Advise. Build. Optimize.
Your time and resources are limited – you need partnership more than vendors. That is where we step in. Providing advisory services helps your decision making. Providing a wealth of experience helps ensure you build a solid, functional security program. Providing proven methods and tools helps you optimize the resources you already own.
Startups
Looking to serve customers in a regulated industry?
Launch your cybersecurity journey with confidence. We take startups from zero security resources to winning deals by demonstrating your Industry-specific expertise and provide secure operational support.
SMBs
Working with limited or outsourced IT staff?
Cybersecurity made simple for SMBs. We pinpoint your current gaps, design a tailored cybersecurity program, implement, and manage it for you so you can focus on growing your business securely.
Large Enterprises
Needing an interim CISO/CSO or Advisor?
Bridge your cybersecurity leadership gap seamlessly. Our expert team keeps the organization running and assesses people, process, and technology to prepare your next cybersecurity leader for immediate impact.
CISO Horizon
We bring experienced and certified professionals to your project.
We make no assumptions about your organization or your environment.
We make you feel like we are part of your internal team by partnering with a focus on communication.
We start with what you have already built, make it more resilient, and implement new solutions to fill gaps.


Critical Infrastructure Sectors Served
Financial Services/Industries
Insurance
Healthcare and Public Health
Technology
Defense Industrial Base
Energy
Information Technology
Government Services and Facilities
Implementation Expertise
AICPA Service Organization Control – Trust Services Criteria (TSC) SOC2
Systems Development – Building Security In Maturity Model (BSIMM)
CIS Critical Security Controls (CSC)
CSA Cloud Controls Matrix (CCM)
Cybersecurity Compliance and Risk Assessment (CCRA)
Cybersecurity Maturity Model Certification (CMMC)
ISO 23053 – Framework for Artificial Intelligence (AI) Systems Using Machine Learning (ML)
ISO 27001 – Information Security Management Systems (ISMS)
ISO 27018 – Code of Practice for PI in Public Clouds Acting as PI Processors
ISO 42001 – AI Management systems and assessments
ISO 31000 – Risk Management
FAIR (Factor Analysis of Information Risk) Quantitative Risk assessment
NIST Privacy Framework
NIST SP 800-53 – Security and Privacy Controls for Information Systems and Organizations
NIST SP 800-171 – Protecting CUI in Nonfederal Systems and Organizations
NIST Cybersecurity Framework (CSF)
PCI SSC Payment Card Industry Data Security Standard (PCI DSS)
PCI Self-Assessment Questionnaire (SAQ)
US States Privacy Law Compliance

“CISO Horizon helped to jumpstart Quome’s security initiatives and create a culture for security day 1 of our business. As a cloud provider, Ben and his team have created a solid multi-year roadmap/budget on how to not only help us achieve SOC 2/HITRUST/ISO27001 compliance, but even pioneered a new shared responsibility model that will greatly help the thousands of digital health companies that need to get through HIPAA compliance initiatives to achieve revenue growth. Beyond this, Ben and the CISO Horizon team are a joy to work with and are a great add to any team.”
Jim Schwoebel, Co-Founder/CEO, Quome
We look forward to hearing from you!
Privacy Policy