Security that holds up to attackers, auditors and assessors.
Since 2002, Security Best Practices has helped organizations harden their networks, meet CMMC, SOC 2, HIPAA and PCI DSS requirements, and respond decisively when incidents happen. You work directly with a senior, CISSP-certified consultant.
Cybersecurity services for organizations that can't afford to get it wrong
Four practice areas, delivered by the same experienced team from first assessment through remediation and ongoing support.
Compliance & Audit Readiness
Gap assessments, remediation roadmaps and evidence preparation so you pass your audit or certification the first time.
CMMC 2.0 Level 1 & Level 2 readiness
NIST SP 800-171 & SPRS scoring
SOC 2 Type I & Type II preparation
HIPAA Security Rule risk analysis
PCI DSS 4.0 & ISO/IEC 27001 readiness
Network & Firewall Security
Design, hardening and day-to-day support for the infrastructure that keeps attackers out and your users productive.
Next-generation firewall design & support
Zero Trust architecture & ZTNA
SASE & secure remote access (VPN)
Network segmentation & microsegmentation
Firewall rule reviews & configuration audits
vCISO & Risk Management
Senior security leadership on a fractional basis: strategy, policy and governance without a full-time executive hire.
Virtual CISO / fractional CISO
Cybersecurity risk assessments
Security policy development & review
Third-party & vendor risk management
Board & executive reporting
Incident Response & Testing
Find the weaknesses before attackers do, and be ready with a tested plan if the worst happens.
Ransomware readiness & response
Incident response planning
Tabletop exercises
Vulnerability assessments
Penetration testing
Compliance frameworks
Current standards, practical guidance
Regulations and frameworks keep changing. We track the latest versions and translate them into controls your team can actually operate.
CMMC 2.0
Cybersecurity Maturity Model Certification for Department of Defense contractors handling FCI and CUI.
NIST CSF 2.0
The updated Cybersecurity Framework, including the new Govern function for risk ownership and oversight.
NIST SP 800-171
The 110 security requirements for protecting Controlled Unclassified Information in non-federal systems.
SOC 2
AICPA Trust Services Criteria for service organizations, covering both Type I and Type II reports.
HIPAA
Security Rule risk analysis and safeguards for covered entities and business associates handling ePHI.
PCI DSS 4.0
Payment Card Industry Data Security Standard v4.0.1, including the now-mandatory future-dated requirements.
ISO/IEC 27001:2022
The international standard for an information security management system (ISMS) and its updated Annex A controls.
SEC Cyber Disclosure
Governance, risk management and material-incident disclosure requirements for public companies.
How we work
A clear path from assessment to assurance
01
Assess
Understand your environment, obligations and risk, and measure where you stand today.
02
Prioritize
Deliver a practical roadmap ranked by risk reduction and audit impact, not vendor wish lists.
03
Remediate
Implement controls, configurations and policies hands-on, alongside your team.
04
Validate & sustain
Test, document evidence and keep you compliant as threats and standards evolve.
About us
Senior expertise. Direct access. No hand-offs.
Security Best Practices, Inc. was founded in 2002 by Keith W. Salustro, CISSP®, a senior network security consultant with more than 25 years of specialized experience. A graduate of Brown University's engineering program, Keith has designed and supported security infrastructure for global banks, healthcare organizations, law firms and growing businesses, conducted security and compliance assessments, and spoken widely on information security.
Clients choose us because they work directly with an experienced practitioner who has seen what works in the real world and who explains risk in plain business terms.
Vendor-neutral advice. We recommend what fits your risk and budget, not what earns a commission.
Hands-on delivery. We don't just write the report. We help implement the fixes.
Regulated-industry experience. Finance, healthcare, legal and life sciences.
Right-sized engagements. From a single assessment to an ongoing vCISO partnership.
AI agents don't just answer questions. They read your email, call APIs and take actions with real credentials. Here are the new risks, what the latest OWASP and NIST guidance says, and a practical checklist for governing agents safely.
From 600+ firewalls breached with nothing more than weak passwords to VPN zero-days exploited by ransomware crews, 2026 has shown that edge devices are attackers' favorite way in. Here's how to harden yours.
On November 10, 2026, third-party CMMC Level 2 certification becomes a condition of award for many DoD contracts involving CUI. Here's what changes, who is affected, and a practical readiness checklist.
Whether you're facing an upcoming audit, a CMMC deadline, a firewall project or a security incident, tell us what's going on. We'll respond within one business day.
Free initial consultation
Confidential, no obligation
Clear scope and fixed-fee options
Thank you!
Your message has been sent. We'll be in touch shortly.