Methodology · How the work is done

We are a young firm. So judge the method, not the logo wall.

Cyberneza LLC was formed in April 2025. We will not manufacture proof we do not have — no invented case studies, no borrowed client logos, no anonymised "a client of ours" stories. That is a deliberate choice, and it is the same standard we will apply to your evidence when an assessor asks for it. This page is what we offer instead: the method, the artifacts, the documentation system, and credentials you can verify without asking us.

Cyber AB RP (CPN 76768) · CISSP · CRISC · CCSK v5 · CCZT  |  29+ years  |  Federal and commercial  |  Veteran-owned

The honest part

Why there are no case studies on this site

Two reasons, and only one of them is about our age.

The first is that Cyberneza is new. Publishing a case study we do not have would be the single fastest way to disqualify ourselves from the work we do. A compliance consultant's entire product is whether their statements can be relied on; a firm willing to invent a client is a firm willing to wave through an incomplete control.

The second outlasts the first. Security and compliance clients rarely permit their readiness gaps to be described publicly, and the ones who do are usually the least representative. So even a mature firm's case-study page is a filtered sample — which is why buyers who know this market ask to see the deliverable instead.

What we will never do

  • Invent or embellish an engagement, a metric, or an outcome
  • Present a training or reference exercise as customer work
  • Use a partner's or vendor's client as though it were ours
  • Claim an audit result — we do not perform audits and cannot promise their outcome
  • Describe a credential we do not hold, or hold in a form other than stated

If any statement on this site turns out to be wrong, tell us and it gets corrected or removed. Contact us →

The method

Four stages, and what each one actually produces

Each stage ends with an artifact and a decision. If a stage cannot name both, it is padding and should not be sold.

Stage 1

ASSESS — establish where you actually are

Interviews, documentation review, evidence sampling, and configuration review against the framework in scope. Scores reflect control design and evidence readiness, because a control that produces no evidence half-exists to an assessor.

Artifact: a written gap assessment — readiness by control domain, findings in the standard format below, and a sequenced remediation plan.

Decision it enables: whether to proceed, what it will take, and whether you need outside help at all.

ASSESS — fixed-fee gap assessment →

Stage 2

BUILD — turn findings into executable work

Security architecture and control design, remediation sequenced by dependency and risk, implementation procedures and configuration guidance, and the validation criteria that define "done". Cyberneza designs; your technical teams execute production changes through your own change-management process.

Artifact: control design, implementation procedures, a sequenced remediation plan, and validation criteria with the evidence each control must produce.

Decision it enables: what your engineers do on Monday, in what order, and how they will know it worked.

BUILD — scope and out-of-scope →

Stage 3

READINESS — test the story before someone else does

Validation of the implemented state, the documentation, the evidence, and control ownership — against what an auditor, assessor, or enterprise customer will actually sample. Remaining gaps are named while there is still time to close them.

Artifact: an evidence review with residual gaps, owners, and the exceptions likely to be raised.

Decision it enables: whether to start the audit or observation window now, or to wait.

READINESS — evidence review →

Stage 4

SUSTAIN — keep it true after the report

Ongoing guidance for controls, evidence, risk decisions, architecture changes, and new contractual or regulatory requirements. Compliance decays quietly; the point of this stage is that the decay is visible while it is still cheap.

Artifact: maintained control and evidence state, and decisions recorded as they are made rather than reconstructed a year later.

Decision it enables: re-audit, recertification, or a new customer requirement, without a scramble.

SUSTAIN — ongoing advisory →

Not every engagement uses all four. The smallest engagement that moves the work forward is the right one, and 100% of the ASSESS fee is credited toward a larger package started within 90 days — which only makes sense for a firm that expects the assessment to be honest. See pricing →

The evidence standard

The shape of every finding we write

A finding that is only an opinion is unusable. Every one we write carries six parts, so it can be argued with, prioritised, assigned, and closed.

1. Observation

What was seen, specifically enough to be reproduced or disputed — the system, the sample, the date, the number.

2. Requirement

The specific criterion or control it maps to — a Trust Services criterion, an 800-171 requirement, an Annex A control — not "best practice".

3. Why it matters

The consequence, stated as risk and as audit exposure. Those are different arguments and both usually need making.

4. Guided remediation

What to change, in enough detail that a competent engineer can start without a follow-up meeting.

5. Effort and owner

A realistic effort estimate and the role that owns it, so the plan can be scheduled rather than admired.

6. Evidence expectation

What the closed control must produce on an ongoing basis. Defined with the fix, not discovered during the audit.

What exists on day one

The documentation system does not start from a blank page

The slowest part of most readiness engagements is writing the paperwork from nothing. Cyberneza maintains a structured documentation system so that time goes into your environment instead of into a template.

Discovery, scoping & system description

Structured intake for the boundary, the systems in scope, the data types, and the description an assessor reads first.

Governance & programme management

Roles, ownership, review cadence, risk process, and the management artifacts every framework asks a programme to be able to show.

