Fractional CISO  ·  CMMC Advisory  ·  Defense Contractors

YOUR SECURITY
PROGRAM
NEEDS A
LEADER.

Most organizations don't need a full-time CISO. They need the judgment, the program architecture, and the executive presence — on a retainer that matches where they actually are. That's what Cyber Control Group provides.

CCG-01 LOCKED HSV // 34.7N RISK // GOV
Credentials
CISSP AAISM CISM CRISC CMMC CCA CMMC CCP Tier 3 Clearance

THE SECURITY LEADERSHIP
GAP IS A REAL LIABILITY.

You have an IT team, maybe an MSP, maybe a compliance checklist — but no one in the room whose job it is to think about security at the executive level. No one owns your risk posture. No one is watching the program as a whole. And when a contract requires it, or an assessor shows up, that gap becomes visible fast.

Cyber Control Group fills that gap. We provide fractional CISO advisory on retainer — giving defense contractors, startups, and manufacturers executive-level security leadership, a structured program, and honest risk assessments that tell leadership where they actually stand. When CMMC is in the picture, you get certified assessor depth on your side of the table. We work alongside your existing IT team or MSP, not in place of them.

20+
Years Security Leadership
6
Active Security Certifications
DIB
Contractors · Startups · Manufacturers
CMMC
Certified Professional & Assessor

NO CISO. NO PROGRAM.
NO ACCOUNTABILITY.

SVC-01  ·  Anchor Engagement

Fractional CISO Advisory

Ongoing strategic security leadership on retainer — security program ownership, risk management, policy frameworks, vendor oversight, board and executive reporting, and a single point of accountability for your security posture. Tiered retainer levels scaled to your organization's size and needs.

SVC-02  ·  Entry Point

Cyber Risk Assessment

An honest, executive-ready picture of where your organization actually stands. CCG's risk assessments map your environment against the frameworks that matter to your business — NIST SP 800-171, NIST CSF 2.0, CIS Controls — and deliver a prioritized roadmap and investment analysis leadership can act on. Conducted by a certified assessor who knows what scrutiny looks like, working for you.

SVC-03  ·  CUI Scoping

CUI Scope Definition & Architecture Advisory

The single most impactful decision in your CMMC journey is how much of your environment falls in scope. Most organizations inadvertently over-scope — dragging systems, users, and infrastructure into the CUI boundary that don't need to be there. CCG brings hands-on experience limiting CUI scope to only what is contractually required, then helping leadership decide whether a purpose-built enclave or an enterprise-wide approach makes more sense for their size, contract mix, and operational reality.

SVC-04  ·  Defense Contractors

CMMC Readiness & DFARS Compliance

Structured progress toward CMMC Level 2 — gap assessments against all 110 NIST SP 800-171 controls, System Security Plan development, POAM management, evidence preparation, and remediation guidance aligned to DFARS 252.204-7012. Led by a credentialed CCA who understands what assessors are looking for — and builds readiness that holds up under scrutiny.

SVC-05  ·  Defense Startups

Security Program for Defense Startups

You just landed your first defense contract. The DFARS clause is in the agreement. You have no SSP, no policies, and no one who owns security. CCG builds your security program from scratch — first policies, first risk assessment, first SSP, and a CMMC readiness posture designed to grow with your contract portfolio without becoming a burden on your team.

SVC-06  ·  Emerging Risk

AI Risk & Shadow AI Governance

Your team is already using AI tools — often without policy, visibility, or any understanding of what data is leaving the environment. For defense contractors, AI use in or adjacent to CUI environments carries specific and underappreciated risk. CCG builds your acceptable use policy, approved tools registry, and shadow AI assessment to get ahead of the exposure before it becomes a compliance or contract problem.

THREE DIB SEGMENTS.
ONE COMMON PROBLEM:
NO ONE OWNS THE PROGRAM.

