Virtual CISO advisory · Amherst, New Hampshire

A Chief Information Security Officer on retainer.

Security leadership for companies too small to carry a full-time security executive — and for the families and executives those companies depend on.

Intelligence first, then defense. I find out what an adversary already knows about you before I recommend a single control. Every price on this page is fixed or published, and every engagement has a first step a New Hampshire owner can say yes to without a committee.

30 years

CISO of Northrop Grumman’s $7 billion Electronics Sector. Global CISO of Exterran for six years. Navy intelligence officer. DoD Cyber Crime Center. Carnegie Mellon Software Engineering Institute.

Published prices

Every retainer, assessment, and incident package has a number on it before the first call. Nothing to negotiate at 2 a.m.

No software to sell

I recommend what I run in my own homes and office, and I don’t replace your IT.

What a CISO does — four questions I get paid to answer

Inventory

What do we have, and what is it worth?

Every account, device, mailbox, cloud tenant, and vendor that touches your money or your customers — and which of them would hurt if it disappeared, leaked, or lied to you. An inventory you can read, kept current.

Exposure

What is already out there?

Which passwords are for sale, which accounts can be reset with a stolen phone number, what an impersonator already knows about your leadership from public records and social media. This is intelligence work, and it comes first.

Readiness

What happens when it goes wrong?

A written plan, a call list, and a rehearsal — before the ransomware note, the fraudulent wire, or the hijacked executive mailbox. Then, when it happens, I run it with you.

Obligations

What do insurers, customers, and regulators require?

Cyber-insurance applications, customer security questionnaires, NIST CSF, CMMC and NIST SP 800-171 for defense suppliers, state privacy and breach-notification law — answered truthfully, with the evidence to back it.

Services & pricing — fixed or published

New Hampshire · under 25 employees

Main Street Security Check

Half a day at your shop, office, or practice. I look at what you actually run — the computers, the email, the Wi-Fi, how money moves — score it against The BLACKBOOK, and leave you a one-page list of the three things to fix first, in plain English, with what each will cost. No report nobody reads.

$1,495Fixed · on site
New Hampshire · under 25 employees

Main Street CISO

A security executive you can call. One on-site visit a quarter, your insurance application and customer questionnaires answered, staff briefed once a year, and a phone number that gets me when something looks wrong. Month to month after the first quarter.

$750Per month
Companies under 50 employees

Virtual CISO retainer

A standing cadence: monthly posture review and scorecard, policies people will actually follow, staff training, insurer and customer questionnaires answered, vendor and tool review, incident leadership, and a briefing the owner can read. Includes the incident-response retainer and the office platform below. Six-month minimum.

$4,000Per month
50 to 200 employees

Virtual CISO retainer

Everything above, plus a control set mapped to what you must prove — NIST CSF, CMMC and NIST SP 800-171 where applicable — and an annual tabletop exercise so the first real incident is not the first rehearsal. Six-month minimum.

$6,500Per month
The starting point · up to 25 employees

BLACKBOOK Business Assessment

Twenty CISO hours. A Gingerbread intelligence report on your leadership, a scored inspection of your people, devices, email, office network, and cloud tenant, and a signed report with the first three fixes and a 90-day plan. Ten business days. Household and executive edition: $2,995.

$4,995Fixed
Executive digital exposure intelligence

Gingerbread

The file an adversary would build on you and your family — leaked credentials, home and family exposure, accounts that fall to a phone number, voice and likeness that could be cloned — ranked, in plain English, with a plan to take it back. Executive & Family: $1,495. Continuous: $195 per month.

$495Per person · fixed
Defined deliverable, defined end

Fixed-scope projects

  • Cyber-insurance renewal and application review
  • Customer security questionnaires and vendor assessments
  • CMMC / NIST SP 800-171 preparation for defense suppliers
  • Policy set, risk register, and incident-response plan
from $7,500Per project
Private equity and M&A

Transaction support

Cyber due diligence on a target before the price is set: what they have, what is already exposed, what an insurer or a customer will find, and what it will cost to fix — delivered as a deal memo with a dollar figure, not a compliance checklist. Sell-side readiness for owners preparing to exit. Post-close: a 100-day security plan and a portfolio-wide standard.

  • Buy-side cyber due diligence, target under 200 employees: $12,500 fixed, ten business days; larger targets scoped
  • Sell-side readiness (six to nine months before market): from $7,500
  • Post-close 100-day plan and portfolio standard: from $15,000
  • Portfolio CISO retainer: $3,000 per portfolio company per month
$12,500Buy-side diligence · fixed
Answered day or night

Incident readiness and response

An annual retainer buys a two-hour response window, the retained hourly rate, and priority — it costs nothing until you call. Business incidents (email compromise, ransomware) begin with a fixed first-40-hours engagement at $9,500; household incidents at $1,500 to stabilize and $3,950 end to end. Hourly work: $300 standard, $250 for retainer clients, $450 after hours.

