Dan Weecks | Cybersecurity, Compliance, and Communications Consulting
Outside Engagements · Accepted Case by Case
Dan Weecks · CISO, CUI Systems

Security and Compliance for Organizations That Cannot Afford a Second Chance

CISO, CUI Systems  |  Lead Information Security Officer, DIB
Public Trust adjudicated · DoD CAC credentialed · CMMC Level 2 Program Lead

Most organizations pursuing federal contracts are not failing because of bad people or weak intentions. They are failing because their security posture, CUI governance, and compliance documentation were built for a different era, and nobody inside has the time or authority to fix it. That is the problem I solve, full time, in house, for a Defense Industrial Base consultancy, and on a selective basis for outside clients whose situations do not conflict with my in-house obligations.

Every inquiry is personally reviewed for mission fit. Accepted applicants typically hear back within one business day.

Dan Weecks, CISO and compliance consultant
Outcomes, Not Activity

Security and technology investments are only worth what they produce. Here is what mine have produced across defense, healthcare, and enterprise operations.

$50,000+
Recurring annual costs eliminated across AI tooling and managed services, cut without losing a single capability
110
NIST SP 800-171 controls owned end to end, from policy and SSP through C3PAO assessment readiness
30–60 hrs
Saved per federal contract submission through a proprietary AI platform built from scratch, on RFPs valued $1.2M to $4.6M
Zero
Disruptions to federal contract delivery during a full MSP transition out of an 8-year-old legacy environment
3,000+
Client accounts managed across government, legal, healthcare, and Fortune 500 organizations over 15 years
38+ hrs
Executive time saved per position through ATS implementation and hiring pipeline automation, per company president
Dan Weecks on the flight deck in instrument meteorological conditions
On the flight deck of a jet aircraft in IMC: zero visibility, full responsibility.
Dan Weecks serving as Red Cross Public Information Officer at a second alarm multi-family fire in Arizona
Red Cross PIO at a second alarm multi-family fire in Arizona. Accustomed to dealing with time-sensitive, life-or-death matters.
Why "Mission Critical" Means Something Different Here

Some Organizations Cannot Afford to Find Out Their Systems Were Wrong

When a contractor loses a federal contract because their CMMC documentation did not hold up, the organization does not get a warning. When a CUI boundary fails an assessment, there is no partial credit. When an incident goes undetected, the breach is already underway.


That zero-fail standard is not abstract to me. Before focusing full time on information security, I flew as an airline captain, hand-flying approaches in zero-visibility conditions where the systems, the checklists, and the person in the left seat all had to work the first time. Every flight. No exceptions.

Before that, I spent years as a first responder and Public Information Officer with the American Red Cross, logging nearly 4,000 hours responding to house fires, floods, and major incidents including the Bighorn Wildfire. I have pulled animals from burning structures. I have stood in front of cameras at an active disaster scene and had to make the right call about what to say to the public, right now, with incomplete information.

What those two environments produced is a specific way of building security programs: logging that cannot be altered, response postures rehearsed before the emergency, and stakeholder communications drafted before they are needed. The standard I hold this work to was established long before it applied to a network.

Where I Take On Client Work

The Problems Organizations Bring to Me

Project-based consulting and advisory retainers, accepted case by case alongside my full-time in-house role at a Defense Industrial Base consultancy. Every service below is grounded in hands-on delivery inside that environment today, not past theory.

CMMC Level 2 and CUI Readiness

Most CMMC programs stall because the contractor hired outside consultants who documented controls they would never have to operate. I took over a program in exactly that condition and rebuilt it end to end: new SSP, complete policy documentation, full assessment objective coverage across all 110 NIST SP 800-171 controls, and POA&M governance, driven to C3PAO assessment and SPRS readiness. If your program is behind, stalled, or built on paper that will not survive an audit, that is the problem I know how to fix.

Apply for readiness support →

Security Program Advisory

Many executives inherit a security function that was never built to do more than check a box. When that organization goes after a federal contract, the gaps surface fast. I provide advisory support for executives building or correcting a security program from the inside, covering policy and SOP review, vendor and third-party risk, audit response strategy, and board-ready reporting, informed by owning security and IT as one accountable function for a DoD contractor today.

