Request a Review
Security without overkill

Practical security for real world businesses.

Risk reviews, policy, and hands on hardening that fit how a company actually runs, not a binder full of theater. I founded MorgSec. Associates, referrals, and partners handle the client work across the range of jobs that show up.

20+
Years in security
Navy
Submarine veteran
Practical
Risk & hardening
Clear
No theater
Risk reviews
Policy & controls
Hands on hardening
Submariner
Partner network
Private practice · founder led
Enterprise security background
Risk reviews & policy
U.S. Navy submariner
Associates & partners
Who I Am

Systems discipline first. Then the checklist.

I started in the weapons department of U.S. Navy Trident submarines: the Lafayette class USS Casimir Pulaski (SSBN 633) and the USS Ohio (SSBN 726), maintaining Trident C-4 strategic weapons systems. On a boat, if a system fails, you do not open a ticket. You put the crew at risk. That is where I learned what security actually means: operational discipline, not theater.

U.S. Navy Enlisted Submarine Warfare Insignia (Silver Dolphins)
Qualified in submarines: systems walkthroughs and board review

For the next two decades I took that habit into enterprise technology around Seattle: building, securing, and fixing infrastructure in the real world. I know the difference between what looks good on paper and what holds up when someone actually checks the environment.

I founded MorgSec for companies that need practical protection without a full time security staff. Between this practice and the rest of the portfolio, there are more kinds of work than one person can (or should) own. Associates take some of it. Referrals and partners take other parts. We put the right people on the job.

Private practice. I am the founder. This is not a government office and does not speak for the U.S. government. It is also not a pitch for me as the default assessor or solo consultant on every engagement. Client work is staffed through associates, referrals, and partners.

"Protection that works on the floor, not a binder that only works in a meeting."
What the practice covers

Focused security work.

Protection that fits how you actually run, not a rigid checklist that only exists for the audit folder. Staffed through associates, referrals, and partners.

Evaluation
Risk reviews

Walk the environment. Find what is exposed. Prioritize fixes that matter to your business and your customers, not a 200-page report nobody reads.

Strategy
Security planning

A realistic roadmap: what to do first, what can wait, and what fits budget and headcount.

Hands on
Hardening & policy

Help implementing tools, tightening configs, drafting usable policies, and training the people who have to live with them.

Ongoing
Advisor support

Periodic reviews and practical advice so protections do not rot after the first project ends.

How work usually runs

Practical risk work.

Security that is part of how you operate, not a project you install once and forget.

01
Understand the risks
What you run, what you hold, what can break

Start with how the business actually works: assets, workflows, and who can reach what. Find what is exposed and what would hurt if it failed.

Asset mapping Threat profiling Gap discovery
02
Build a roadmap
Priorities, budget, and sequence

A phased plan that balances real risk with headcount and money, not a fantasy shopping list.

Security roadmap Control selection Budget fit
03
Put fixes in place
Alongside your team or MSP

Configure tools, tighten access, write procedures people can follow, and leave something you can run without us.

04
Keep it current
Checks and course corrections

Periodic reviews and scans so last year's fixes still match this year's systems and threats.

The Reality

What a real gap analysis looks like.

A gap analysis is not a questionnaire. It's a structured walkthrough of your environment against a control framework, and for most small to medium businesses, that means a structured control set appropriate to their risk and customer requirements. The process starts with asset inventory: a complete list of where sensitive business data lives, who touches it, how it moves between systems, and what the network boundary actually is. Most companies discover during this step that their sensitive data lives in more places than they thought, a shared OneDrive folder, a technician's personal laptop that connects to the shop Wifi, an unencrypted email archive going back three years.

Network mapping comes second. The goal is a current, accurate diagram of every device that can reach systems containing sensitive data, not just the servers, but every endpoint, printer, IoT device, and remote connection. Serious customers and auditors will often ask to see your network diagram. If it doesn't match the actual environment, that's a finding. If it matches but shows gaps (a switch with no logging, remote access without MFA, a contractor VPN with too much access), each of those is a separate control deficiency with a documented path to remediation.