Policy pack

Starting points covering 18 policy areas — drafted to be tailored to your environment, never issued as generic documents with your name substituted in.

Procedure & operating-record pack

The procedures and recurring records that turn a written policy into something that produces evidence month after month.

Audit readiness & reporting

Readiness review structures, evidence expectations, and the reporting formats used through an audit or assessment window.

Engagement readiness workbook

A multi-tab working record tracking control state, evidence, ownership, and open items — so status is a lookup rather than a meeting.

Two honest caveats. These are working starting points, not a product — Cyberneza does not sell or licence them as a documentation package, and a policy handed over untailored is worse than no policy because it creates an obligation nobody intends to meet. And they are framework-aligned, not framework-guaranteed: your assessor's expectations, not our template, decide what is acceptable.

Verifiable, not asserted

Credentials you can check without asking us

Every item below is verifiable at its issuer or in a public registry. A claim that can only be confirmed by the person making it is not evidence.

Professional credentials

  • Cyber AB CMMC Registered Practitioner (RP) — CPN 76768, since June 2026 · verify
  • CISSP — ISC2, since 2010 · ISC2
  • CRISC — ISACA, since 2011 · verify
  • CCSK v5 — Cloud Security Alliance, since 2025 · verify
  • CCZT — Cloud Security Alliance (Zero Trust), since 2026 · verify
  • CompTIA A+ — since 2002

Training and education

  • SANS SEC530 — Defensible Security Architecture and Engineering / Zero Trust (2023)
  • NVIDIA Certified Associate — AI Infrastructure and Operations (NCA-AIIO)
  • ServiceNow Fundamentals
  • BS, Computer Information Systems — Troy University, cum laude
  • AS, Avionic Systems Technology — Community College of the Air Force

Business registrations and designations

  • SBA-Certified Veteran-Owned Small Business (VOSB) — effective 13 July 2026
  • SAM.gov — UEI T97XZHE7C5D5, CAGE 1AVJ5, registered for All Awards
  • Better Business Bureau — accredited · profile
  • Cyberneza LLC — Florida limited liability company, formed April 2025

Background

29+ years across Department of Defense, federal contracting, energy, financial services, and SaaS — including enterprise cybersecurity architecture in global financial services and operations management for the DoD's first SaaS provider (IBM e-Collab Center).

Full background → · Capability statement →

Independence

What we are not, and why it protects you

Cyberneza does not perform audits, does not issue certifications, and is not a C3PAO. We prepare an organization and then coordinate with the independent CPA firm, certification body, C3PAO, or assessor that does. A firm that both builds the controls and blesses them is not offering you an assurance product.

We take no referral fee from auditors. On attest engagements AICPA independence rules would not permit it in any case, and the practical consequence is the one that matters: the incentive is to introduce you to the firm that fits your stage, budget, and framework, not the one paying the largest commission.

Also true

  • Tool-agnostic. Partner relationships — including Vanta and Drata — expand what can be delivered; they do not decide the recommendation.
  • If an assessment shows you do not need a further engagement, we say so. That is the point of a fixed-fee assessment that credits forward.
  • Cyberneza is not a staffing or recruiting firm and does not place personnel.
  • Audit, certification-body, and platform fees are paid by you, directly, and are separate from our fee.
FAQ

Common questions

Can you share client references?

Not yet, and we will say so rather than manufacture one. What is available instead is on this page: the method, two full sample deliverables, and credentials verifiable at their issuers. If a reference is a hard requirement for your procurement process, tell us early — that is a legitimate constraint and worth knowing before either side spends time.

Are the sample reports based on real clients?

No. Both sample deliverables were prepared for fictional organizations and are labelled as fictional on the page itself. They demonstrate the structure, depth, and directness of the deliverable, not a customer engagement.

Why should we hire a firm without a client list?

Because for this kind of work the decision is about the practitioner and the method, and both are inspectable. You will work directly with a senior practitioner rather than being sold by a principal and delivered by a junior — which is the more common failure in compliance consulting than inexperience is.

Do you use the same method for federal and commercial work?

Yes. The stages, the finding standard, and the evidence discipline are the same; what changes is the requirement set, the assessor, and the vocabulary. CMMC and NIST SP 800-171 work and SOC 2 and ISO 27001 work are peer lines of the same practice, not a specialism and a sideline.

Who actually does the work?

Larry Downard, founder and principal consultant, delivers engagements directly, drawing on a network of specialist partners when a project needs specialist work. You are told when a partner is involved and what they are doing.

What happens if you find we do not need you?

We tell you. The fixed-fee assessment exists so that outcome costs you one published fee and a clear written answer rather than a multi-month engagement, and that fee credits forward in full if you do decide to continue within 90 days. See pricing →

Read the deliverable, then decide.

The strongest thing a young firm can offer is the work itself, in advance and in full. Read a sample report end to end. If the standard is one you would want applied to your own programme, the next step is a conversation about scope.