About
What is Cybersecurity Consulting?
The consulting practice of Capital Cyber. It gives defense contractors and federal programs CISO level leadership for CMMC, NIST SP 800-171, federal authorization and the protection of ITAR technical data, without a full time hire.
Who does the practice serve?
Small and mid sized defense contractors and federal integrators that handle Controlled Unclassified Information or export controlled technical data, and federal programs that need RMF, enterprise audit or insider threat leadership.
How do engagements run?
- Every engagement starts with a call and a written scope that names the deliverables and who does what.
- Each engagement has one accountable lead who briefs your leadership as the work moves.
- The Capital Cyber team carries out the assessment, documentation and evidence work, and coordinates with your MSP or MSSP on implementation.
- Decisions and accepted risks are recorded in writing, so your leadership can see what was decided and why.
Capital Cyber is not an Authorized C3PAO. No consultant can promise the outcome of an assessment or authorization.
Which engagements are offered?
- CMMC Level 2 program leadership
- SSP and POA&M review and assessor readiness
- CUI enclave design
- C3PAO readiness and mock assessment
- vCISO and security program leadership
- RMF, ATO and continuous authorization
- Insider threat and enterprise audit
- Incident response and tabletop exercises
- ITAR cybersecurity program
Which frameworks does the practice cover?
CMMC (32 CFR Part 170)NIST SP 800-171 Rev 2NIST SP 800-171ANIST SP 800-53 and 53ARMF and SP 800-37SP 800-30 and SP 800-39SP 800-61CNSS 1253FISMADFARS 252.204-7012, 7019, 7021 and 7025SSP, POA&M, ATO and A&AMicrosoft GCC High and AzureITAR technical dataInsider threat and user activity monitoringEnterprise audit and logging
Ready to talk it through?
BOOK A CALLPick a time for a 30 minute call with the practice.
What happens in 30 minutes
- We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
- We talk through where you stand and which engagement fits, if any does.
- If there is a fit, we follow up with a written scope. No slides.