What a virtual CISO actually does in the first 90 days
A look at how a vCISO engagement starts — and what to expect month by month.
Tri State Cyber runs your entire security program as your virtual CISO: setting strategy, closing gaps, meeting compliance, and watching for threats — so you can focus on running the business.
From executive-level strategy down to hands-on fixes, we cover the work most businesses can't staff for in-house.
We map your environment, risks, and compliance obligations against a recognized framework.
You get a roadmap ranked by real risk and effort — no 200-page report you'll never read.
Policies, controls, and defenses get put in place — and we remediate the gaps ourselves.
Ongoing management, monitoring, and reporting. Your security program keeps running.
Most providers hand you findings and walk away. We stay, we own outcomes, and we do the work — at a fraction of the cost of a full-time CISO.
Book a free 30-minute consultation. We'll talk through your environment, your obligations, and where the real risk is.
Book a consultation →Engage us for your full program, or bring us in for a specific need. Every engagement is scoped to your business, your risk, and your budget.
Security needs aren't one-size-fits-all. Pick the model that fits where your business is right now — and scale it as you grow.
A Chief Information Security Officer-level partner who owns your security program — strategy, governance, compliance, and day-to-day decisions — on a fractional basis that fits a growing business.
You've hit the size where customers, partners, and insurers start asking hard security questions.
SOC 2, HIPAA, PCI, or CMMC are on the table and you need someone to own the program.
Your IT staff is capable but stretched, and security keeps falling to the bottom of the list.
Something happened, and "never again" needs to become an actual, managed program.
Every program starts with a conversation about your business and your risk. No obligation.
Book a consultation →Tri State Cyber is an independent cybersecurity consultancy helping businesses across the tri-state area build, run, and defend serious security programs — without the overhead of a full in-house team.
FOUNDER & PRINCIPAL CONSULTANT
With over 25 years leading technology and security programs across financial, telecommunications, and healthcare industries, I founded Tri State Cyber to give growing businesses the kind of senior security leadership that's usually out of reach. My approach is practical: reduce real risk, meet your obligations, and never drown you in jargon.
We believe good security is mostly about doing the fundamentals well, consistently. We won't sell you tools you don't need or reports you won't use. We'll tell you where the real risk is, fix what we can, and keep your program moving.
New Jersey, Pennsylvania, and Delaware — on-site where it helps, remote where it doesn't.
Practical security thinking for business owners and IT leaders. (These are placeholder posts — replace with your own articles in WordPress.)
A look at how a vCISO engagement starts — and what to expect month by month.
The handful of things to get in order before you ever talk to an auditor.
What credential exposure means for your business, and what to do about it.
Tell us a bit about your business and what's on your mind. We'll get back to you within one business day.
Thanks for reaching out — we'll get back to you within one business day.
Last updated: 7/1/2026
Tri State Cyber LLC ("Tri State Cyber," "we," "us," or "our") respects your privacy. This Privacy Policy explains what information we collect through our website, how we use it, and the choices you have. By using this website, you agree to the practices described here.
We collect two categories of information:
We do not sell or rent your personal information. We may share it with:
Our website may use cookies and similar technologies to remember preferences and understand how the site is used. You can control cookies through your browser settings; disabling them may affect some functionality.
We use reasonable administrative, technical, and physical safeguards designed to protect your information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We retain personal information for as long as needed to fulfill the purposes described in this policy, to comply with our legal obligations, resolve disputes, and enforce our agreements.
Depending on where you live, you may have rights to access, correct, delete, or restrict the use of your personal information, or to opt out of certain processing. To make a request, contact us using the details below. We will respond consistent with applicable law.
Our website may link to third-party sites we do not control. This policy does not apply to those sites, and we encourage you to review their privacy practices.
Our website and services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. Changes become effective when posted on this page, and we will update the "Last updated" date above.
Questions about this policy or your information can be sent to info@tristatecyber.com or by phone at 856-685-3041.
Last updated: 7/1/2026
These Terms of Service ("Terms") govern your access to and use of the website of Tri State Cyber LLC ("Tri State Cyber," "we," "us," or "our"). By accessing or using this website, you agree to these Terms. If you do not agree, please do not use the site.
This website provides general information about our cybersecurity and technology consulting services, including virtual CISO (vCISO) services, security program management, risk and gap assessments, remediation, dark web monitoring, and compliance readiness. Any consulting services we perform for you are governed by a separate written agreement, statement of work, or engagement letter. In the event of a conflict between these Terms and a signed engagement agreement, the engagement agreement controls with respect to those services.
Information on this website is provided for general purposes only and does not constitute professional, legal, or security advice, and does not create a consulting or advisory relationship. Cybersecurity involves evolving and unpredictable threats: while we apply industry-recognized practices, no service, assessment, or safeguard can guarantee complete security or that a system will be free from vulnerabilities, breaches, or incidents. Nothing on this website is a warranty or guarantee of any particular security outcome.
You agree not to:
The website and its content — including text, graphics, logos, and design — are owned by or licensed to Tri State Cyber and are protected by applicable intellectual property laws. You may view and use the site for your own informational, non-commercial purposes. All other rights are reserved.
Our website may reference or link to third-party websites and services that we do not control. We are not responsible for their content, availability, or practices, and referencing them does not imply endorsement.
The website and its content are provided "as is" and "as available," without warranties of any kind, whether express or implied, including implied warranties of merchantability, fitness for a particular purpose, non-infringement, and any warranties regarding accuracy, reliability, or availability, to the fullest extent permitted by law.
To the fullest extent permitted by law, Tri State Cyber and its members, officers, employees, and contractors will not be liable for any indirect, incidental, special, consequential, or punitive damages, or for any loss of data, profits, or business, arising out of or related to your use of this website — even if advised of the possibility of such damages. Liability for our consulting services is addressed in the applicable engagement agreement.
You agree to indemnify and hold harmless Tri State Cyber from claims, damages, liabilities, and expenses arising out of your misuse of the website or your violation of these Terms.
Confidential information exchanged during an actual engagement is protected under the terms of the applicable engagement agreement or a separate non-disclosure agreement, not by these website Terms.
These Terms are governed by the laws of the State of [New Jersey], without regard to its conflict-of-laws rules. You agree that any dispute relating to these Terms or the website will be resolved in the state or federal courts located in [New Jersey].
We may update these Terms from time to time. Changes become effective when posted on this page, and continued use of the website constitutes acceptance of the updated Terms.
Questions about these Terms can be sent to info@tristatecyber.com or by phone at 856-685-3041.