$3,600Per year · business retainer

Prices in USD, pre-tax. What you spend on a first step credits toward the next. Hardware and third-party licenses pass through at cost plus 15% unless included.

Who it's for

New Hampshire businesses, first

Machine shops, medical and dental practices, law and accounting firms, contractors, real estate offices. I am in Amherst; I come to you. Start with a half-day check, not a contract.

Owner-led companies, 10 to 200 people

You have an IT provider or a small IT team. Nobody is translating between the technology and the business, and nobody has signed their name to the risk.

Defense suppliers and regulated firms

CMMC and NIST SP 800-171 are contract conditions now. You need someone who has read them and can tell you what is actually required, then hold the line with your IT provider.

Professional firms that move money

Law, accounting, real estate, wealth management, construction — anywhere a single fraudulent wire or a hijacked partner mailbox ends the year.

Private-equity sponsors and acquirers

A target’s security posture is a price term. The diligence memo says what is exposed, what an insurer or customer will find, and what it will cost to fix — before you sign, and again at day 100.

Executives, families, and family offices

The people a company depends on are attacked at home first. I have provided security to dozens of UHNW family offices and their principal homes; Gingerbread and the BLACKBOOK came out of that work.

How I work

Intelligence first

Before any control is recommended, I find out what an adversary already knows and which of your habits make their job easy. Then the plan is built against the threat that exists, not the one you imagine.

I sell no software

I recommend what I run myself, and I say so. Product referrals earn me nothing; the design is the deliverable.

I don’t replace your IT

Your provider keeps the keys and does the work. I set the requirements, verify the result, and answer for it to you, your insurer, and your customers.

Everything in writing

A risk register the owner can read, a plan the staff have rehearsed, and a scorecard that shows whether this quarter was better than last.

Readiness, not certificates

I get you ready. An independent assessor certifies. Never the same party — that’s the whole point.

The reference stack — eat your own dog food

What I run in my own homes and office

When a client wants the stack designed and deployed, it is this one: endpoint protection with patching and backup on every computer and phone, API-connected email protection on every mailbox, a solid-state gateway at each home and office, and a web application firewall in front of anything public.

Consumer-grade edge hardware, no per-seat security licenses beyond the agents, no 24×7 operations center. Low cost by design.

GOLEM — the intelligence fusion cell

Every one of those sensors reports to GOLEM, our self-built intelligence-operations layer. It takes all sources — endpoint, email, edge, the Gingerbread dossier, threat feeds, public records, and the non-cyber facts of your world — fuses them into indications and warnings, acts on its own where the answer is clear, and produces an intelligence-based action plan for what remains.

  • The stack runs itself; a virtual CISO reads what it reports.
  • No console watch is sold or implied. The design’s point is that nobody has to stare at one for it to work.

Monadnock Cyber is not a managed service provider and does not operate a security operations center. GOLEM-connected protection for a household starts at $245 per month; for a small business, a $1,000 monthly platform fee plus $35 per device.

“I’d try the business first. If I couldn’t get in, I’d enumerate the employees, then the family, then the home network. AI now does that in minutes, and everything it produces looks real. The family is the attack path, and it always was.”Jeff Stutzman · CEO, Monadnock Cyber

Who you are working with

Jeff Stutzman has done the CISO job at scale and in the small: Chief Information Security Officer for Northrop Grumman’s $7 billion Electronics Sector, global CISO of Exterran for six years, and security executive on retainer to dozens of ultra-high-net-worth family offices and their principal homes.

Before that, thirty years in intelligence and cybersecurity: a Navy intelligence officer, leadership at the Department of Defense Cyber Crime Center, Principal Engineer at Carnegie Mellon’s Software Engineering Institute, an early watchstander at what became the Internet Storm Center, and a contributing author to the Honeynet Project’s Know Your Enemy. He founded a managed security service provider that defended small and mid-sized businesses for eight years before it was sold.

He holds the CISSP, an MBA, and a Senior Executive Fellowship from the Harvard Kennedy School. Monadnock Cyber, LLC is a service-disabled veteran-owned small business in Amherst, New Hampshire, and the publisher of The BLACKBOOK of Cyber Security and Fraud Protection. The firm is deliberately small: clients work with Jeff, and the stack above is the one that protects his own homes and office.

If something looks wrong

Call before you change anything. The evidence worth having is the same evidence that gets destroyed by cleaning up.

1 888 299 6615 Answered day or night

Connect

Start with a conversation. Thirty minutes, no charge, no pitch. Bring the question that keeps you up — an insurance application, a questionnaire from your biggest customer, a phone that is acting strangely — and I’ll tell you what I would do first and why. If that’s the end of it, good.

Principal
Jeff Stutzman
Email
[email protected]
Direct
603 930 2222
Incident
1 888 299 6615
Office
Amherst, New Hampshire