vCISO Services
Fractional security leadership for organizations that need a CISO's judgment but not a CISO's salary.
About
Cybersecurity compliance, led personally — not delegated.
Vigilant Cybersecurity is a specialized consultancy serving small and mid-sized defense contractors in Alaska's defense industrial base. We exist for organizations that need to meet CMMC and federal cybersecurity requirements without the cost, overhead, and disconnect of a national firm — and that means doing the work differently.
Every engagement is led personally by the principal consultant, supported by a vetted network of independent specialists when implementation requires it. Strategy, scoping, assessment, remediation guidance, and documentation all come from the same hands. When something needs to change mid-engagement, the conversation is with the person who can change it — not the partner-in-charge, not the engagement manager, not the bench staff.
The result is compliance work that fits your operation rather than fighting it: scoped honestly, documented defensibly, and built so your team can sustain it after the engagement closes.
Principal Consultant
Hutch White is the founder and principal consultant of Vigilant Cybersecurity. He is a Lead CMMC Certified Assessor and brings over 15 years of security experience across multiple industries, including hands-on information system security officer work inside a regulated organization and support for compliance audits at organizations with thousands of users.
Hutch founded Vigilant Cybersecurity to bring real-world, operationally grounded compliance expertise to organizations that have historically had to choose between under-qualified local generalists and unaffordable national firms.
He is based in Anchorage and serves clients across Alaska and nationwide.
Independence
Hutch will not serve on a CMMC assessment of any organization Vigilant Cybersecurity has advised. Advisory and assessment work are kept separate, consistent with CMMC's conflict-of-interest rules.
Fractional security leadership for organizations that need a CISO's judgment but not a CISO's salary.
A focused 2–4 week engagement that tells you exactly where you stand and what it will take to close the distance.
Full-engagement Level 1 and Level 2 readiness for defense contractors and subcontractors moving from current state to assessment-ready.
Annual and quarterly support for organizations that have already achieved readiness and need to maintain it year-over-year.
Whether you're scoping a CMMC engagement, preparing for an upcoming defense contract, or just want a candid second opinion on your current security posture — we'd be glad to connect.
Or reach a practitioner directly: (907) 229-5222 · consultations@vigilantcybersecurity.net