Information Security & Compliance Consulting

Enterprise-grade cybersecurity, scaled for the mid-market.

Cybersecurity Group, LLC designs and operates the security programs growing companies need but rarely have the in-house bench to run. Risk assessments, compliance readiness, virtual CISO leadership, and incident response, scoped in writing and delivered by senior practitioners. Headquartered in Orlando, serving businesses from 25 to 1,000+ employees across Florida and nationwide.

What we do

The whole practice. One firm to call.

Each engagement is scoped to a one-page statement of work before any meter starts. Senior consultants only. No offshore handoff on assessment or compliance work.

01 / Risk

Cyber Risk Assessment

A posture review aligned to NIST CSF or ISO 27001. Written report, prioritized risk register, and a remediation plan keyed to your budget and headcount.

See engagement
02 / Compliance

Audit and Compliance Readiness

SOC 2, HIPAA, PCI DSS, CMMC, and NIST 800-171. Gap analysis, policy authoring, evidence runbook, and direct audit support.

See engagement
03 / Leadership

Virtual CISO

Senior security leadership on a monthly retainer. Strategy, board reporting, vendor reviews, architecture sign-off, customer questionnaires.

See engagement
04 / Response

Incident Response

Same-day retainer for ransomware, business email compromise, and data loss events. Containment through post-incident hardening.

See engagement
05 / Offensive

Penetration Testing

External, internal, and web application testing to PTES and OWASP. Manual verification, an attack narrative, and a free retest of High and Critical findings.

See engagement
06 / Resilience

Ransomware Readiness

The controls that decide a ransomware outcome: tested backups, identity hardening, segmentation, and a rehearsed response runbook.

See engagement
07 / Cloud

Microsoft 365 & Workspace Security

Microsoft 365 and Google Workspace hardened to the CIS Benchmarks: identity, conditional access, email security, sharing, and DLP.

See engagement
08 / Advisory

Security Consulting

A senior practitioner by the hour for the work between the named engagements: architecture reviews, vendor selection, tabletops, and AI governance.

See consulting
Senior practitioners at work on client deliverables
The firm

Senior practitioners. Plain English. Written deliverables.

Cybersecurity Group, LLC serves mid-market businesses across Florida, the Southeast, and remote engagements nationwide. Our consultants hold CISSP, CGRC, and CISA credentials and come from federal cyber operations, enterprise security engineering, and Big Four audit backgrounds.

Every engagement is scoped, priced, and delivered in writing. When the work is done, the artifacts (policies, runbooks, risk registers, network diagrams) transfer to the client as editable source files. No platform dependency.

Reviewing written findings and documentation during a consulting engagement
General cybersecurity consulting

When a defined service is not the right shape.

Not every problem fits a four-week SOC 2 sprint or a twelve-month vCISO retainer. Some questions are smaller. Some are bigger. Some are urgent and need a senior practitioner in the room for an afternoon. We engage on those, too.

Hourly and project-based consulting for the work that sits between the named services. Architecture review before a launch. A second opinion on a vendor proposal. A tabletop scripted around your board's actual risk concerns. A program design for a business unit that is starting from zero.

01 / Advisory Board readouts, second opinions, security strategy memos.
02 / Architecture Identity, network, and cloud reviews before a build or migration.
03 / Vendor selection Technical scoring for SIEM, EDR, MDM, IAM, and backup tooling.
04 / Diligence Pre-acquisition cybersecurity diligence and post-merger integration.
05 / Tabletops Ransomware, BEC, and insider-threat exercises for leadership teams.
06 / AI security NIST AI RMF, model governance, and acceptable-use policy for LLM adoption.
How we engage

From first call to handover, in writing.

01

A thirty-minute call

Tell us what you are working on. We learn the business and the pressure behind the question. If we are not the right firm, we say so on the call and point you toward one that is.

02

Scoped before it starts

A one-page statement of work names the deliverables, the timeline, and the cost before any meter starts. Scope changes go in writing first.

03

Senior delivery, tracked

Senior consultants do the work, and you watch it move stage by stage in the client portal. When something calls for a specialty outside our practice (a C3PAO, a breach attorney), we flag it and refer.

04

The files are yours

Policies, runbooks, reports, and diagrams ship as source files in standard formats. Word, Markdown, draw.io, Visio. If you ever change firms, the work travels with you.

Client portal

Watch the work move, stage by stage.

Every engagement runs in a private portal the firm built and operates. Track each project as it moves through its stages, see findings with owners and due dates, sign documents, review parsed scan results, and message your engagement lead directly. One login, included with every engagement.

The CSG client portal showing a CMMC Level 2 engagement: control progress against NIST SP 800-171, open POA&M items by control, recent messages, and a System Security Plan ready to sign.
Sample CMMC Level 2 engagement.
Where we work

Florida and remote United States.

Searching for a cybersecurity or IT security firm near you in Central Florida? We are headquartered in Orlando: on-site work across the metro is included in the engagement price, and remote engagements run nationwide.

Engage the firm

Tell us what you are working on.

A thirty-minute call to understand your business and the pressure behind the question. If we are not the right firm, we will say so on the call and point you toward a firm that is.