All Capabilities
04
Capability 04 / 08

Cybersecurity

Defend forward. Respond decisively.

Cyber resilience is a posture, not a product. Black Fox builds layered defenses, hunts threats inside your perimeter, and responds when the rest of the industry is still triaging tickets.

// What We Deliver

Capabilities

Each engagement combines a small senior team with the systems, tooling, and partner network the mission demands.

01

Risk & Compliance

RMF, FedRAMP, CMMC 2.0, and SOC 2 packages produced by assessors who have signed packages on the federal side.

02

Threat Hunting & SOC

Managed detection and response with named analysts, custom hunt logic, and MITRE ATT&CK coverage maps.

03

Penetration Testing

Black-, gray-, and white-box assessments — including red-team engagements with rules of engagement signed by leadership, not the help desk.

04

Incident Response

Retained IR and forensic readiness with a 1-hour engagement SLA, on-prem and cloud evidence collection, and counsel-ready reporting.

// Method

How We Engage

01
Step 01

Baseline

Inventory the attack surface, the crown-jewel data, and the controls you actually have — not the controls listed in the SSP.

02
Step 02

Harden

Identity, endpoint, network, and data tier hardening prioritized by exploitability, not vendor capability.

03
Step 03

Hunt

Continuous threat hunts informed by current adversary tradecraft and your specific business context.

04
Step 04

Respond

Pre-built playbooks, tabletop rehearsals, and a retainer that activates inside one hour.

1hr
IR Engagement SLA
MITRE
ATT&CK Aligned
24/7
SOC Coverage
// Past Performance

Proof, not promises.

A representative slice of recent cybersecurity engagements across local, state, federal, quasi-government, and private clients. Signed past-performance references — including direct contracting officer phone numbers — are furnished on qualified inquiries.

Risk & Compliance
2024

FedRAMP High Authorization Support

Authored full SSP and produced control evidence for 421 NIST 800-53 Rev. 5 controls; package achieved FedRAMP High ATO at first JAB review with no major findings.

Customer
Federal Civilian Agency Mission System
Value
$2.1M / 11 mo.
Location
National Capital Region
Risk & Compliance
2024

CMMC 2.0 Level 2 Readiness

Closed 78 control gaps across 14 NIST SP 800-171 control families; client passed third-party C3PAO assessment on first attempt with zero findings.

Customer
Defense Industrial Base Manufacturer
Value
$0.9M
Location
Southeast U.S.
Threat Hunting & SOC
2023

24x7 Managed Detection & Response

Stood up a managed SOC with named analysts and ATT&CK-aligned hunt logic across 9,200 endpoints and OT segments; mean time to detect cut from 11 days to <30 minutes.

Customer
Quasi-Government Utility Authority
Value
$3.9M / 36 mo.
Location
Georgia
Penetration Testing
2024

State Agency Red-Team Engagement

Full-scope red-team operation against external, internal, and physical attack surfaces; achieved domain dominance in 6 days and produced an evidence-grade remediation roadmap.

Customer
State Department of Public Safety
Value
$0.6M
Location
Southeast U.S.
Incident Response
2023

Ransomware Incident Response

Activated under a 1-hour IR retainer following a Conti-variant intrusion; restored core services within 72 hours, preserved counsel-ready evidence, and led the post-incident lessons-learned report to the council.

Customer
Local Government (County)
Value
$0.7M (engagement)
Location
Georgia
Risk & Compliance
2024

Private Bank SOC 2 Type II Program

Designed and operated the Type II control environment; achieved unqualified opinion across all five trust-services criteria with zero exceptions in two consecutive audit windows.

Customer
Private Regional Bank
Value
$1.3M / 24 mo.
Location
Atlanta, GA
// Cybersecurity

Engage Black Fox on cybersecurity.

Tell us what you are trying to accomplish. We will tell you, in writing, whether we are the right team and how we would attack it.

Build With Us