Kenneth holds the CERT Insider Threat Program Manager designation from Carnegie Mellon University’s Software Engineering Institute — the only professional certification program of its kind in the country. Combined with U.S. Army counter-intelligence experience and Fortune 100 insider threat work at Dell SecureWorks, this credential combination does not exist elsewhere in the boutique advisory market.
Three organizations where insider risk is the highest-consequence exposure
Research from the University of Buffalo found that 58% of future healthcare workers would consider selling patient data. HIPAA mandates access controls and workforce training — but most practices do not have a documented insider risk program. We build one.
Law firms, accounting practices, and financial advisors hold confidential client data that departing employees carry with them. ABA and state bar guidance increasingly requires documented security controls. We build programs that address the actual risk — not just the checklist.
Volunteers and contractors access donor and beneficiary data without standard employment agreements and access controls. That gap is where insider risk lives. We design programs that fit nonprofit structures — without enterprise complexity or cost.
Understanding the scope of internal security risks
Advisory-led program design, governance, and workforce risk awareness
AI-powered analysis of user activities to detect anomalies and potential threats before they become incidents.
Comprehensive visibility into endpoint activities including file access, application usage, and data transfers.
Prevent sensitive data exfiltration through email, cloud storage, USB devices, and other channels.
Enhanced oversight for administrators and users with elevated access to critical systems.
Educate employees on insider threat indicators and foster a security-conscious culture.
Create comprehensive insider threat policies aligned with regulatory requirements and best practices.
Protection against all forms of internal risk
Employees or contractors who intentionally steal data, sabotage systems, or commit fraud for personal gain.
Well-meaning employees who accidentally cause security incidents through careless actions or policy violations.
Legitimate users whose credentials have been stolen by external attackers through phishing or other means.
Let our experts assess your insider threat vulnerabilities and build a comprehensive protection program.