About

Experienced cybersecurity expertise. Direct client engagement. Practical results.

Craft Consulting Solutions is a consulting practice built around senior delivery: the person who scopes your engagement is the person who performs the work and presents the findings.

The Practice

Established expertise. Independent since 2018.

Craft Consulting Solutions has operated as an independent cybersecurity practice since 2018, backed by senior experience that reaches back well before that. It exists to deliver the kind of security work that tends to get diluted inside larger organizations: senior people doing the technical work themselves, writing the report themselves, and sitting in the debrief to defend the findings.

That structure has practical consequences. Scoping conversations are technical from the first call. Engagements do not get handed down to whoever is available. When you have a question about a finding six weeks later, you are asking the person who found it.

What we will not claim. No assessment identifies every vulnerability, and no engagement makes an organization secure. Security testing reduces uncertainty and directs effort. That is a genuinely valuable outcome, and it is the one we sell.

Background

Offensive security and security leadership in the same practice

The founder of Craft Consulting Solutions is an experienced cybersecurity practitioner and consultant with substantial professional experience across both hands-on technical testing and senior security leadership. Those two skill sets are usually found in different people, and the combination is what shapes how we deliver work.

Technical security experience

  • Penetration testing
  • Vulnerability assessments
  • Web application testing
  • Red team engagements
  • Social engineering
  • Wireless assessments
  • Incident response
  • Digital forensics

Program and leadership experience

  • Security program assessments
  • CIS assessments
  • Security governance
  • Security strategy
  • Risk management
  • Security roadmaps
  • Executive cybersecurity leadership

Certifications

  • CISSP badge CISSP — Certified Information Systems Security Professional ISC2 · Issued 2017 · Valid through 2027
  • GCFE badge GCFE — GIAC Certified Forensic Examiner GIAC · Issued 2012 · Valid through 2028
  • GSEC badge GSEC — GIAC Security Essentials GIAC · Issued 2010 · Valid through 2030
  • GPEN badge GPEN — GIAC Penetration Tester GIAC · Issued 2010 · Valid through 2030

Education

  • Harvard University logo Master of Liberal Arts (ALM), Information Management Systems Harvard University · 2024
  • Harvard Extension School logo Graduate Certificate in Cybersecurity Harvard Extension School · 2022

Training

Technical training

Course work completed with the providers below. These are training courses, not certifications; the certifications held are listed above.

SANS Institute

  • SEC660 - Advanced Penetration Testing, Exploit Writing and Ethical Hacking
  • SEC560 - Network Penetration Testing and Ethical Hacking
  • SEC504 - Hacker Techniques, Exploits and Incident Handling
  • FOR408 - Computer Forensic Investigations
  • MGT414 - Information Security Professional
  • SEC401 - Security Essentials
  • SEC305 - Technical Writing and Presentation Skills for Security Professionals

Offensive Security

  • OSCP - Penetration Testing with Kali Linux (course)
  • WEB-200 - Foundational Web Application Assessments with Kali Linux (course)
  • WEB-300 - Advanced Web Attacks and Exploitation (course)
  • OWASP Top 10:2025

ISC2

  • Cloud Computing Security

HP Enterprise Security

  • ArcSight Masters Series, ArcSight University
  • Fortify Software Security Assurance Solutions
  • TippingPoint Advanced Technical Security Products

Palo Alto Networks

  • CNSE Bootcamp
  • Accredited Systems Engineer (ASE)
  • PAN-201 Networks Essentials
  • PAN-101 Firewall Essentials

Other vendor training

  • Darktrace Engineer Training
  • Trend Micro Deep Security
  • VMware VSP 5.5

How We Work

The advantage of working directly with the consultant

No handoff

The person who scopes the engagement performs the testing and writes the report. Context does not get lost between a sales conversation and a delivery team.

Direct answers

Technical questions get technical answers during the engagement, not after a round trip through an account manager.

Proportionate process

Enough structure to run an engagement properly, without the overhead a larger firm has to charge for regardless of engagement size.

Findings written for humans

Reports are authored, not generated. Every finding includes why it matters here, in this environment, rather than a generic description of the vulnerability class.

Independent recommendations

We do not resell security products. Recommendations follow from your risk and requirements, and sometimes the recommendation is to buy nothing.

Right-sized engagements

Small organizations are welcome. A focused engagement that answers one important question is often the right place to start.

Location & Reach

Remote delivery, nationwide reach

Craft Consulting Solutions, LLC is an Idaho company. Local relationships matter to us, and we are glad to meet in person with organizations in the Boise area and across the state.

The addressable work is not limited to Idaho. Nearly all services, including internal network penetration testing, are delivered remotely, and clients throughout the United States are served the same way. On-site delivery is available where an engagement genuinely requires it.

Start a conversation

Talk with a security consultant

The fastest way to find out whether we are a fit is a short conversation about what you are trying to accomplish.