In the sea services, it means grip the line and don't let go — whatever the weather does. That's the standard this firm was built to deliver for the suppliers who keep the Defense Industrial Base running.
The large consultancies do good work — for clients big enough to command their A-team. Small and mid-sized defense suppliers usually get something else: a rotating cast of junior consultants, templated deliverables, and an invoice that assumes a compliance department is receiving the work.
Holdfast Cyber was founded to be the alternative: a senior practitioner who scopes the engagement, does the work, and answers the phone during your audit. The same discipline the founder learned standing watch in Coast Guard port security — accountability, documentation, no shortcuts — applied to protecting your place in the defense supply chain.
The crest carries the firm's three commitments: hold your position under pressure, see trouble before it reaches you, and defend what your contracts depend on.
Eight years as a Port Security Specialist with PSU 309, protecting critical maritime infrastructure. The origin of the firm's operating discipline: stand the watch, document the watch, hand off the watch clean.
Executive security leadership including a 500-endpoint zero-trust deployment and a 22% cyber-insurance premium reduction — building and running programs, not just auditing them.
Principal consultant managing a multi-million-dollar portfolio across 25+ clients: eight organizations taken to first-time ISO 27001 certification with zero critical findings, three PCI DSS v4.0 Level 1 ROC engagements as named lead, and a 40% reduction in high-severity findings across managed programs.
That full stack — operator, executive, and assessor-grade consultant — focused on one mission: getting Detroit-metro defense suppliers certification-ready and keeping them there.
Every engagement is delivered against the standard of a practitioner holding CISSP, CISM, CRISC, C|CISO, and ISO 27001 Senior Lead Auditor credentials, backed by an M.S. in Cybersecurity. You're not paying for a firm's letterhead — you're getting the person the letterhead is about.
If your SPRS score is a 45, you'll hear 45 — with the exact route to raise it. Optimistic assessments fail audits; honest ones pass them.
The practitioner who scopes your engagement runs your assessment, writes your documentation, and picks up when the assessor calls.
Policies and plans written to how your operation actually runs — because an SSP that describes a fictional company is a finding waiting to happen.
Start with a conversation about where you are and what your contracts require.
Get in Touch