Financial services
FFIEC, PCI DSS, SOC 2 — banks, fintech, insurers, advisors.
Regulated, high-stakes, and adversary-facing. These are the sectors where manual testing and governance depth actually move the needle.
We work with organizations where a bad security outcome is a regulatory event, a contract loss, or a patient-safety incident. That shapes how we write the report.
FFIEC, PCI DSS, SOC 2 — banks, fintech, insurers, advisors.
HIPAA, HITECH — hospitals, clinics, payors, health-tech platforms.
Client confidentiality, privilege, matter-level data controls.
CJIS, FERPA — state, municipal, higher-ed, K-12 districts.
IT/OT segmentation, CIS for ICS, Purdue model realities.
SOC 2 Type II, bespoke threat models, customer-facing reports.
NERC CIP, operational technology, vendor risk at the edge.
PCI DSS 4.0, in-store network segmentation, franchise risk.
A 30-minute scoping call is how most engagements start. No sales theater — you talk to the senior operator who would actually run the work.