Cyber Risk Assessment
A posture review aligned to NIST CSF or ISO 27001. Written report, prioritized risk register, and a remediation plan keyed to your budget and headcount.
See engagementInformation Security & Compliance Consulting
Cybersecurity Group, LLC designs and operates the security programs growing companies need but rarely have the in-house bench to run. Risk assessments, compliance readiness, virtual CISO leadership, and incident response, scoped in writing and delivered by senior practitioners. Headquartered in Orlando, serving businesses from 25 to 1,000+ employees across Florida and nationwide.
Each engagement is scoped to a one-page statement of work before any meter starts. Senior consultants only. No offshore handoff on assessment or compliance work.
A posture review aligned to NIST CSF or ISO 27001. Written report, prioritized risk register, and a remediation plan keyed to your budget and headcount.
See engagementSOC 2, HIPAA, PCI DSS, CMMC, and NIST 800-171. Gap analysis, policy authoring, evidence runbook, and direct audit support.
See engagementSenior security leadership on a monthly retainer. Strategy, board reporting, vendor reviews, architecture sign-off, customer questionnaires.
See engagementSame-day retainer for ransomware, business email compromise, and data loss events. Containment through post-incident hardening.
See engagementExternal, internal, and web application testing to PTES and OWASP. Manual verification, an attack narrative, and a free retest of High and Critical findings.
See engagementThe controls that decide a ransomware outcome: tested backups, identity hardening, segmentation, and a rehearsed response runbook.
See engagementMicrosoft 365 and Google Workspace hardened to the CIS Benchmarks: identity, conditional access, email security, sharing, and DLP.
See engagementA senior practitioner by the hour for the work between the named engagements: architecture reviews, vendor selection, tabletops, and AI governance.
See consulting
Cybersecurity Group, LLC serves mid-market businesses across Florida, the Southeast, and remote engagements nationwide. Our consultants hold CISSP, CGRC, and CISA credentials and come from federal cyber operations, enterprise security engineering, and Big Four audit backgrounds.
Every engagement is scoped, priced, and delivered in writing. When the work is done, the artifacts (policies, runbooks, risk registers, network diagrams) transfer to the client as editable source files. No platform dependency.
Not every problem fits a four-week SOC 2 sprint or a twelve-month vCISO retainer. Some questions are smaller. Some are bigger. Some are urgent and need a senior practitioner in the room for an afternoon. We engage on those, too.
Hourly and project-based consulting for the work that sits between the named services. Architecture review before a launch. A second opinion on a vendor proposal. A tabletop scripted around your board's actual risk concerns. A program design for a business unit that is starting from zero.
Tell us what you are working on. We learn the business and the pressure behind the question. If we are not the right firm, we say so on the call and point you toward one that is.
A one-page statement of work names the deliverables, the timeline, and the cost before any meter starts. Scope changes go in writing first.
Senior consultants do the work, and you watch it move stage by stage in the client portal. When something calls for a specialty outside our practice (a C3PAO, a breach attorney), we flag it and refer.
Policies, runbooks, reports, and diagrams ship as source files in standard formats. Word, Markdown, draw.io, Visio. If you ever change firms, the work travels with you.
Every engagement runs in a private portal the firm built and operates. Track each project as it moves through its stages, see findings with owners and due dates, sign documents, review parsed scan results, and message your engagement lead directly. One login, included with every engagement.
Searching for a cybersecurity or IT security firm near you in Central Florida? We are headquartered in Orlando: on-site work across the metro is included in the engagement price, and remote engagements run nationwide.
Practical writing on programs, frameworks, and incidents. No vendor placements. No content marketing.
What Type I requires, what evidence you need before the audit window opens, and how to run the engagement without hiring a full-time compliance manager.
Read articleThe economics that drove attackers downmarket, the attack patterns now dominant against 20 to 200 person businesses, and the controls that move the needle.
Read articleA practical Zero Trust reference for mid-market networks. What the principle means, which NIST 800-207 components matter, and what to ignore.
Read articleA thirty-minute call to understand your business and the pressure behind the question. If we are not the right firm, we will say so on the call and point you toward a firm that is.