Skip to content
Papa Corporation

A standing specialty, not an add-on

The security discipline of a large company, sized for a team without one.

Seven years in enterprise cybersecurity, where a single miss takes the whole company down, brought to a team your size. It is not one service. Take the whole function or just the part you are missing.
Security audit5 fixes, ranked
#FindingDue
  • 01Critical priorityMFA not enforced on 6 admin accountsFix now
  • 02High priorityLegacy mail protocol (IMAP) still enabledThis week
  • 03High priorityForwarding rules to outside addressesThis week
  • 04Medium priorityOver-privileged service accountThis month
  • 05Medium priorityDMARC not enforced (policy p=none)This month
Ranked by priorityA short list you can act on, not a 200-page report
IllustrativeAn audit delivered as a ranked punch list, each item with a clear next action.
  • Email and account security: a continuous audit of Gmail and Microsoft 365
  • Threat detection and response, acting before a break-in spreads
  • Incident response: you reach me within 30 minutes on your worst day
  • Security audits: a short list of fixes ranked by priority, not a 200-page report
  • Compliance readiness: the audit your customers ask for (SOC 2) and a contract requires (CMMC)
  • Identity and access hardening: multi-factor, least privilege, locked-down accounts

The seat behind the service

Seven years triaging real attacks, before advising anyone on how to stop them.

This did not start with a slide deck. It started in an enterprise security operations center: seven years working up from SOC analyst to senior analyst, triaging alerts across the stack, writing the detections that catch what the stack misses, and owning incidents end to end. You get an operator who has answered the alert at 2 a.m., not a vendor reading from a datasheet.

Detection engineering

Custom detections written in Microsoft Sentinel (KQL): Azure AD device-registration correlation, an AI and LLM consumption anomaly detector, Snowflake brute-force, and AWS suspicious activity. Response automated with Torq SOAR playbooks.

Incident response

Incidents owned start to finish, from a live PHP web shell to the seven-page briefing that translated it for leadership. The technical work, and the version the board can actually read.

The stack, in production

Cortex XDR, Microsoft Defender, Sentinel, Entra ID, and Intune, plus Proofpoint, Palo Alto, Rapid7, and Critical Start MDR, built on with Python and PowerShell.

Proof

Forty-seven hidden forwarding rules, found in one sweep.

An industrial distributor had no view into its 200-plus mailboxes. A mailbox audit surfaced 47 hidden forwarding rules in the first pass. One had been copying invoices and signed contracts to an outside address for the better part of a year. On another engagement, a network audit found a camera server quietly calling home to an address overseas. The line was cut the same day. And for a defense manufacturer, a filable CMMC Level 1 package came together in weeks, not quarters.

Start the hour

Let's talk

Tell me what your team does by hand, or what you want to build.