$ anchor --status

Enterprise Security.
SMB Friendly.

25+ years of cybersecurity expertise powering scalable products and strategic consulting. From security awareness to incident readiness to Virtual CISO (vCISO) services.

25+
Years Experience
100+
Policies Authored
25+
Audits & Assessments
85+
Published Articles

Why Anchor

Four things that separate working with us from hiring another security vendor.

Practitioner, not just consultant

Jonathan has led SOC 1 and SOC 2 programs as Director of GRC at Kevel, and performed third-party vendor reviews aligned to ISO 27001 at other organizations. He's built real compliance programs — not just advised on them.

Enterprise expertise, SMB cost structure

25+ years in Director-level security roles at enterprise organizations. Priced and scoped for companies without a dedicated security team.

Products + consulting in one shop

BitDrip for AI data loss prevention. TL;CR for CPE tracking. Tools built because the problem was real — and still maintained by the same person doing your consulting.

Published, verifiable expertise

8-part NIST CSF series. Active security blog with 85+ articles. Transparent credentials: CISSP, CISM, CCSP, GRCP. Nothing behind a sales wall.

Who We Work With

If any of these describe your situation, we should talk.

You're a SaaS company with enterprise customers asking for SOC 2 before signing contracts

You're a healthcare organization with HIPAA obligations and no dedicated compliance officer

You're building your first formal security program and don't know where to start

You need CISO-level security leadership but can't justify a full-time hire

You're preparing for government contracts that require NIST CSF alignment

You've had a security incident and need a structured response and prevention plan

Industries We Serve

Healthcare
HIPAA, PHI handling, OCR readiness
SaaS & Technology
SOC 2, ISO 27001, enterprise security
Professional Services
Data privacy, client confidentiality
Financial Services
GLBA, PCI DSS, state security requirements
Manufacturing
OT/IT security, supply chain, federal contracts

Frameworks We Support

Our products and services help organizations meet these compliance requirements.

Client Work

A sample of recent engagements. Additional references available on request.

SOC 1 Type 1 Readiness

FinTech Startup · 2025
GRC & Compliance

A payments-adjacent FinTech startup needed SOC 1 Type 1 readiness to satisfy enterprise customer due diligence. No formal compliance program existed at the start of the engagement.

Delivered a complete readiness package in six weeks: stakeholder interviews across six departments, a COSO 2013-aligned gap analysis, 20 finalized control policies, a visual gap summary for executive leadership, and a remediation tracker. Engagement concluded with a formal written confirmation from the client that all deliverables met scope.

20
Policies Delivered
6
Week Timeline
6
Departments Interviewed

Third-Party Vendor Risk Assessments

Professional Services Firm · 2025
Vendor Risk

Engaged as a security subcontractor to support a consulting firm's vendor risk program. Conducted ISO 27001-aligned third-party vendor risk assessments across multiple vendors, including review of security documentation, compliance posture, and risk rating.

TPVR · ISO 27001-Aligned · Subcontract Consulting

NIST CSF & Cloud Security Assessment

Enterprise Media Company · 2023
Security Assessment

Performed a NIST Cybersecurity Framework alignment review and AWS cloud security assessment across multiple production environments for a large media platform. Delivered gap analysis findings to executive leadership with a prioritized remediation roadmap.

NIST CSF · AWS · Multi-Environment Assessment
“Anchor Cyber Security delivered a complete SOC 1 Type 1 readiness package — 20 control policies, COSO-aligned gap analysis, and full readiness binder — in under six weeks. Jonathan was professional, thorough, and made a complex process manageable.”
Tushar Kirtane
Leadership · FinTech Startup

Ready to build a security program that actually holds up?

Schedule a free consultation. No sales pitch — just a direct conversation about your specific situation.