About
Experienced cybersecurity expertise. Direct client engagement. Practical results.
Craft Consulting Solutions is a consulting practice built around senior delivery: the person who scopes your engagement is the person who performs the work and presents the findings.
The Practice
Established expertise. Independent since 2018.
Craft Consulting Solutions has operated as an independent cybersecurity practice since 2018, backed by senior experience that reaches back well before that. It exists to deliver the kind of security work that tends to get diluted inside larger organizations: senior people doing the technical work themselves, writing the report themselves, and sitting in the debrief to defend the findings.
That structure has practical consequences. Scoping conversations are technical from the first call. Engagements do not get handed down to whoever is available. When you have a question about a finding six weeks later, you are asking the person who found it.
What we will not claim. No assessment identifies every vulnerability, and no engagement makes an organization secure. Security testing reduces uncertainty and directs effort. That is a genuinely valuable outcome, and it is the one we sell.
Background
Offensive security and security leadership in the same practice
The founder of Craft Consulting Solutions is an experienced cybersecurity practitioner and consultant with substantial professional experience across both hands-on technical testing and senior security leadership. Those two skill sets are usually found in different people, and the combination is what shapes how we deliver work.
Technical security experience
- Penetration testing
- Vulnerability assessments
- Web application testing
- Red team engagements
- Social engineering
- Wireless assessments
- Incident response
- Digital forensics
Program and leadership experience
- Security program assessments
- CIS assessments
- Security governance
- Security strategy
- Risk management
- Security roadmaps
- Executive cybersecurity leadership
Certifications
-
CISSP — Certified Information Systems Security Professional
-
GCFE — GIAC Certified Forensic Examiner
-
GSEC — GIAC Security Essentials
-
GPEN — GIAC Penetration Tester
Education
-
Master of Liberal Arts (ALM), Information Management Systems
-
Graduate Certificate in Cybersecurity
Training
Technical training
Course work completed with the providers below. These are training courses, not certifications; the certifications held are listed above.
SANS Institute
- SEC660 - Advanced Penetration Testing, Exploit Writing and Ethical Hacking
- SEC560 - Network Penetration Testing and Ethical Hacking
- SEC504 - Hacker Techniques, Exploits and Incident Handling
- FOR408 - Computer Forensic Investigations
- MGT414 - Information Security Professional
- SEC401 - Security Essentials
- SEC305 - Technical Writing and Presentation Skills for Security Professionals
Offensive Security
- OSCP - Penetration Testing with Kali Linux (course)
- WEB-200 - Foundational Web Application Assessments with Kali Linux (course)
- WEB-300 - Advanced Web Attacks and Exploitation (course)
- OWASP Top 10:2025
ISC2
- Cloud Computing Security
HP Enterprise Security
- ArcSight Masters Series, ArcSight University
- Fortify Software Security Assurance Solutions
- TippingPoint Advanced Technical Security Products
Palo Alto Networks
- CNSE Bootcamp
- Accredited Systems Engineer (ASE)
- PAN-201 Networks Essentials
- PAN-101 Firewall Essentials
Other vendor training
- Darktrace Engineer Training
- Trend Micro Deep Security
- VMware VSP 5.5
How We Work
The advantage of working directly with the consultant
No handoff
The person who scopes the engagement performs the testing and writes the report. Context does not get lost between a sales conversation and a delivery team.
Direct answers
Technical questions get technical answers during the engagement, not after a round trip through an account manager.
Proportionate process
Enough structure to run an engagement properly, without the overhead a larger firm has to charge for regardless of engagement size.
Findings written for humans
Reports are authored, not generated. Every finding includes why it matters here, in this environment, rather than a generic description of the vulnerability class.
Independent recommendations
We do not resell security products. Recommendations follow from your risk and requirements, and sometimes the recommendation is to buy nothing.
Right-sized engagements
Small organizations are welcome. A focused engagement that answers one important question is often the right place to start.
Location & Reach
Remote delivery, nationwide reach
Craft Consulting Solutions, LLC is an Idaho company. Local relationships matter to us, and we are glad to meet in person with organizations in the Boise area and across the state.
The addressable work is not limited to Idaho. Nearly all services, including internal network penetration testing, are delivered remotely, and clients throughout the United States are served the same way. On-site delivery is available where an engagement genuinely requires it.
Talk with a security consultant
The fastest way to find out whether we are a fit is a short conversation about what you are trying to accomplish.