nick@jax:~$ cat services/README.md
Southern Cyber Solutions_
Operator-grade GRC for the Defense Industrial Base and commercial sector. An independent practice launching after my December 2026 graduation. Early conversations welcome now.
dib_services · cmmc & federal
ls services/dib/
cmmc-l1 · self-assessment package
Scoping, control mapping, SPRS submission support, and policy templates for Level 1 self-attestation.
cmmc-l2 · readiness & gap assessment
NIST 800-171 gap analysis, System Security Plan authoring, POA&M development, and a prioritized remediation roadmap.
cmmc-l2 · remediation & implementation
Hands-on hardening: Windows/Linux STIG implementation, MFA rollout, logging and SIEM tuning to close the gaps found.
pre-audit · c3pao mock assessment
Interview practice, evidence review, and control scoring before the real assessment team shows up.
commercial_services · saas & enterprise
ls services/commercial/
soc2 · type i & ii readiness
Gap-to-attestation: control design, continuous evidence collection via Drata or Vanta, and auditor liaison.
vciso · retainer
Executive security leadership without the executive salary: board reporting, vendor reviews, roadmap ownership.
ir · playbooks & tabletops
NIST 800-61-aligned playbooks and facilitated tabletop exercises your team will actually remember.
ai · llm red team assessment
Prompt-injection testing, adversarial fuzzing, and data-leakage analysis for teams shipping LLM features.
why_this_practice
diff us competitors
+ cleared operator
Active TS/SCI and six years inside classified DoD environments, not a checklist consultancy.
+ both sides of audit
I’ve written the packages and answered the assessors. Zero-rework documentation is the standard.
+ readiness, honestly
Readiness consulting only. Not an authorized C3PAO or assessor, and clients hear that upfront.
// built nights and weekends in Jacksonville, on the same coffee budget as the rest of this site