Cybersecurity & compliance consulting

Security that holds up to attackers, auditors and assessors.

Since 2002, Security Best Practices has helped organizations harden their networks, meet CMMC, SOC 2, HIPAA and PCI DSS requirements, and respond decisively when incidents happen. You work directly with a senior, CISSP-certified consultant.

  • 2002Founded
  • CISSPCertified leadership
  • Finance · Healthcare · LegalRegulated industries

Trusted by organizations including

ABN AMRO Bentley Publishers BNHC Dunkin' Fragomen GV20 Therapeutics Handelsbanken NDCP Wagner

Services

Cybersecurity services for organizations that can't afford to get it wrong

Four practice areas, delivered by the same experienced team from first assessment through remediation and ongoing support.

Compliance & Audit Readiness

Gap assessments, remediation roadmaps and evidence preparation so you pass your audit or certification the first time.

  • CMMC 2.0 Level 1 & Level 2 readiness
  • NIST SP 800-171 & SPRS scoring
  • SOC 2 Type I & Type II preparation
  • HIPAA Security Rule risk analysis
  • PCI DSS 4.0 & ISO/IEC 27001 readiness

Network & Firewall Security

Design, hardening and day-to-day support for the infrastructure that keeps attackers out and your users productive.

  • Next-generation firewall design & support
  • Zero Trust architecture & ZTNA
  • SASE & secure remote access (VPN)
  • Network segmentation & microsegmentation
  • Firewall rule reviews & configuration audits

vCISO & Risk Management

Senior security leadership on a fractional basis: strategy, policy and governance without a full-time executive hire.

  • Virtual CISO / fractional CISO
  • Cybersecurity risk assessments
  • Security policy development & review
  • Third-party & vendor risk management
  • Board & executive reporting

Incident Response & Testing

Find the weaknesses before attackers do, and be ready with a tested plan if the worst happens.

  • Ransomware readiness & response
  • Incident response planning
  • Tabletop exercises
  • Vulnerability assessments
  • Penetration testing

Compliance frameworks

Current standards, practical guidance

Regulations and frameworks keep changing. We track the latest versions and translate them into controls your team can actually operate.

CMMC 2.0

Cybersecurity Maturity Model Certification for Department of Defense contractors handling FCI and CUI.

NIST CSF 2.0

The updated Cybersecurity Framework, including the new Govern function for risk ownership and oversight.

NIST SP 800-171

The 110 security requirements for protecting Controlled Unclassified Information in non-federal systems.

SOC 2

AICPA Trust Services Criteria for service organizations, covering both Type I and Type II reports.

HIPAA

Security Rule risk analysis and safeguards for covered entities and business associates handling ePHI.

PCI DSS 4.0

Payment Card Industry Data Security Standard v4.0.1, including the now-mandatory future-dated requirements.

ISO/IEC 27001:2022

The international standard for an information security management system (ISMS) and its updated Annex A controls.

SEC Cyber Disclosure

Governance, risk management and material-incident disclosure requirements for public companies.

How we work

A clear path from assessment to assurance

  1. 01

    Assess

    Understand your environment, obligations and risk, and measure where you stand today.

  2. 02

    Prioritize

    Deliver a practical roadmap ranked by risk reduction and audit impact, not vendor wish lists.

  3. 03

    Remediate

    Implement controls, configurations and policies hands-on, alongside your team.

  4. 04

    Validate & sustain

    Test, document evidence and keep you compliant as threats and standards evolve.

About us

Senior expertise. Direct access. No hand-offs.

Security Best Practices, Inc. was founded in 2002 by Keith W. Salustro, CISSP®, a senior network security consultant with more than 25 years of specialized experience. A graduate of Brown University's engineering program, Keith has designed and supported security infrastructure for global banks, healthcare organizations, law firms and growing businesses, conducted security and compliance assessments, and spoken widely on information security.

Clients choose us because they work directly with an experienced practitioner who has seen what works in the real world and who explains risk in plain business terms.

  • Vendor-neutral advice. We recommend what fits your risk and budget, not what earns a commission.
  • Hands-on delivery. We don't just write the report. We help implement the fixes.
  • Regulated-industry experience. Finance, healthcare, legal and life sciences.
  • Right-sized engagements. From a single assessment to an ongoing vCISO partnership.

Insights

Latest from our team

All insights

Contact

Let's talk about your security goals

Whether you're facing an upcoming audit, a CMMC deadline, a firewall project or a security incident, tell us what's going on. We'll respond within one business day.

  • Free initial consultation
  • Confidential, no obligation
  • Clear scope and fixed-fee options