Virtual CISO services for government agencies
Executive security leadership for state, county and local government, without the cost of a full-time CISO. We work on a fractional or project basis.
Serious risk, no budget for it
Ransomware crews, nation-state actors and opportunists all go after state, county and local government. Emergency services, public utilities, election systems and financial records are high-value targets. Most agencies still cannot fund a full-time chief information security officer.
A virtual CISO (vCISO) fills that gap. We take the security leadership role on a fractional or project basis, which puts the oversight in place without the salary line.
Every consultant here served as a Cybersecurity Advisor with the U.S. Cybersecurity and Infrastructure Security Agency (CISA), working with state and local governments in the field. Spencer Wood, our Founder, CEO and Principal Consultant, covered CISA Region 5: Illinois, Indiana, Michigan, Minnesota, Ohio and Wisconsin, after senior roles inside Ohio state government.
What a government vCISO does
A vCISO is not a managed security service provider. We do not monitor your network or run your helpdesk. We set the security direction, carry the risk conversation at the leadership level and brief the elected officials who approve the budget.
What is included
Engagements get scoped to what your agency needs and what it can spend.
-
Security program development
We build or rebuild a formal cybersecurity program against NIST CSF, CISA guidance or your state's own framework, including the policies, standards and governance structure underneath it.
-
Cybersecurity risk assessments
What is most likely to hurt you, and in what order to fix it. The ranking is written so leadership can act on it and put a number against it.
-
Leadership and board advisory
We represent security at the executive level. That means the briefings, a standing report to elected officials or department heads, and the numbers behind the budget request.
-
Incident response planning
We write the plan with your team, then put it through an exercise before you need it. The scenarios are government ones: ransomware, a data breach and an election system going down on the wrong day.
-
Security awareness training
We train elected officials, department heads and staff on phishing and social engineering. No jargon, and the examples are public-sector.
-
Vendor and third-party risk
Your technology vendors, your software contracts and everyone outside the building who can reach your systems. You get a prioritized list of the risk sitting in those contracts and connections.
Tabletop exercises and cyber-physical convergence
Most agencies find the gaps in their incident response plan during the incident. A tabletop exercise moves that discovery earlier. We write and run the scenario, and the useful part is finding out where coordination breaks: who gets called, who owns the decision, whether the phone list is current.
The scenario has to be one you could face. That means a break-in at a water plant on the same night as a network compromise, or ransomware locking an election management system 72 hours before polls open.
The convergence problem
Cyber and physical security usually sit in different departments and under different bosses. Your access control, cameras, HVAC and power management all run on the network now, and they carry the same vulnerabilities as everything else on it. Attackers already work both sides. Most security programs are still organized as though these were two separate jobs.
So we assess them together. Spencer ran cybersecurity programs in Ohio state government and assessed physical security at government offices, critical infrastructure sites and election facilities, including as part of his federal advisory work with CISA.
If the building itself is the worry, we assess that too: physical security consulting.
Who this is for
We work with public-sector organizations nationwide.
- Counties and municipalities with no security staff at all
- State agencies that need a program audited, or rebuilt after one
- Election offices
- Public utilities and water systems carrying critical infrastructure obligations
- Emergency management agencies
- Regional councils of government and other multi-jurisdictional bodies, where the security job usually belongs to nobody in particular
- Government contractors that have to meet federal security standards
Every consultant who works with Foundation Consultant Group served as a Cybersecurity Advisor with CISA, the federal field role for reducing cyber risk in state and local government and critical infrastructure.
- Six states CISA Region 5: Illinois, Indiana, Michigan, Minnesota, Ohio and Wisconsin, where Spencer Wood served.
- More than 20 years His record in enterprise, government and critical infrastructure.
- Nationwide Where we take engagements now.
Leadership
Spencer Wood held senior roles in Ohio state government, including interim State Chief Information Officer and Deputy CIO of Ohio, and CIO for the Ohio Secretary of State, where he ran enterprise IT and supported statewide election security work. StateScoop and Government Technology covered the interim State CIO appointment in 2018. Federal service came after that: CISA Region 5, reducing cyber, operational and physical risk with the officials who own those systems. He holds the CISM and has more than 20 years in enterprise, government and critical infrastructure.
Next step
Tell us what your agency is dealing with. We will tell you whether a standing vCISO engagement is the right shape, or whether a one-time risk assessment gets you further for less money.
Get in Touch