Independent since 2014.
Black Bay Security is an independent cybersecurity advisory firm. We help companies understand their current risk, design a stronger future-state security program, and provide ongoing executive guidance to implement it effectively.
Four commitments we can be held to.
Proactive, not reactive
We identify and mitigate risk using current security and AI strategy, before it becomes an incident report.
Tailored, not templated
Solutions informed by current industry trends and your actual environment, not a reference architecture from a vendor deck.
Trust as an outcome
Compliance expertise that builds stakeholder confidence, with customers, insurers, auditors and the board.
Aligned to the business
Cybersecurity practice integrated with business objectives, because a program nobody funds is not a program.
We are paid to be right, not to move product.
Most security "advice" arrives attached to a catalog. Black Bay holds no reseller agreements and takes no commissions, which changes what we are able to tell you: sometimes the answer is that the tool you already own is sufficient, and the gap is in process.
- No reseller agreements, no product commissions
- Advisors carry 30+ years of experience before assignment
- Every recommendation traces to a business risk you named
- You keep the assessment output whether or not you engage us
2014
Managing security programs for organizations across the United States.
137 years
Combined cybersecurity experience across the advisory bench.
300+
COMPASS security assessments completed to date.
deepcurrent
Our own GRC platform, included with every program.
The people you will actually work with.
You are assigned a named advisor, not a rotating bench.

Dan Schuyler, Co-Founder, vCISO
Security Leader | Strategic vCISO | AI Security, Governance & Risk | Helping Leaders Turn Cybersecurity into Business Confidence
LinkedIn
Scott Cowan, VP of Sales
Technology Sales and Sales Management | Financial Vertical Expert | Leadership | Cybersecurity Advisor and Business Alignment
LinkedIn
Todd Neilson, Principle Advisor
AI-Native Security Leader, Client vCISO | Co-Founder and Global Practice Builder | Keynote Speaker
LinkedInTrusted by security and executive teams since 2014
About the firm.
What does "independent" mean in practice?
We hold no reseller agreements, take no product commissions, and have no channel targets. When we recommend a control, we have no financial interest in which vendor delivers it.
How experienced are your advisors?
Every vCISO brings more than 30 years of industry experience before being assigned to a client engagement. Across the team that is 137 combined years of security experience.
How long has Black Bay been doing this?
Since 2014, with 100+ managed security clients and 300+ COMPASS assessments completed.
Where are you based?
Salt Lake City, Utah, serving clients across the United States.
Start with a conversation.
Get your first no-cost advisory call, a demo of deepcurrent, or an honest answer to a question you have been carrying around.
No cost. No obligation. No vendor pitch. We don't resell anything.