, where we address all the various aspects of successfully navigating your unique cyber risks. The CIRP is merely an artifact of our work together.
Learn More

Tabletop Exercises (TTX)

Go beyond the tactical and technical with experienced, management-level TTXs.
Learn more

Workshops

Develop your organization's CIRP and become a better cyber security leader at a three-day workshop in one of our great locations. 15-seat max.
Learn more

Industries We Support

With 10+ years of experience writing Comprehensive Cyber Incident Response Plans (CIRP) and conducting management level Tabletop Exercises (TTXs), you can feel comfortable that we address your industry specific needs.

  • Financial Services
  • Healthcare
  • Insurance
  • Energy
  • Manufacturing
  • Technology
  • Government

Our Mission Is Simple

In this new era of Board of Director (BOD) Cyber Risk oversight, we prepare you and your team to successfully protect your organization from cyber risks. Take advantage of our Top Down, Risk Based, and Business Focused approach and elevate your InfoSec program beyond the typical “Tactical” & “Technical” mindset and ensure that you and your InfoSec program are BOD ready. We have leveraged this approach with hundreds of global clients for the past 10 years and stand ready to assist you.

About Me

Meet Neal McCarthy

Neal is an ISC2 distinguished subject-matter expert with decades of cyber security experience in the military, law enforcement, and business domains. For the past decade, he has focused on management-level CIRPs and TTXs, including Board of Directors-level involvement.

Why our approach works

Elevate Your Cyber Readiness

Lead cyber security incidents with confidence and improve your InfoSec program.