ACCEPTING NEW ENGAGEMENTS EST. LOUISIANA · NATIONWIDE

Find what attackers would, before they do.

Independent penetration testing and security consulting for small businesses and industrial operations, by a working IT/OT security engineer. Based in Lafayette, Louisiana — available nationwide.

IT + OT experience Cyber Operations degree Bug bounty researcher
brennan@stjohncyber: ~
// live threat feed
88% of breaches at small businesses involved ransomware source: Verizon 2025 DBIR

Most breaches don't start with a genius exploit.

They start with something ordinary, a forgotten server, a reused password, a default nobody changed. My job is to find yours first.

A clear engagement, end to end

No mystery, no surprises. You know exactly what happens at every stage, and where you sign off.

01

Scope

We define what's in bounds, your goals, and any operational constraints. For OT and production systems, safety and uptime come first.

02

Test

Hands-on testing the way a real attacker works. Findings are exploited and verified manually, proof of impact, not just a scanner flag.

03

Report

A prioritized report with clear remediation steps and proof of impact, written to be acted on, not a 200-page scanner dump.

04

Retest

Once your team has remediated, I re-verify the fixes so you can prove the issues are actually closed.

Scoped to your environment, not a price list

Every engagement is quoted after a short scoping conversation, so you only pay for the work your environment actually needs. A few things shape the number:

Scope & size

How much is in bounds, a single application versus your whole network and everything on it.

Number of targets

How many hosts, applications, sites, or devices fall inside the agreed scope.

Environment complexity

Standard IT versus OT/ICS and production systems, which need extra, safety-first care.

Depth & retest

How deep the testing goes, and whether you want a retest to verify your fixes.

Why Work With Me

A working practitioner, not a detached consultant, you get the person doing the testing.

B.S. Cyber Operations Dakota State University · NSA-designated
Security+, CySA+ & ISC2 CC CompTIA & ISC2 certified
Enterprise IT & OT Daily hands-on practitioner
Bug Bounty Researcher Findings credited by Adobe & 3CX

A Working Practitioner

I work daily as a cybersecurity engineer across enterprise IT and OT, the same kinds of systems I'll be testing for you, not theory from a slide deck.

Manual, Not Just Scanned

I exploit findings by hand to prove real-world impact, not just flag what a scanner noticed. Modern tooling helps me move faster, the judgment and accountability stay human.

A Real Attacker's Mindset

Active bug bounty researcher with credited findings, including a critical-severity issue in a widely used enterprise product. I find what scanners and checklists miss.

Reports You Can Act On

Prioritized findings, proof of impact, and remediation steps your team can actually implement, not a 200-page dump of raw scanner output.

Real-World MSP Experience

A prior background across 30+ MSP engagements means I understand real budget constraints, mixed environments, and the compliance pressure you're under.

Direct Access

You work directly with the person doing the testing. No account managers, no handoffs, no junior quietly doing the real work.

Ready to scope a test?

Tell me what you're protecting — I'll tell you what I'd test and what it costs. No pressure, no retainer pitch.

Start the conversation

Sample Work

Internal Network Penetration Test

Multi-vector attack chain demonstrating lateral movement and domain compromise.

View Report

Malware Analysis Report

Analysis of multi-stage malware including macro document, dropper, and exfiltration payload.

View Report

Bug Bounty Findings

Credited vulnerability research across public programs, including a critical-severity finding currently under non-disclosure.

HackerOne profile

Frequently Asked Questions

How long does a penetration test take?
Most small-business engagements run one to two weeks from kickoff to final report, depending on scope and the number of targets. You'll get a clear timeline before any testing starts.
Will testing disrupt my operations?
Safety and uptime come first, especially for OT and production systems. We agree on rules of engagement up front, schedule any intrusive testing around your operations, and I check in before doing anything that carries risk.
Is the testing automated or manual?
Every engagement is human-driven. I use tooling to widen coverage and speed up the tedious parts, but I validate every finding by hand before it reaches your report. You're not paying for raw scanner output, you're paying for verified, exploitable findings and someone accountable for them.
Do you offer retests after we remediate?
Yes. Once your team has fixed the findings, I re-verify the affected issues so you can demonstrate to customers, auditors, or leadership that they're actually closed.
What size and type of businesses do you work with?
Small and mid-sized businesses, MSPs, and industrial operations, anywhere a focused, independent test is more valuable than a big-firm retainer. Based in Louisiana, available remotely nationwide. Get in touch and we'll scope the right engagement together.

Contact

Ready to find out what attackers would find?

Let's discuss your security needs and how a penetration test can help protect your business. I personally read and respond to every inquiry within one business day.

Penetration testing across Louisiana — Lafayette, Baton Rouge, and New Orleans · Available for remote engagements nationwide

Goes straight to Brennan · reply within one business day