Grounded Security

Cybersecurity advice for small organizations.

Fairfax County, Virginia

Why this matters

You hold things people had no real choice about handing over. Case files. Medical records. The bank details behind every utility autopay in town. You are also the kind of organization least likely to have anyone whose actual job is protecting them.

Whoever handles your IT is not your security. They built it, so asking them whether it is safe is asking them to grade their own work. That is not a knock on them. They are paid to keep things running, and they do. Nobody is paid to ask the other question.

It will not look like a hack. It looks like an invoice you paid to a bank account that changed halfway through an email thread. A rule in a mailbox quietly copying every message somewhere else. A login that still works months after someone left, on a shared account, so nobody can say who used it.

Someone is going to ask you. An insurance renewal questionnaire. A client's security addendum. A board, an auditor, or a records request after something goes wrong. You will answer from a document you already have, or from memory in a week you did not plan for.

Why me

Sam Aydlette. Over a decade in cybersecurity, in both federal government and private sector roles. I have led continuous monitoring and vulnerability management programs covering dozens of major cloud services, written federal policy on vulnerability scanning, and run the scans myself. CISSP. Before any of that, I was an infantryman in the 82nd Airborne.

Most of my time has been spent where strategy, regulation, engineering and security meet. That is an unusual place to stand, and it is the reason this practice exists. I can sit down with whoever actually runs your organization, understand what the business does and what it is on the hook for, and say what to do about security in terms that connect to both.

How it works

Advisory only. I never log into, install, or manage anything you own. We talk for an hour, and I ask how your organization actually runs: where files live, how payments get approved, what happens to accounts when someone leaves. Then I send you a short written report, three or four pages: what to fix now, and the structural problem underneath it.

Most of my recommendations are cheap. The incidents they prevent are not.

Who I work with

Small law firms. Small medical, dental and optometry practices. Counties, cities, towns and nonprofits.

What it costs

Discovery sessionOne hour, then a report of what your organization should fix first$1,000
Baseline assessmentYour regulated and privileged material, assessed against a tailored NIST SP 800-53 control set and mapped to whatever applies to you$7,500
Full assessmentThe same method across a larger or more complex organization. Tell me roughly how many staff and how many sitesQuoted

Follow-ups are $500 an hour, flat rate.

Get in touch

sam@groundedsecurity.io

Tell me what kind of organization you are and what prompted you to reach out.