
Cyber Stoics provides world-class Virtual CISO and Ethical Hacker services to clients across the globe.
Learn how we're different. Schedule a no-cost one-hour consultation today.
Who We Work With
Every environment is different. These are a few of the sectors where we spend most of our time.

NGOs & Humanitarian Organizations
Organizations operating in conflict zones face adversaries most businesses never will — including well-resourced nation state actors targeting frontline staff. We have assessed infrastructure across multiple international offices and helped boards understand, prioritize, and close the gaps that put their people at risk.

Healthcare
Protected health information raises the stakes on every assessment. We work with regional health systems on comprehensive reviews of people, process, and technology — surfacing hidden attack paths in legacy Active Directory environments while ensuring PHI never leaves the client's facility.

Higher Education
A university is a dozen industries under one budget: a bank, a hotel, an ISP, a police force, a stadium, a school. Our founder served as higher ed's first Shared CISO across a consortium of institutions, and we bring that operational fluency to every campus engagement.
Our Services
Vulnerability Assessments
We use the same tools, techniques, and procedures as real-world threat actors to identify vulnerabilities in your technical environment.
Security Architecture and Design
The best way to build a secure system is to design it to be secure from day one. We can help you to incorporate secure design principles into any upcoming deployments.
Incident Response
Does everyone know what to do in the event of a cybersecurity incident? We'll help your team design, test, and deploy a robust incident response plan.
Risk Management
We apply a risk management philosophy to our work with clients. A vulnerability rating score is meaningless if not considered in your organization's unique context.
Virtual CISO Services
Need a part time Chief Information Security Officer to help build, guide, or advise your security team? We can help.
Security Analytics and Threat Intelligence
Want to know if the security of a product or service is up to your standards? We regularly perform independent evaluations against cloud and software providers to identify gaps between their offerings and your policy requirements.
Secure Cloud Computing
Using services like Google, M365, AWS, Azure, or Salesforce? Security of your data in these platforms is still largely your responsibility. We can help.
Security Awareness and Training
Do your users know what to do when they encounter a cyber security threat? Do they know how to identify one? We'll help you to build an effective training program that isn't seen as an annual chore by your staff.
Continuous Monitoring
While prevention of threats is important, detection is critical. We'll help you to find a continuous monitoring solution that fits your needs. We are not a solutions reseller and will work with you to find the best product or solution for your organization.
Compliance and Regulatory Knowledge
Many of our clients are inundated with questionnaires asking about their PCI, HIPAA, or SOX compliance, or are being asked detailed cybersecurity questions by auditors or insurance. We don't believe in checkbox compliance, rather we'll help you build an information security governance program that makes compliance obligations a breeze.