About Soteric Cyber
An independent advisory and assessment practice, working with a small number of clients at a time. The range runs from the boardroom to the disassembler.
The idea
A lot of companies are too big to ignore security and too small to justify a full-time executive to own it. What they usually get instead is a compliance platform, a tool vendor, or a large consultancy. What tends to work is someone senior who understands the business, has run programs at scale, and sits beside the people holding the budget.
How I work
- Vendor neutral. No resale agreements, no commissions, nothing to sell you.
- Plain language. A position an executive can act on and an engineer can respect.
- Risk-ranked. You get an order, a cost, and the reasoning.
- Honest scoping. If you don't need the engagement, I'll say so.
One advisor
The person you meet on the first call is the person advising you.
Founder & Principal Advisor
Soteric Cyber LLC
Twenty-six years across program management, engineering, and cybersecurity, holding the CISSP. Enough engineering background to know when a plan is fantasy, and enough program experience to know what it takes to land one.
The technical grounding underneath that: intrusion detection and incident response, reverse engineering, penetration testing, and threat intelligence work against APT-class adversaries.
Most organizations have never inventoried what their browser extensions can read. I built and published a tool for checking them.
Only a few engagements run at once, so there is no queue behind a larger account.
If it sounds like a fit, see what engagements involve.