Services & Expertise

"The impediment to action advances action. What stands in the way becomes the way."

— Marcus Aurelius, Meditations, Book 5

Cyber Stoics is a small practice by design. What follows is who you will actually be working with, the environments we know best, the tooling we built when nothing off the shelf would do, and the full range of services we offer.

Who You'll Be Working With

Eric Smith, founder of Cyber Stoics

Eric Smith is the founder of Cyber Stoics and personally leads all engagements.

Eric's passion for technology was ignited when he received a Texas Instruments home computer from his parents for Christmas in 1985. Since then, he's never been very far from a keyboard. His professional career began in the early '90s and has progressed through several organizations and various technical and operational roles, ranging from helpdesk and user support to network engineering and information security. Throughout his 30+ years of professional experience, Eric has accumulated numerous industry certifications, including Certified Information Security Professional (CISSP), RedHat Linux Certified Engineer, Microsoft Certified System Engineer, and Salesforce Certified Developer, among others.

Outside of work, Eric enjoys spending time with his two college-age kids and his millions of honeybees. Eric is an Eastern Apicultural Society (EAS) Certified Master Beekeeper and president of the Beekeepers of the Susquehanna Valley.

Healthcare

We work with regional health systems on comprehensive reviews of all three sides of a security program — people, process, and technology. Often the organization already has a capable internal IT and security team, and what they actually need is independent external validation: a second set of eyes with no stake in the decisions that got them where they are.

The findings that matter most tend to be the quiet ones. Any organization that has run Active Directory since the late '90s is carrying two decades of legacy configuration, and those leftovers add up to privilege escalation paths that a threat actor can walk once they have any foothold at all. Surfacing those buried attack paths is consistently where we deliver the most value.

Healthcare also raises the stakes on how an assessment is conducted, not just what it finds. HIPAA-protected health, treatment, and payment data cannot leave the facility — which is the constraint that led us to build the Enclave described below.

We write our reports to be read by two audiences at once: understandable by business leaders and the board, but specific enough to be useful to the security engineers and network administrators who have to act on them. Several healthcare clients have gone on to retain us as Virtual CISO — helping stand up information security committees, navigating overlapping contractual and regulatory obligations, and filling technical skills gaps so security projects don't stall waiting on a hire.

Purpose-Built Tooling: The Cyber Stoics Enclave

The Cyber Stoics Enclave, a portable assessment device

Remote assessments have a quiet accuracy problem. Traditional VPN access introduces packet filtering, NAT, and other controls that sit between the assessor and the environment — quietly concealing the very vulnerabilities the assessment is meant to surface.

So we built our own answer. An enclave is a protected space with its own boundary, and that is exactly what this device creates. The Cyber Stoics Enclave is a portable, self-contained system that ships to the client site and gives our team the same quality of access we would have standing in the server room — without opening a path back out.

That boundary is the point. All analysis happens on the device itself, so protected health information and other regulated data never leave the client's facility. For organizations bound by HIPAA and similar obligations, this turns a difficult conversation about remote access into a straightforward one.

Each unit is fully encrypted with separate boot and data drives. At the end of an engagement we remotely wipe the data drives and issue a certificate of destruction — or hand the client the wipe procedure to run in-house when their policy requires it.

Our Services

  • Vulnerability Assessments

    We use the same tools, techniques, and procedures as real-world threat actors to identify vulnerabilities in your technical environment.

  • Security Architecture and Design

    The best way to build a secure system is to design it to be secure from day one. We can help you to incorporate secure design principles into any upcoming deployments.

  • Incident Response

    Does everyone know what to do in the event of a cybersecurity incident? We'll help your team design, test, and deploy a robust incident response plan.

  • Risk Management

    We apply a risk management philosophy to our work with clients. A vulnerability rating score is meaningless if not considered in your organization's unique context.

  • Virtual CISO Services

    Need a part time Chief Information Security Officer to help build, guide, or advise your security team? We can help.

  • Security Analytics and Threat Intelligence

    Want to know if the security of a product or service is up to your standards? We regularly perform independent evaluations against cloud and software providers to identify gaps between their offerings and your policy requirements.

  • Secure Cloud Computing

    Using services like Google, M365, AWS, Azure, or Salesforce? Security of your data in these platforms is still largely your responsibility. We can help.

  • Security Awareness and Training

    Do your users know what to do when they encounter a cyber security threat? Do they know how to identify one? We'll help you to build an effective training program that isn't seen as an annual chore by your staff.

  • Continuous Monitoring

    While prevention of threats is important, detection is critical. We'll help you to find a continuous monitoring solution that fits your needs. We are not a solutions reseller and will work with you to find the best product or solution for your organization.

  • Compliance and Regulatory Knowledge

    Many of our clients are inundated with questionnaires asking about their PCI, HIPAA, or SOX compliance, or are being asked detailed cybersecurity questions by auditors or insurance. We don't believe in checkbox compliance, rather we'll help you build an information security governance program that makes compliance obligations a breeze.