Security program management · Syracuse, New York

One security program.
Ready for your regulator.

Orion Secure builds and runs cybersecurity programs for New York water and wastewater systems, defense contractors, and firms regulated by the New York State Department of Financial Services (DFS). We prepare you for the examiner or assessor, then keep the program running after they leave.

Book a 30-minute call

30+ DFS examinations

Client examinations under NYS DFS Part 500, the state's cybersecurity regulation for financial services. None failed. No regulatory findings.

20 years

In information security, including security leadership at a hospital.

CISSP · CISM · MS

Certified Information Systems Security Professional and Certified Information Security Manager. MS, Syracuse University.

We prepare. We never assess our own work.

The examiner or assessor is always independent of us. Our job is getting you ready for them.

Services

Three regulators.
One program underneath.

Every program we build sits on the NIST Cybersecurity Framework (CSF), a public standard from the National Institute of Standards and Technology. Water, defense, and DFS requirements all map to it, so work done for one regulator counts toward the next.

New York water and wastewater

New York drinking water systems serving more than 3,300 people must meet the Department of Health (DOH) cybersecurity rule by January 1, 2027, and wastewater systems face parallel Department of Environmental Conservation (DEC) rules. We build the program, policies, incident and emergency response plans, and operator training, then prepare you for the regulator.

Water and wastewater systems →

CMMC for defense contractors

Defense contractors that handle Controlled Unclassified Information (CUI) are seeing Cybersecurity Maturity Model Certification (CMMC) Level 2 written into their contracts. We build the program, prepare you for the Certified Third-Party Assessment Organization (C3PAO) that performs the assessment, and stay on as your virtual Chief Information Security Officer (vCISO).

CMMC Level 2 readiness →

NYS DFS Part 500

Most of our current clients work here, and it is where our record comes from: more than 30 examinations, none failed, no regulatory findings. We run Part 500 programs year-round, so the annual certification and the next examination arrive with the evidence already in place.

DFS Part 500 program management →

For Canadian defense suppliers, we also prepare organizations for the Canadian Program for Cyber Security Certification (CPCSC), including combined CMMC and CPCSC programs for companies that sell on both sides of the border.

Also in our practice

The same program, for other regulated work

We also run security programs for healthcare organizations under HIPAA (the federal health information privacy and security law), municipalities, non-profits, and businesses that take card payments under PCI DSS (the payment card industry's security standard). Same Gap Review, Build, and Run.

Current clients in these areas: nothing changes. If you know an organization that needs this work, we welcome the introduction.

How an engagement runs

The same four steps for every regulator. Timelines depend on your size and starting point, and you get ours in writing before you commit.

No charge · 30 minutes

1. A call

You tell us who regulates you and your deadline. We tell you plainly what the work involves and whether we're the right firm for it.

Fixed fee · [2 to 4 weeks]

2. Gap Review

We compare your current program against the requirements that apply to you. You get a written, prioritized list of gaps and a fixed price to close them.

Fixed fee · [2 to 6 months]

3. Build

We write the policies and plans, work with your staff or IT provider to put the controls in place, and assemble the evidence the regulator will ask to see.

Monthly · no long-term contract

4. Run

We manage the program month to month and prepare you for each examination. We don't take a client into an examination we don't expect them to pass.

Who you work with

A principal-led team.
No handoff to a junior.

Every engagement is led by Brandon Finton, President and Principal Consultant (CISSP, CISM), who stays your point of contact from the first call through the examination.

Analysts

Evidence collection, policy drafting, and vulnerability management.

Testing partner

Penetration testing through an established partner firm.

Monitoring partner

24x7 monitoring through a partner security operations center (SOC).

About the team and how we work →

Fixed fees to start.
Monthly after that.

Gap Review and Build are fixed-fee projects. Run is a monthly retainer you can end with [30] days' notice.

A DFS Part 500 Gap Review is $3,000. A CMMC Level 2 Gap Review is $12,500. Water and wastewater pricing is set by system size.

See full pricing →

Start with a 30-minute call.

Bring your deadline and any letter from your regulator. You'll leave knowing what the work involves and roughly what it costs.

Book a 30-minute call