BackstopCyber Start a conversation
Security & compliance consulting

The backstop for overworked IT and security teams.

You already have people doing security. Backstop Cyber puts senior capability behind them — vCISO leadership, audit readiness, risk assessment — scoped to the deadline in front of you and no larger.

vCISO & fractional leadership SOC 2 · HIPAA · CMMC · PCI DSS Remote-first, [FILL: area served]

The situation

It is not a competence problem. It is a capacity problem.

The teams we work with are not making obvious mistakes. They are making reasonable trade-offs, every day, with less time than the work requires.

The scope outgrew the team

Your infrastructure got more complex, your customers got more demanding, and your security scope quietly tripled. Headcount did not. The people holding it together are good at their jobs — there are simply not enough hours in a week to both do the work and prove the work.

The audit date does not move

A customer contract, an insurer, or a regulator has put a date on the calendar. Somebody now owns evidence collection, policy gaps, and a control set they did not design — on top of the job they already had.

Everything is urgent, so nothing is ranked

Alerts, security questionnaires, vendor reviews and a backlog of findings all arrive at the same priority. Without someone whose job is to rank them against real risk, the loudest item wins — and the loudest item is rarely the most important one.

Services

What we take off your plate

Five engagements. Each one is written down before it starts, scoped to end, and built so your team can run what is left behind.

  1. S-01

    Fractional security leadership (vCISO)

    A senior security leader on your team for a defined number of hours each month. We own the security roadmap, sit in the meetings where risk decisions actually get made, translate technical exposure into language a board, an insurer or an enterprise customer will accept, and give your engineers a named person to escalate to. This is not an advisory retainer that produces slide decks — it is accountability for outcomes you agree on in writing before the engagement starts.

    • Roadmap ownership
    • Board & exec reporting
    • Policy authority
    • Vendor & tool triage
  2. S-02

    Compliance and audit readiness

    SOC 2, HIPAA, CMMC, PCI DSS and ISO 27001. We work backward from your audit date: scope the control set, run a gap assessment before the auditor does, write policies that survive scrutiny rather than templates that do not, stand up evidence collection so it becomes a by-product of normal operations instead of a quarterly fire drill, and run a readiness dry-run against the actual criteria. We are not your auditor and cannot be — we are the team that makes the audit uneventful.

    • Gap assessment
    • Policy drafting
    • Evidence automation
    • Readiness dry-run
  3. S-03

    Risk assessment

    A structured look at what could actually hurt you, ranked. We inventory what you run, where the data lives, who can reach it, and what the realistic failure modes are — then hand you a prioritised risk register with owners, effort estimates, and a defensible rationale for the things you have consciously chosen not to fix yet. Mapped to NIST CSF or whichever framework your customers ask about, so the output is reusable in questionnaires, renewals and insurance applications.

    • NIST CSF mapping
    • Risk register
    • Third-party review
    • Remediation plan
  4. S-04

    Security program build-out

    The unglamorous foundation, built properly: asset and identity inventory, an access review cadence that actually happens, logging and detection somebody reads, vulnerability management with an SLA attached, backups you have tested by restoring them, and an incident plan that names people rather than roles which no longer exist. We build it with your team, document it as we go, and hand it over.

    • Identity & access
    • Logging & detection
    • Vulnerability management
    • Backup & recovery
  5. S-05

    Incident response retainer

    A pre-negotiated agreement so that the worst day is not also the day you go shopping for help. We hold your environment context, contacts and escalation path in advance, commit to a response window ([FILL: your response SLA]), and run tabletop exercises so the plan has been rehearsed by the people who will have to use it. When something happens you make one call and we are already oriented.

    • Retained hours
    • Tabletop exercises
    • Escalation path
    • Post-incident review

Engagement

How an engagement works

Three steps. No discovery phase that bills for six weeks before anything useful happens.

  1. First conversation

    A working session, not a pitch

    We spend the first call on your situation rather than our capabilities: what is due, who owns it today, what has already been tried, and what happens if the date slips. You leave with an honest read on whether you need us at all. Sometimes the answer is one more hire or a tool you already pay for — we will say so.

  2. Before any work starts

    A written scope with a number on it

    You get the specific deliverables, who does what, the hours or the fixed fee, the assumptions we are making, and the date the engagement ends. No open-ended retainer that quietly becomes permanent. If the scope needs to change, that is a conversation first and an invoice second.

  3. Through delivery, and after

    We work alongside your team, then hand it back

    We work in your tools, in your meetings, with your people, documenting as we go. The measure of a good engagement is that your team can run what we built without us. When the scope is delivered we say so and stop — continuing is a decision you make, not a default that happens.

Fit

Who this is for — and who it is not

We would rather lose an hour here than three months on a bad fit. If the right-hand column describes you, we are not the right call and will tell you so on the first one.

This fits if

  • You have an internal IT or security team already carrying the work, and it is stretched.
  • A SOC 2, HIPAA, CMMC, PCI DSS or ISO 27001 deadline exists and is real.
  • A customer, insurer, investor or board has asked a security question you cannot answer with confidence.
  • You want to own your security program long-term rather than rent it forever.
  • You would rather hear “you do not need this” than be sold a larger scope.

This is not a fit if

  • You need the auditor or certifying body itself. We prepare you for those; we cannot also be them.
  • You want the cheapest possible path to a certificate. That is a different kind of vendor.
  • You need a 24/7 staffed SOC or managed detection as a product. We will help you choose one.
  • You want a fixed price quoted before anyone has looked at your environment.
  • You need someone to take the blame rather than the work.

Frameworks

Frameworks we work in

We prepare organisations for these programs and operate inside them. Backstop Cyber is not an auditor, an assessor, or a certifying body, and does not present itself as one.

  • SOC 2 Type I and Type II readiness
  • HIPAA Security & privacy rule
  • CMMC Level 1 and Level 2 prep
  • PCI DSS Scope reduction & SAQ support
  • ISO 27001 ISMS design and readiness
  • NIST CSF Risk mapping & maturity

Contact

Tell us what is due, and when.

Send the shape of the problem and the date attached to it. A person reads every message that comes through this form and replies to it — there is no sequence, no drip, and nothing is added to a list.

Reply time
[FILL: your response commitment]
Coverage
[FILL: area served]
Phone
[FILL: phone number]
Active incident right now?
Call [FILL: incident line] rather than using this form.
Email, if you prefer
[FILL: role address]
We reply to this address only.
The framework, the date, and who owns it today is usually enough.

We use what you send only to reply. See the privacy notice.

This form uses a Cloudflare Turnstile check, which needs JavaScript. With JavaScript off, please use the phone number or email address listed beside this form instead.