Security controls for counsel and contracts
When a case or a contract turns on cybersecurity or data protection, the question is usually simple. Which baseline applied, were the controls implemented, and did they work? That includes whether the data those words were supposed to protect was in scope and controlled. I am the engineer who does that work. I help counsel get a defensible answer. I help buyers know what to require in the contract and the SOW. I help sellers know what they will have to produce and prove. I do not exist to pre-clear a deliverable pile before it goes out the door.
Work with meExpert Witness
Counsel retain me when the dispute is the security program. I review what baseline applied, what was implemented on the organization and on the system, and whether those controls were effective, including whether the data at issue was actually protected. The work is a written opinion, deposition, and trial if the case goes that far.
Expert witnessContracts
I help both sides of the deal understand the cybersecurity and data-protection commitment before it is locked. If you are buying, here is what you need to request. If you are selling, here is what you need to be able to provide. The work is scope, baseline, evidence, and vendors, not a last-minute review of product deliverables.
Contract scopingNIST SP 800-53 / 800-53B | CNSSI 1253 | CMMC / NIST 800-171 and 800-172 | FedRAMP / DoD cloud