Thirty years of protecting institutions.
Now available by the engagement.

Independent cybersecurity expertise for organizations, executives, and family offices, for the risks no software product solves. Take it as a fixed-scope engagement, or as an ongoing virtual CISO subscription.

Start here

Which problem is yours?

The work is different depending on who the target is. Pick the one that describes your week.

An organization to defend

You own security for a company, or you are the executive who inherited it. You need to know where you actually stand, in what order to fix it, and how to answer the board, the auditor, or the customer asking for your security posture.

See engagements for organizations →

A person, and the people around them

You are an executive visible enough to be worth targeting personally, or a family office responsible for principals and their households. Names, devices, voices, and family members are all in scope for an attacker, and none of it is covered by what the company bought.

See engagements for executives and family offices →

Track one

For organizations

Senior security judgment, without the headcount and without a twelve-week discovery phase.

What you can hire me to do

Virtual CISO Subscription

Monthly subscription, three-month minimum

  • Your security program owned by someone who has run one, without a full-time executive hire
  • Also sold elsewhere as a fractional CISO or vCISO, at a flat monthly fee instead of an hourly draw
  • A roadmap and a budget you can defend to the people who approve it
  • Tool and vendor decisions made once, correctly, instead of by demo fatigue
  • The security questions from boards, insurers, and enterprise customers, answered

The seat is covered by someone who has sat in it, month after month, for less than the seat costs.

One-Week Security Assessment

Five working days, report included

  • Current-state review of your security program, controls, and environment
  • Prioritized gap analysis, ordered by real risk rather than by framework line item
  • A written report you can hand to a board, an auditor, or a customer
  • A live readout with your team, so the findings land with the people who own them

You end the week knowing what to fix, in what order, and what it buys you.

Track two

For executives and family offices

The company bought protection for the company. Nobody bought it for the principal, their household, or the people around them. That is where attackers go now.

What you can hire me to do

Executive Exposure Report

One engagement, one report

  • What an attacker can already assemble about you and your household from public and broker data
  • The accounts, devices, and people around you that would be hit first, and why
  • A deepfake and voice-cloning playbook, including a family verification phrase that actually works under pressure
  • A prioritized removal and hardening plan, written for a human rather than an analyst

You see yourself the way someone targeting you already does.

Family Office Program

Multiple principals, one accountability

  • An Executive Exposure Report for each principal the office is responsible for
  • Guided remediation, gap by gap, until each one is verified closed rather than assumed closed
  • Remi deployed across the households, so the work continues after the engagement ends
  • One point of contact and one view of where every household actually stands

The office can answer the question it currently cannot: are our families secure, and how do we know.

An individual family, not a family office? You want the app, not an engagement. Remi walks your household through the same fixes →

Something else entirely?

These are the engagements that come up most, not the limit of the work. Diligence on an acquisition, a security program built from nothing, a board that needs to be brought up to speed, a threat nobody has a playbook for yet. Bring the problem and it gets scoped honestly, including when the honest answer is that you do not need me.

Describe your problem →

The terms

How engagements work

Set before anything starts, so the work is about the problem instead of the invoice.

Fixed scope, or a monthly subscription

Project work is quoted as a whole after a short call. Ongoing work runs as a virtual CISO subscription at a flat monthly fee, so the cost is predictable and so is the coverage. Either way, no hourly billing and no meter running on a phone call.

A report and a readout, always

Project work produces something written that outlives the conversation, and a live session where the people who have to act on it can argue with it. Subscriptions report on a standing cadence.

Scoped on a 30-minute call

One call to understand the problem and what is already in place. You get the scope and the quote in writing after it, not a proposal built to be negotiated down.

A small number at a time

These engagements are delivered personally, so only a few run concurrently. Timing is committed once an engagement is signed, never guessed at beforehand.

Scope is what drives a quote, so it is worth knowing what moves it: the size of the organization, the complexity of the environment, the regulatory and contractual scope you have to satisfy, and for family office work, how many principals and households are covered. Two engagements with the same name can be very different pieces of work, which is why the number comes after the call and not before it.

Who you are hiring

One person, and thirty years of it

Corey White is the founder of Cythentic. He has spent more than thirty years in cybersecurity, protecting Fortune 500 institutions, governments, and critical infrastructure, and has held senior consulting and executive roles building and running security services organizations at scale. At Cylance he built ThreatZERO, the delivery model behind one of the first AI-driven endpoint protection companies.

He previously founded, scaled, and sold a managed cybersecurity company with zero reported major customer breaches across seven years, protecting more than 200 organizations. He is the author of the forthcoming book You’re Already a Target, and he built Remi, the guided remediation product that grew out of the same work.

Engagements are delivered by Corey. Not by a team you meet once during the pitch and never see again.

  • 30+ years in cybersecurity
  • Built ThreatZERO at Cylance
  • SANS Summit Talk of the Year, 2024
  • RSA Conference, 2021
  • Inc. 5000 honoree
  • LA Times CEO of the Year finalist, 2025
  • Octane CEO of the Year finalist, 2025
  • Tampa Bay Wave Hall of Fame
  • ICIC Year of Innovation
  • 50+ media appearances
  • Author, You’re Already a Target

Start with the call.

Thirty minutes, no charge, and you leave it knowing whether there is an engagement here or not.

Not ready for an engagement? Remi, our product, scores your personal security and walks you through the fixes →