What we do
Here are a few recent engagements where we helped clients address concrete cybersecurity needs, in a way that fit their business, their risks, and their reality.
Incident Response Tabletop Exercise (TTX)
For a public sector client, we designed and led tabletop exercises that tested how the organization would respond to a realistic cyber incident. We built a scenario that reflects their environment, operations, risks, and decision-making structure, then guided key participants through the response step by step.
This exercise helps identify what works, what is unclear, and where teams may struggle with communication, escalation, roles, priorities, third parties, or business continuity. After the session, we provided clear findings and practical recommendations so the client can improve its incident response plans, strengthen coordination, and be better prepared to manage a real cyber event with less confusion, less disruption, and more confidence.
Cybersecurity Target Operating Models (TOM)
For a large private sector client, we defined a cybersecurity Target Operating Model (TOM) that clarified how security should be organized, governed, delivered, and improved over time. We reviewed the current structure, responsibilities, processes, capabilities, tools, committees, and interactions with internal teams and external providers, then designed a practical operating model aligned with the client’s size, risks, priorities, and maturity.
This deliverable helped clarify who does what, how decisions are made, which services should exist, how they should be managed, and where improvements are required. It gave the client a clear and realistic path to strengthen cybersecurity governance, reduce ambiguity, improve coordination, and ensure that security activities support the organization’s mission and operational needs.
Roadmap definition and delivery
For a public sector transportation organization, we defined a cybersecurity roadmap to help translate strategic priorities, current-state observations, and identified risks into a clear, actionable improvement plan. We structured the work to clarify what should be addressed, in what order, and why, taking into account the organization’s operational reality, public-sector responsibilities, available capacity, and maturity level.
The roadmap provided a practical sequence of initiatives across governance, risk management, security operations, incident preparedness, awareness, technology, and third-party considerations. Its value was to give leadership a structured path forward: helping prioritize investments, align stakeholders, reduce ambiguity, and progressively strengthen cybersecurity in a realistic and sustainable way.
Testimonials
What others say about us
Anonymous, CISO
“They understood the difference between buying technology and building protection. That changed the way we prioritized, invested, and delivered.”
Investment group CISO & CIO
“Eric has a rare ability to translate complex security issues into business terms without losing the technical substance. His advice helped our leadership team understand what mattered, what could wait, and where investment would create the most value.”
Transportation industry CIO
“Sandstorm Cyber cut through the noise and helped us focus on the risks that were actually material to our organization. The result was a more disciplined cybersecurity roadmap, better executive alignment, and stronger confidence in our next steps.”