Choose a system in the room. Every highlighted object is interactive.
Cyber Security
Read page details
Cyber Security
Detect, protect, respond — with a named person reading the results and writing down what should change.
Cyber Security here means four things done for organizations that do not have a security person of their own: a review a human reads and writes up, monitoring that a human reads on a schedule, an incident response plan written for your organization and rehearsed once, and infrastructure protection that is documented item by item.
Every part of the room links to the matching section below. Nothing on this page is a certification, a guarantee, or a claim of round-the-clock coverage; those are stated per engagement, in writing, when they are true.
Security monitoring overview
The threat map and the 100% readout in the room are illustration. Monitoring in practice is scoped to what you run and reported in plain language on an agreed schedule.
Security review and system health
A person reads the configuration, the exposure and the logs, and writes down what should change and why.
Incident response planning
Who is called, what is isolated, what is preserved, who is told — decided before an incident, rehearsed once.
Infrastructure protection
Patching, segmentation, backups that restore, and access that is granted on purpose.
Security review process
Scope, collect, read, report, remediate, re-check.
The problem this solves
Most small organizations and local government offices do not have a security person. They have a laptop fleet, a few servers or cloud accounts, a website, email, and vendors — and nobody whose job is to read the logs, check the configuration, or decide in advance what happens when something goes wrong. The exposure is ordinary: reused passwords, unpatched systems, backups that were never restored, and no plan for the day an account is compromised.
Who it is for
- City, county and district offices that run their own IT with a small staff or a contractor
- Prime contractors that need a subcontractor to cover the security work on a delivery
- Small and medium businesses with 5 to 250 people and no in-house security role
What is included
- Security review: configuration, exposure and access read by a person, across the systems you name in scope
- Monitoring set-up on the systems you already run, with results read and explained in plain language on an agreed schedule
- Incident response plan: who is called, what is isolated, what is preserved, who is told — written for your organization and rehearsed once
- Infrastructure protection: patching cadence, network segmentation, backups that are restore-tested, access granted on purpose and documented
What you receive
- A written security review with findings ordered by what to fix first, and why
- A monitoring summary you can read without a technical background, on the agreed schedule
- An incident response plan document plus one rehearsal record
- An infrastructure protection checklist with the current state of each item and its owner
- A remediation record: what changed, when, and how it was checked
Limits and exclusions
- Compliance certification or attestation of any kind — this work prepares you for a reviewer; it does not certify you
- 24/7 monitoring or guaranteed response times unless written into a specific engagement
- Penetration testing against systems you do not own or have not authorized in writing
- Handling of classified or controlled unclassified information; scope is agreed before any such material is discussed
- Legal advice on breach notification — the plan names when to call counsel, it does not replace counsel
How an engagement proceeds
- Scope. A written list of the systems, accounts and people in scope, and what is explicitly out of scope.
- Collect. Read-only access, configuration exports and logs, gathered with your staff present.
- Read. A person reads what was collected. Tools are used; conclusions are written by hand.
- Report. Findings ordered by risk, in plain language, with the evidence for each.
- Remediate. Agreed fixes are made or handed to your staff with instructions; each is checked afterwards.
- Re-check. A second look at the fixed items and a short written close-out.
What supports this
- ThatDeveloperGuy LLC has operated as a business since 2017.
- Founding date on the organization record. Supported by the organization record
- The organization operates 218 live websites for clients across its hosting.
- Live count of every candidate hostname on the organization record, 2026-09-12. Supported by the organization record
- The founder maintains a public professional record (ORCID, GitHub, published work).
- Person record with verified external identifiers. Supported by the organization record
- Named past security engagements and references.
- To be supplied and approved by the owner before publication. Not yet published — awaiting the owner
- Certifications, clearances or set-aside status.
- None are claimed. Shown only if and when issued and verified. Not yet published — awaiting the owner
Questions buyers ask
We are a small office with no IT person. Is a security review still worth it?
Yes, and it is the most common case. The review is scoped to what you actually run — usually a handful of laptops, email, a website and one or two cloud services — and the report is written so that whoever manages the office can act on it without a technical background.
Will this make us certified or compliant?
No. The work prepares you for a reviewer and produces the records a reviewer asks for, but ThatDeveloperGuy does not issue certifications or attestations. If a specific framework applies to you, that is written into the scope and the report maps findings to it.
Is the monitoring 24/7?
Not by default. Monitoring is set up on your systems and read by a person on an agreed schedule — daily, weekly, or as written into the engagement. Continuous coverage or guaranteed response times are only offered when they are written into a specific agreement.
What if we are having an incident right now?
Call the number in the footer. An active incident is handled as its own engagement with its own written scope; the incident response plan described here is preparation for next time, not emergency service.
What access do you need?
Read-only wherever possible, granted by you, with your staff present, and removed when the review ends. Anything that requires more than read access is listed in the scope before work starts.
Do you work with government offices and prime contractors?
Yes. Government organizations and prime contractors buy through a written requirement and need records that survive the project; the Government Solutions room describes that pathway. Procurement identifiers are shown on this site only once the owner has supplied and verified them.
What happens after the report?
The agreed fixes are either made by ThatDeveloperGuy or handed to your staff with step-by-step instructions, each fix is checked afterwards, and a short close-out records what changed.