Small on purpose.
Senior by default.
We build security programs to win business, not only to reduce risk. That is a choice about what security is for, and plenty of good people in this field would make it differently.
Nighthawk is a security practice run by people who have held the CISO seat, not people who have advised it. Every engagement is led by someone who has built and run a program at a company whose product was data. We keep the client list short, and when we're full we say so.
Where we come from
- Fifteen years in the seat
CISO at a venture-backed data infrastructure company selling into the Fortune 500. Director-level at a public security vendor. Global cyber defense for a Fortune 500 multinational with operations on four continents. Security and IT for a data business inside one of the largest enterprises in its industry. In every case, the data was the thing worth protecting.
- Builders
We still write code, run infrastructure, and stand up our own tooling. That matters because the advice you get from someone who can't do the work is advice you'll end up paying twice for.
- Onshore
US-based. The person on the scoping call is the person doing the work.
- The name
The nighthawk is a bird that hunts at dusk and is almost impossible to spot until it moves. The aircraft that borrowed its name was built on the same idea. Good security is like that: it does its job without making a spectacle of itself.
What that produced
Specifics, because a practice that says it has run security programs should be able to say what came out of them.
- Zero to SOC 2 Type II and ISO 27001
A security program built from nothing at a company whose product is data, through SOC 2 Type II and the ISO 27001, 27017 and 27018 family. The whole thing, from first policy to clean report.
- An international security organization
Security engineering, operations and architecture for a multi-tenant, ML-powered SaaS platform, led across multiple countries. SOC 2, PCI DSS, FedRAMP and HIPAA on a single estate, with the team that had to live with the answers.
- Five to seven million in pipeline
Attributed to customer trust work: security reviews, questionnaires and executive briefings that moved real deals. This is the number that makes the case for a security program to a board.
- Incident command on a nation-state intrusion
Ran the investigation at a multinational, alongside federal law enforcement. It ended in court testimony.
- AI governance that gates shipping
Established the framework that decides how AI features reach enterprise customers, at a company that ships them now. Written to survive a customer's security review, because it has to.
- Still in the seat
This is not a retired operator's practice. The same work is being done today, as a sitting CISO and CIO at a cloud-native SaaS data platform.
What we believe
Short version. We're happy to argue any of these on a call.
- Security earns you the right to a customer's business
The best programs we've seen weren't cost centers. They were the reason the company could sell to a bank, a hospital, or a government when a competitor couldn't.
- AI is a security problem and a sales problem at the same time
Your buyers are going to ask whether your AI is safe. The companies that have a real answer will win those deals. The rest will write a blog post about responsible AI and lose them.
- Say the uncomfortable thing early
If something is going to fail diligence, you want to hear it from us in week one, not from a customer in month six.