Virtual CISO advisory · Amherst, New Hampshire
Security leadership for companies too small to carry a full-time security executive — and for the families and executives those companies depend on.
Intelligence first, then defense. I find out what an adversary already knows about you before I recommend a single control. Every price on this page is fixed or published, and every engagement has a first step a New Hampshire owner can say yes to without a committee.
CISO of Northrop Grumman’s $7 billion Electronics Sector. Global CISO of Exterran for six years. Navy intelligence officer. DoD Cyber Crime Center. Carnegie Mellon Software Engineering Institute.
Every retainer, assessment, and incident package has a number on it before the first call. Nothing to negotiate at 2 a.m.
I recommend what I run in my own homes and office, and I don’t replace your IT.
What a CISO does — four questions I get paid to answer
Every account, device, mailbox, cloud tenant, and vendor that touches your money or your customers — and which of them would hurt if it disappeared, leaked, or lied to you. An inventory you can read, kept current.
Which passwords are for sale, which accounts can be reset with a stolen phone number, what an impersonator already knows about your leadership from public records and social media. This is intelligence work, and it comes first.
A written plan, a call list, and a rehearsal — before the ransomware note, the fraudulent wire, or the hijacked executive mailbox. Then, when it happens, I run it with you.
Cyber-insurance applications, customer security questionnaires, NIST CSF, CMMC and NIST SP 800-171 for defense suppliers, state privacy and breach-notification law — answered truthfully, with the evidence to back it.
Services & pricing — fixed or published
Half a day at your shop, office, or practice. I look at what you actually run — the computers, the email, the Wi-Fi, how money moves — score it against The BLACKBOOK, and leave you a one-page list of the three things to fix first, in plain English, with what each will cost. No report nobody reads.
A security executive you can call. One on-site visit a quarter, your insurance application and customer questionnaires answered, staff briefed once a year, and a phone number that gets me when something looks wrong. Month to month after the first quarter.
A standing cadence: monthly posture review and scorecard, policies people will actually follow, staff training, insurer and customer questionnaires answered, vendor and tool review, incident leadership, and a briefing the owner can read. Includes the incident-response retainer and the office platform below. Six-month minimum.
Everything above, plus a control set mapped to what you must prove — NIST CSF, CMMC and NIST SP 800-171 where applicable — and an annual tabletop exercise so the first real incident is not the first rehearsal. Six-month minimum.
Twenty CISO hours. A Gingerbread intelligence report on your leadership, a scored inspection of your people, devices, email, office network, and cloud tenant, and a signed report with the first three fixes and a 90-day plan. Ten business days. Household and executive edition: $2,995.
The file an adversary would build on you and your family — leaked credentials, home and family exposure, accounts that fall to a phone number, voice and likeness that could be cloned — ranked, in plain English, with a plan to take it back. Executive & Family: $1,495. Continuous: $195 per month.
Cyber due diligence on a target before the price is set: what they have, what is already exposed, what an insurer or a customer will find, and what it will cost to fix — delivered as a deal memo with a dollar figure, not a compliance checklist. Sell-side readiness for owners preparing to exit. Post-close: a 100-day security plan and a portfolio-wide standard.
An annual retainer buys a two-hour response window, the retained hourly rate, and priority — it costs nothing until you call. Business incidents (email compromise, ransomware) begin with a fixed first-40-hours engagement at $9,500; household incidents at $1,500 to stabilize and $3,950 end to end. Hourly work: $300 standard, $250 for retainer clients, $450 after hours.
Prices in USD, pre-tax. What you spend on a first step credits toward the next. Hardware and third-party licenses pass through at cost plus 15% unless included.
Who it's for
Machine shops, medical and dental practices, law and accounting firms, contractors, real estate offices. I am in Amherst; I come to you. Start with a half-day check, not a contract.
You have an IT provider or a small IT team. Nobody is translating between the technology and the business, and nobody has signed their name to the risk.
CMMC and NIST SP 800-171 are contract conditions now. You need someone who has read them and can tell you what is actually required, then hold the line with your IT provider.
Law, accounting, real estate, wealth management, construction — anywhere a single fraudulent wire or a hijacked partner mailbox ends the year.
A target’s security posture is a price term. The diligence memo says what is exposed, what an insurer or customer will find, and what it will cost to fix — before you sign, and again at day 100.
The people a company depends on are attacked at home first. I have provided security to dozens of UHNW family offices and their principal homes; Gingerbread and the BLACKBOOK came out of that work.
How I work
Before any control is recommended, I find out what an adversary already knows and which of your habits make their job easy. Then the plan is built against the threat that exists, not the one you imagine.
I recommend what I run myself, and I say so. Product referrals earn me nothing; the design is the deliverable.
Your provider keeps the keys and does the work. I set the requirements, verify the result, and answer for it to you, your insurer, and your customers.
A risk register the owner can read, a plan the staff have rehearsed, and a scorecard that shows whether this quarter was better than last.
I get you ready. An independent assessor certifies. Never the same party — that’s the whole point.
The reference stack — eat your own dog food
When a client wants the stack designed and deployed, it is this one: endpoint protection with patching and backup on every computer and phone, API-connected email protection on every mailbox, a solid-state gateway at each home and office, and a web application firewall in front of anything public.
Consumer-grade edge hardware, no per-seat security licenses beyond the agents, no 24×7 operations center. Low cost by design.
Every one of those sensors reports to GOLEM, our self-built intelligence-operations layer. It takes all sources — endpoint, email, edge, the Gingerbread dossier, threat feeds, public records, and the non-cyber facts of your world — fuses them into indications and warnings, acts on its own where the answer is clear, and produces an intelligence-based action plan for what remains.
Monadnock Cyber is not a managed service provider and does not operate a security operations center. GOLEM-connected protection for a household starts at $245 per month; for a small business, a $1,000 monthly platform fee plus $35 per device.
“I’d try the business first. If I couldn’t get in, I’d enumerate the employees, then the family, then the home network. AI now does that in minutes, and everything it produces looks real. The family is the attack path, and it always was.”Jeff Stutzman · CEO, Monadnock Cyber
Who you are working with
Jeff Stutzman has done the CISO job at scale and in the small: Chief Information Security Officer for Northrop Grumman’s $7 billion Electronics Sector, global CISO of Exterran for six years, and security executive on retainer to dozens of ultra-high-net-worth family offices and their principal homes.
Before that, thirty years in intelligence and cybersecurity: a Navy intelligence officer, leadership at the Department of Defense Cyber Crime Center, Principal Engineer at Carnegie Mellon’s Software Engineering Institute, an early watchstander at what became the Internet Storm Center, and a contributing author to the Honeynet Project’s Know Your Enemy. He founded a managed security service provider that defended small and mid-sized businesses for eight years before it was sold.
He holds the CISSP, an MBA, and a Senior Executive Fellowship from the Harvard Kennedy School. Monadnock Cyber, LLC is a service-disabled veteran-owned small business in Amherst, New Hampshire, and the publisher of The BLACKBOOK of Cyber Security and Fraud Protection. The firm is deliberately small: clients work with Jeff, and the stack above is the one that protects his own homes and office.
Call before you change anything. The evidence worth having is the same evidence that gets destroyed by cleaning up.
Connect
Start with a conversation. Thirty minutes, no charge, no pitch. Bring the question that keeps you up — an insurance application, a questionnaire from your biggest customer, a phone that is acting strangely — and I’ll tell you what I would do first and why. If that’s the end of it, good.