Defense Contractors

No one on your team owns security risk end to end. Your SSP is incomplete, your POA&M is a spreadsheet, and your compliance obligations — DFARS, NIST SP 800-171, progress toward CMMC Level 2 — sit with whoever has spare cycles. We provide the fractional CISO leadership and risk assessments to close that gap, without full-time headcount you don't need.

Defense Startups

You're moving fast, your first DoD contract is in hand, and security obligations just arrived that no one was planning for. You need a risk-informed security program built for where you're going — not a framework dropped on a company that isn't ready for it. We assess your actual risk, build the architecture that grows with you, and keep you credible with primes and customers.

Defense Manufacturers

Your production floor handles CUI you didn't know needed protecting, your IT environment was built for operations — not security — and your primes are asking harder questions every quarter. We assess the real risk on your shop floor, build the security program and CUI handling controls, and keep you moving toward CMMC Level 2 so you stay in the supply chain.

WHAT YOU'RE ACTUALLY BUYING
WHEN YOU HIRE A FRACTIONAL CISO.

Judgment

20+ Years of Security Leadership Across Defense & Enterprise

A Navy veteran and former VP of Information Security who has led organizations through CMMC Level 2 in complex, fast-moving defense environments. The kind of experience that lets you make the right call under pressure — not just run a framework checklist.

Assessment Depth

CMMC CCA Credentialed — We Know What Assessors Are Looking For

CCG's principal holds both CMMC CCA and CCP credentials and has worked assessments from the assessor side. When we prepare a defense contractor for CMMC, we build readiness that will hold up under scrutiny — because we understand what scrutiny actually looks like.

Technical Credibility

Security Operations Roots — Not Just a GRC Practitioner

CISSP, CISM, CRISC, and AAISM-credentialed — but grounded in security operations, not just governance. We can evaluate your stack, your architecture, and your detection capability. When your team pushes back on a security recommendation, we can hold the technical conversation.

Business Fit

Fractional Means You Get More Than You're Paying For — and Only What You Need

CCG's principal founded, scaled, and sold a cybersecurity firm before moving into executive security leadership. We understand that security has to make business sense. The program we build for you will be right-sized for where you are — and built to scale as you grow.

THE CREDENTIAL STACK THAT
BACKS EVERY ENGAGEMENT.

CISSP
ISC²  ·  Certified Information Systems Security Professional
AAISM
ISACA  ·  AI Security & Management
CISM
ISACA  ·  Certified Information Security Manager
CRISC
ISACA  ·  Certified in Risk & Information Systems Control
CMMC CCA
ISACA  ·  Certified CMMC Assessor
CMMC CCP
ISACA  ·  Certified CMMC Professional

Every CCG engagement is led by Dan DeFay — a Navy veteran, former VP of Information Security, and MSP founder who sold his firm before transitioning into executive security leadership. His credential stack spans risk, governance, compliance, and AI security.

Dan holds dual CMMC credentials administered by ISACA and has worked the assessment process from both sides — giving clients a readiness posture built to hold up under actual assessor scrutiny, not just documentation that looks right on paper.

Based in Huntsville, Alabama — embedded in the Defense Industrial Base and available for remote and on-site engagements nationally.

Meet Dan DeFay →

IF YOU'RE WONDERING WHETHER YOU
NEED A FRACTIONAL CISO —
YOU PROBABLY DO.

The conversation doesn't have to be complicated. Tell us where you are: what's driving the need, what you've already got, and what's keeping you up at night. We'll give you a straight answer about whether CCG is the right fit — and what that engagement would actually look like.

Engagement Details
Based In Huntsville, Alabama  ·  Redstone Arsenal Ecosystem
Travel National availability for on-site engagements
Verticals Defense Contractors, Defense Startups & Defense Manufacturers
Retainer Options Tiered fractional CISO engagements & project-based advisory
Risk Assessments Fixed-fee cyber risk assessments & investment decision analysis
CMMC Advisory & readiness led by a certified CMMC assessor (CCA)