Access control is where most organizations find their densest cluster of gaps. “Only authorized people get in” sounds simple, but enforcing it means reviewing every account that can reach sensitive systems, confirming departed employees are gone, verifying service accounts use minimum privilege, and checking that guests cannot wander into protected resources. In practice, most companies pick up three to five access gaps over a couple of years of normal change, turnover, new software, remote work. Finding them is mechanical. Fixing them before a customer or insurance review is the point.

The Threat

Why small businesses are ransomware targets.

The common belief that ransomware groups target large enterprises is wrong. The Verizon Data Breach Investigations Report consistently shows that small businesses represent a majority of confirmed breach victims each year. The reason is economics: a company with 50 employees and no dedicated security staff is orders of magnitude easier to compromise than a Fortune 500 with a 40-person security operations center. The ransom demand from a small business attack (typically $50,000 to $250,000) is small enough that many insurance providers will simply pay, creating a self reinforcing incentive for attackers to target them repeatedly.

The average cost of a ransomware incident for a small business is not just the ransom payment. It's the forensic investigation (15,000 to 40,000), the downtime (typically 21 days to recover operations), the notification requirements if customer data was involved (legal fees, credit monitoring services), and the reputation damage with clients who learn their data was in a compromised system. A 50-person company that processes $8M in annual revenue and shuts down for three weeks loses approximately $460,000 in revenue before accounting for any of the breach response costs. That's the actual number that belongs in the risk conversation, not the ransom demand.

The three most common attack vectors for small business ransomware infections are phishing emails that deliver credential stealing malware, exposed RDP (Remote Desktop Protocol) ports on externally accessible servers, and compromised third party software updates. The first requires employee awareness training and email filtering. The second requires eliminating unnecessary external RDP exposure or placing it behind a VPN with MFA. The third requires software inventory management and patch discipline. None of these controls are expensive. All of them are standard, documented security practice. Most small businesses that get hit with ransomware were missing at least two of the three.

The Distinction

Compliance is not the same as security.

This is the most important thing a small business needs to understand about compliance frameworks. Passing a checklist or certification means you documented controls that met a standard at a point in time. It does not mean your environment is secure against a motivated adversary. Those are not the same thing, and confusing them creates false confidence that leads companies to stop improving once they pass the assessment.

Compliance frameworks are necessarily backward looking. Many framework controls were written based on known threats and established best practices at the time of publication. The adversary community doesn't wait for the framework to be updated. Living off the land attacks that use legitimate system administration tools to move laterally after initial compromise don't require any malware to drop, they're invisible to most endpoint detection tools that look for malicious file signatures. A company that has checked every box on a framework and has no behavioral monitoring or network traffic analysis in place is compliant and vulnerable at the same time.

MorgSec cares about both outcomes because they answer different questions. A checklist or customer questionnaire may need documentation that proves you met a standard on a given day. Actual security is about whether your network is a soft target. The gap analysis maps what a customer or insurer may ask for. Ongoing advisory work covers what no static checklist fully captures: monitoring, incident readiness, and adjusting when the threat picture moves.

Background

Who founded this, and how work gets done.

MorgSec is a private commercial practice I founded. The people on the engagement (associate, partner, or referral), look at your systems with operational judgment, not a script of buzzwords. Paper certificates are not the product. Working controls are.

My background is submarine systems discipline plus 20+ years of enterprise infrastructure and security work in the Seattle area. I am the founder, not the default hands on consultant on every job. Client work is staffed through associates, referrals, and partners so different companies and different kinds of work across the portfolio can actually get covered. Not a government service.

Security background
Background supporting regulated and higher stakes environments
Silver Dolphins Insignia
Qualified in submarines
Attained through cross functional systems walkthroughs and a rigorous evaluation board
FTB MT
U.S. Navy Submariner | Weapons Department
USS Casimir Pulaski (SSBN 633) & USS Ohio (SSBN 726) · Trident C-4 systems

Core Competencies

Cybersecurity Domains
Risk reviews Policy & controls Network hygiene Incident readiness Scope boundaries
Security Management
Risk analysis Policy creation Security training Vulnerability scanning
Infrastructure Security
MFA implementation Network segmentation Cloud architecture Identity management
Get in touch

Tell us what you need.

Send a short note. We'll get it to the right person: associate, partner, or referral. Private practice. Not a government service. No slide theater.

Select all areas where you need advisory or support: