Security program management · Syracuse, New York
One security program.
Ready for your regulator.
Orion Secure builds and runs cybersecurity programs for New York water and wastewater systems, defense contractors, and firms regulated by the New York State Department of Financial Services (DFS). We prepare you for the examiner or assessor, then keep the program running after they leave.
30+ DFS examinations
Client examinations under NYS DFS Part 500, the state's cybersecurity regulation for financial services. None failed. No regulatory findings.
20 years
In information security, including security leadership at a hospital.
CISSP · CISM · MS
Certified Information Systems Security Professional and Certified Information Security Manager. MS, Syracuse University.
We prepare. We never assess our own work.
The examiner or assessor is always independent of us. Our job is getting you ready for them.
Services
Three regulators.
One program underneath.
Every program we build sits on the NIST Cybersecurity Framework (CSF), a public standard from the National Institute of Standards and Technology. Water, defense, and DFS requirements all map to it, so work done for one regulator counts toward the next.
New York water and wastewater
New York drinking water systems serving more than 3,300 people must meet the Department of Health (DOH) cybersecurity rule by January 1, 2027, and wastewater systems face parallel Department of Environmental Conservation (DEC) rules. We build the program, policies, incident and emergency response plans, and operator training, then prepare you for the regulator.
CMMC for defense contractors
Defense contractors that handle Controlled Unclassified Information (CUI) are seeing Cybersecurity Maturity Model Certification (CMMC) Level 2 written into their contracts. We build the program, prepare you for the Certified Third-Party Assessment Organization (C3PAO) that performs the assessment, and stay on as your virtual Chief Information Security Officer (vCISO).
NYS DFS Part 500
Most of our current clients work here, and it is where our record comes from: more than 30 examinations, none failed, no regulatory findings. We run Part 500 programs year-round, so the annual certification and the next examination arrive with the evidence already in place.
For Canadian defense suppliers, we also prepare organizations for the Canadian Program for Cyber Security Certification (CPCSC), including combined CMMC and CPCSC programs for companies that sell on both sides of the border.
Also in our practice
The same program, for other regulated work
We also run security programs for healthcare organizations under HIPAA (the federal health information privacy and security law), municipalities, non-profits, and businesses that take card payments under PCI DSS (the payment card industry's security standard). Same Gap Review, Build, and Run.
Current clients in these areas: nothing changes. If you know an organization that needs this work, we welcome the introduction.
How an engagement runs
The same four steps for every regulator. Timelines depend on your size and starting point, and you get ours in writing before you commit.
1. A call
You tell us who regulates you and your deadline. We tell you plainly what the work involves and whether we're the right firm for it.
2. Gap Review
We compare your current program against the requirements that apply to you. You get a written, prioritized list of gaps and a fixed price to close them.
3. Build
We write the policies and plans, work with your staff or IT provider to put the controls in place, and assemble the evidence the regulator will ask to see.
4. Run
We manage the program month to month and prepare you for each examination. We don't take a client into an examination we don't expect them to pass.
Who you work with
A principal-led team.
No handoff to a junior.
Every engagement is led by Brandon Finton, President and Principal Consultant (CISSP, CISM), who stays your point of contact from the first call through the examination.
Analysts
Evidence collection, policy drafting, and vulnerability management.
Testing partner
Penetration testing through an established partner firm.
Monitoring partner
24x7 monitoring through a partner security operations center (SOC).
Fixed fees to start.
Monthly after that.
Gap Review and Build are fixed-fee projects. Run is a monthly retainer you can end with [30] days' notice.
A DFS Part 500 Gap Review is $3,000. A CMMC Level 2 Gap Review is $12,500. Water and wastewater pricing is set by system size.
Start with a 30-minute call.
Bring your deadline and any letter from your regulator. You'll leave knowing what the work involves and roughly what it costs.
