Your security person, long term.
I'm Sam Lyhin, founder of LSCP LLC. An advisory year works the way a good security hire works: one annual budget, paid monthly like a salary – and behind it, one person who owns your security questions all year. From "what do you make of this vendor?" to "I think my people are leaking to a competitor – take a look." The shape is the closest thing to a long-term security hire, without the headcount line.
Ask the first question
How the year works
- One budget, in writing, paid monthly. Agreed once for the year, paid in twelve parts like a salary line. This pre-allocated budget covers projects to be delivered during the year.
- Any question, all year. A vendor to judge, an architecture to walk, a second opinion on another firm's report, a strange feeling about what's leaving your network. Small and big questions welcome.
The logic is deliberately simple: here is the year's budget – and here is all the work a security person is supposed to cover, with one line in your books and no surprise invoices.
What lands on the seat
Decisions
A call before a vendor is chosen, a technical check before a deal, a second opinion on the pentest report another firm delivered, a quiet read of "how bad is this?" – and yes, "look at what my own people are doing" belongs here too.
Architecture
Walkthroughs of what you're about to build – web, mobile, API, cloud, Active Directory, cryptography including post-quantum. Findings arrive as recommendations your team can implement.
The budget at work
Pre-allocation of budget means that the budget actually gets spent over the year – with more in-context Penetration Testing, and less surprising Incident Response.
What could be budgeted
| Ask for | Already delivered |
|---|---|
| Web application pentest | A decade of full-cycle testing, from scoping to exploitation and remediation validation; OSWE-backed white-box depth. |
| Mobile application pentest (iOS / Android) | App and binary testing including reverse engineering, mapped to OWASP MASTG / MASVS; GMOB. |
| API pentest | OWASP API Top 10, a standard part of full-cycle engagements. |
| Network, Active Directory & infrastructure | Large enterprise networks with BloodHound attack-path mapping and AV/IDS/IPS evasion; an engagement inside one of Europe's largest telecom providers. |
| Cloud pentest (AWS / Azure / GCP) | All three major platforms, in client engagements. |
| Secure source-code review | Java, Python, Go, Node.js, PHP, .NET, Erlang; two half-year review engagements on a national healthcare system, plus many smaller ones. |
| Enterprise PKI & cryptography assessment | A production post-quantum rollout delivered – ML-DSA (FIPS 204), design advisory plus post-implementation audit; two penetration-testing engagements for a central-bank-grade financial regulator; a B.S. in Applied Cryptology. |
| Red team / adversary emulation | Emulation mapped to MITRE ATT&CK; built and ran a Big-4 offensive security practice – 10+ testers, ~200 engagements a year. |
| AI / ML red teaming | Application-layer testing mapped to MITRE ATLAS – prompt injection, model evasion – on production ML-powered platforms. |
| Real-time communications (WebRTC / VoIP) | Original WebRTC Top-10 research, presented at OWASP Columbus – recorded. |
| IoT / hardware device testing | Hands-on device work; technical mentor at an IoT Village CTF. |
| Configuration review | CIS Benchmarks up to DoD STIG level, under NIST 800-37. |
| Phishing & social engineering | Campaigns designed and run inside long-term client engagements. |
| Incident response | End-to-end casework: DarkGate malware, business email compromise, a production platform incident. |
| Exploit & vulnerability research | 12+ CVEs, published 0-day write-ups, the "MakeSense" Hack The Box machine, OffSec lab content – the Responsible Disclosure Lab. |
Not a whole year yet?
You can still ask a question and I'll try my best to respond. But to give a deeply validated answer, I need to be in the context of your system. The annual budget is the best way to organize the understanding of this context.
Ask a questionMeanwhile, keep growing your own cybersecurity awareness:
- For tactical growth – The Security Spirit® daily video series
- For strategic, evergreen cybersecurity topics – EXP Lore Cyber® irregular podcast
- For ongoing Threat Intelligence trends – The LSCP Newsletter, monthly
- For technical hands-on skills – The Responsible Disclosure Lab (RSS feed)
Email: mail@lscp.llc · LSCP LLC – Dublin, Ohio.