About NPS

A security practice, not a staffing desk.

NPS is a cybersecurity advisory firm. We work with organizations that are accountable to somebody: a regulator, a prime contractor, an insurer, or the enterprise customer whose security review is holding up the contract.

Why we exist

Security advice has a delivery problem. The large firms sell partner credibility and deliver junior hours. The tooling vendors sell a platform and leave the program to you. Both models produce documents. Neither reliably produces a security posture you could defend in a room with someone who knows what they are looking at.

We built NPS around the opposite arrangement. Senior practitioners doing the work directly, staying long enough to see the control actually operate, and writing in language the person signing the cheque can evaluate.

What we are not

We are not a managed security service, and we will not pretend that monitoring is a strategy. We are not a reseller dressed as an advisor, which is why we can tell you that the tool you are about to buy will not fix the problem you have. And we are not a body shop: every engagement is scoped to an outcome, not to a headcount.

At a glance
PracticeSecurity advisory
BasedNew Jersey, USA
Practice areas8
DeliverySenior-led, always
How we operate

Four commitments we will be held to.

Clarity over jargon

If a smart non-specialist cannot follow the argument, we have not finished writing it. Complexity is not the same as depth.

Say the uncomfortable thing

You are paying for judgment, and judgment that only ever agrees with you is worthless. We will tell you when the answer is that you have a people problem, not a tool problem.

Own the outcome

We do not hand over a findings list and call it delivery. We stay until the control works and someone on your team owns it.

Proportion, always

Security that costs more than the risk it removes is a bad trade. Part of our job is telling you what not to do.

Credentials

Certification is table stakes. Experience is the differentiator.

Our practitioners hold the credentials you would expect and, more usefully, have run the programs those credentials describe. Ask us about the engagement, not the acronym.

CISSPCISMCCSPCISAISO 27001 Lead AuditorISO 27001 Lead ImplementerCMMC RPAWS SecurityAzure Security EngineerCIPP/EGIACCRISC
Questions

Things people ask before engaging.

How is this different from hiring a security consultancy?
Two things. First, the person who scopes your engagement is the person who does the work, there is no pyramid where a partner sells and an analyst delivers. Second, we operate programs rather than just recommending them. If we tell you to build a control, we will help you build it and stay through the first audit cycle.
We're small. Are we too early for this?
Usually not, but the shape changes. A 30-person company does not need a governance committee; it needs the four or five controls that remove most of its real exposure and an honest answer for its enterprise customers. We scope to your stage. If the right advice is “do three things and call us in a year,” that is what you will get.
What does a first conversation look like?
Thirty minutes, no deck. You describe what triggered the call: a customer requirement, an audit date, an incident, a board question. Then we tell you what we would do about it and roughly what it takes. If we are not the right fit, we will say so and point you somewhere better.
Can you work alongside our existing MSSP or IT provider?
Yes, and often that is the point. Your MSSP monitors and responds; they are generally not accountable for your risk decisions, your compliance posture or your architecture. We fill that gap and hold the provider to a measurable standard on your behalf.
Do you actually implement, or only advise?
Both. Assessments and strategy are how most engagements start, but our architecture, AppSec and operations work is hands-on, building the guardrails, wiring the pipeline, tuning the detections, sitting in the design review. Advice that stops at the recommendation is where most security money is wasted.
How do you charge?
Three ways, chosen to fit the work. Fixed fee for scoped projects like assessments and certification programs. A monthly retainer for ongoing work such as fractional CISO or embedded architecture. And hourly for advisory support that is genuinely open-ended, where pretending to know the scope in advance would only cost you money. Whichever applies, the rate and the shape of the engagement are agreed in writing before we start.

Start with a straight conversation

Thirty minutes, no deck, no pitch. Tell us what prompted the call and we will tell you what we would do about it, including when the answer is that you do not need us yet.