Fractional CISO · Compliance · AI Security

Fractional CISO, compliance, and AI security for the regulated mid-market.

RedOps Cyber Intelligence Group secures regulated mid-market firms across the full enterprise AI security lifecycle — governance, risk, model defense, and adversarial testing. Fractional CISO leadership and compliance delivery across NYDFS §500, SOC 2, ISO 27001, HIPAA, and NIST AI RMF.

Frameworks
NYDFS 23 NYCRR §500 SOC 2 Type II ISO 27001 NIST AI RMF ISO 42001 HIPAA MITRE ATLAS
On the regulatory clock

AI oversight is now calendar-driven. A few of the forcing functions shaping 2026.

days
Colorado Reg 10-1-1 — insurer AI compliance report due
days
EU AI Act — high-risk obligations apply
days
NYDFS — AI guidance for covered entities
01 — Who we serve

Built for regulated firms where AI risk now reaches the board.

RedOps serves mid-market organizations — typically 100 to 2,000 employees — where adopting AI has outpaced the governance, evidence, and board reporting their regulators and enterprise customers now expect.

01

Insurance

NYDFS- and NAIC-regulated carriers facing AI underwriting oversight and board reporting obligations.

02

Fintech

Regulated payments and lending firms answering enterprise and cross-border AI security review.

03

Healthcare

HIPAA-covered organizations bringing AI into clinical, operational, and member-facing workflows.

04

Regulated SaaS

Platform companies whose buyers now send AI security questionnaires alongside SOC 2.

02 — The approach

One lifecycle, four disciplines.

Most security functions can answer questions about the network. Far fewer can answer the board's questions about AI. RedOps covers the full lifecycle — so governance, risk, defense, and testing reinforce one another instead of living in silos.

01

Governance

AI inventory, model risk policy, and board-ready oversight aligned to NIST AI RMF and ISO 42001.

02

Risk

A maintained model risk register and third-party AI diligence that hold up to examination.

03

Model Defense

Controls for prompt injection, data poisoning, and AI-specific incidents, mapped to MITRE ATLAS.

04

Adversarial Testing

AI-augmented offensive testing that validates the program against how attackers actually operate.

03 — Services

Five named engagements, not open-ended hours.

Each engagement is scoped to a clear deliverable and a defined outcome — so you know exactly what you are buying and what lands on the board's desk.

01Fixed-fee engagement

NYDFS §500 Compliance

A productized annual certification lifecycle for NY-regulated insurers and fintechs: evidence repository buildout, BEC and ransomware tabletop exercise, and board reporting.

DeliverableAnnual certification filing, evidence repository, and tabletop readout.
02From $7,500 / month

AI Security Posture Management

The flagship retainer. A governance baseline, maintained AI inventory and model risk register, NIST AI RMF and ISO 42001 alignment, and a quarterly posture review for the board.

DeliverableQuarterly AI posture report to the board or audit committee.
03By engagement

Pentest-as-a-Service

Continuous, AI-augmented penetration testing on a defined cadence, with structured reporting and remediation tracking — modern coverage at mid-market economics.

DeliverableRecurring pentest report with a remediation tracking dashboard.
04Starts at $35K

AI Governance Readiness

A fixed-scope, six-to-eight-week entry engagement: AI use-case inventory, NIST AI RMF and ISO 42001 gap analysis, a model risk policy stack, and a board-ready governance memo with a 90-day roadmap.

DeliverableReadiness assessment, policy stack, and board memo.
05By engagement

AI Social Engineering Detection & Training

A behavioral threat-intelligence baseline, GenAI social-engineering simulation campaigns, a staff training program, and a detection pattern library — grounded in current research.

DeliverableSimulation program, training curriculum, and detection playbook.
Find your starting point

What's driving the search?

Pick the closest. We'll point you to the right entry engagement.

Recommended starting point Discuss this →
04 — Leadership

Security leadership the board can put its name behind.

Dr. Sam Wertheim, Founder and Principal
Founder & Principal

Dr. Sam Wertheim

0+
Years in security leadership
Top 1%
Expert-Vetted CISO

D.Cybersecurity, Capella University — research in GenAI social engineering and behavioral threat intelligence. Practice based in Long Island, NY, serving the NY metro and remote.

RedOps was built on a simple observation: across regulated mid-market firms, boards are now asking AI risk questions their security functions can't yet answer. Examiners expect AI to appear in board reporting. Enterprise buyers send AI security questionnaires alongside SOC 2. The gap between AI adoption and AI governance has become a business risk.

RedOps closes that gap. We provide fractional CISO leadership and productized AI security engagements that produce examination-ready evidence and board-ready reporting — not slideware. The work is grounded in regulated-vertical pattern recognition, from an NYDFS-regulated insurance carrier to an identity software vendor answering enterprise security review.

The differentiator is range: governance, risk, model defense, and adversarial testing under one accountable principal — informed by doctoral research into how AI changes the threat landscape, and an AI-augmented testing capability that validates the program against real adversary behavior.

05 — Benchmark

How ready is your AI security program?

Five quick questions. You'll get a posture snapshot across the dimensions boards and regulators now ask about — and where to focus first.

Your snapshot
Answer the five to see your snapshot

07 — Questions

Common questions.

A traditional fractional CISO covers general security leadership. RedOps adds depth where most can't — AI governance, model risk, and adversarial testing — producing examination-ready evidence and board reporting on AI specifically, alongside the core CISO role.
No. RedOps works alongside your internal team and managed providers — setting direction, owning the governance program, and translating technical risk into terms your board and regulators understand.
Fixed-scope engagements like AI Governance Readiness typically begin within one to two weeks of a signed scope and run six to eight weeks. Retainers open with an onboarding and baseline assessment in the first month.
NYDFS 23 NYCRR §500, SOC 2, ISO 27001, HIPAA, NIST AI RMF, ISO 42001, and MITRE ATLAS for AI-specific threats — mapped to the obligations that apply to your vertical.
Defensible artifacts: an AI inventory and model risk register, a governance memo mapped to the rules that apply to you, and — on retainer — a quarterly posture report written for directors and audit committees, not engineers.
08 — Get in touch

Your board will ask about AI in 2026. Be ready with an answer.

Start with a short scoping conversation. We'll map your AI footprint and regulatory exposure, then recommend the right entry point — no obligation.

Request a consultation →
Location
Long Island, NY · NY metro & remote