Cascadia Cyber Consulting

Services

Project-based security work for public-sector IT teams.

Four service lines, each scoped as a discrete engagement with a written deliverable. Built for IT directors and deputy directors at counties and municipalities with 200–2,000 endpoints and no dedicated security staff.

Security gap audit

A two-week assessment of your environment against CIS Controls v8, NIST CSF 2.0, and the Washington State Auditor's cybersecurity performance audit criteria. Delivered as a written report with prioritized findings and a 90-day remediation roadmap.

  • Endpoint, network, identity, and data review
  • Policy and procedure gap analysis
  • State Auditor readiness assessment
  • Prioritized findings with effort estimates
Investment
Starting at $7,500
Duration
2 weeks

Incident response program

Six-week engagement to build a complete incident response capability — written plan, runbooks for the most likely incident types, tabletop exercise, and 30 days of post-delivery Q&A. Aligned to NIST SP 800-61 R3, CJIS, and HIPAA where applicable.

  • Incident Response Plan (IRP) document
  • Runbooks for ransomware, BEC, insider, and data loss
  • Tabletop exercise with leadership
  • Communications templates for legal, PIO, public
Investment
Starting at $12,000
Duration
6 weeks

Incident response support

Hands-on assistance during an active incident — containment, eradication, recovery, and post-incident reporting. Active incidents are handled on a best-effort basis, with priority response for retainer clients.

  • Containment and eradication guidance
  • Coordination with EDR/XDR and DNS-layer tooling
  • Evidence preservation for internal review
  • Written post-incident report
Investment
$250 / hour
Duration
8-hour minimum

Security awareness training

A custom training program tailored to your workforce — the threats your people actually face, in language they actually use. Designed for integration with KnowBe4 or similar platforms if you already have them.

  • Role-based curriculum (front office, field, leadership)
  • Phishing simulation campaign design
  • Onboarding and annual refresher modules
  • Metrics and reporting framework
Investment
Starting at $3,500
Duration
Custom

Ready to scope an engagement?

Tell me about your environment and what you're working toward. I respond to project inquiries within 1–2 business days.