Apply for advisory support →

Incident Response and Crisis Communications

Organizations that have never run a real incident do not know what they are missing until one happens. I have detected and shut down live incidents across the DIB space, including unauthorized Microsoft 365 tenant access handled with formal notification procedures. Years as a FEMA ICS-certified first responder and Public Information Officer taught me to walk into an active incident with a plan already briefed. I build the logging, response posture, and stakeholder communications before they are needed, so your team is not improvising when it counts.

Request an incident readiness review →

Legacy IT Modernization and MSP Transition

An 8-year-old IT environment built before your current compliance requirements existed is not a minor inconvenience. It is a liability that grows every time you add a federal client. I research, negotiate, and direct complete MSP replacements, including a recent migration of every system out of a legacy environment to full NIST 800-171 Rev 2 alignment with zero disruption to federal contract delivery and over $20,000 in annual savings. The result your team actually owns when the engagement ends is the only result that matters.

Scope a modernization project →

Healthcare and Public-Sector IT Implementation

Regulated environments have a specific failure mode: technology gets deployed faster than the people and policies around it can absorb. I advised hospital leadership on IT systems implementation and patient-facing service design at Banner Boswell Medical Center, and led AI integration, telehealth implementation, and ATS automation in a regulated healthcare environment at CHS Healthcare. Secure adoption is the deliverable, not just deployment.

Plan a secure implementation →

Security Training, Tooling, and Workforce Standards

Compliance training nobody can verify completed is not compliance. I built a CMMC access control and audit hub with immutable logging and a company-wide compliance training platform that auto-generates certificates and reports directly to compliance on every pass. As a CTE Education Quality Commissioner for the Arizona Department of Education, I validate the technical standards that feed the IT workforce pipeline. I build training programs and tooling that hold up to both auditors and educators.

Discuss training and tooling →
Selective by Necessity

Outside Work Is Limited and Screened for Conflicts First

My primary obligation is securing a Defense Industrial Base consultancy. Outside engagements exist because the problems I solve there appear elsewhere, and sometimes I can help. Every inquiry is conflict-checked before anything else moves forward.

The work I take on

  • Defense Industrial Base contractors pursuing CMMC Level 2 or maturing NIST SP 800-171 programs
  • Organizations ready to treat security and IT as one accountable function, not a checkbox
  • Leadership teams with executive sponsorship and the authority to act on findings
  • Regulated and mission-driven environments where systems must work the first time, every time
  • Teams that want documented systems, SOPs, and training they will own after the engagement ends

The work I decline

  • Paper-only compliance with no intention of operational change
  • Engagements without a decision-maker at the table
  • Scopes built around shortcuts that put federal contracts or CUI at risk
  • Anything that conflicts with my in-house role, my employer's interests, or existing client commitments
  • Timelines my full-time obligations cannot honestly support

If you are unsure whether your situation qualifies, apply anyway. A direct no with a referral is still a useful answer, and you will get one quickly.

Working Together

What Happens After You Apply

Clear expectations from the first message. No ambiguity, no scope drift.

01

Apply

Submit the inquiry form with a short description of the problem, the environment, and the timeline. Every application is read personally.

02

Fit and Conflict Review

Before anything else, the application is checked against my in-house obligations and screened for conflicts of interest. Cleared inquiries move to a focused discovery call. The rest receive a direct no with a referral where possible.

03

Scoped Proposal and Delivery

A written scope with deliverables, timeline, and pricing, followed by execution with documented systems, SOPs, and training that your team owns when the engagement ends.

In Their Words

What Happens When the Work Is Done

From U.S. ambassadors to emergency response directors to Fortune 500 operators, the people who have worked with me speak to one consistent pattern: the job got done, the first time, the way it was supposed to.

I especially appreciated that you anticipated challenges and you arrived early enough to resolve every possible glitch before it became a problem.
Barbara M. Barrett
U.S. Ambassador (Ret.); later 25th Secretary of the Air Force
Weecks Productions consistently delivered high quality service, took the time to understand our industry and our company's brand, and always delivered on time and budget.
Thomas Hall
Digital Media Strategist, Swift Transportation
Not only are you an engaging, dynamic speaker but authentic as well. Students really responded and connected with you. After your instruction, students were energized and put what they learned into action.
Jeremy Babendure, Ph.D.
Executive Director, Arizona SciTech Festival; Chief Science Officers Program
I only hire and re-hire people who can think on their feet, keep their eye on the goal and get the project finished the first time, on time and in a professional manner.
Douglas L. Beck, Au.D.
Board Certified Audiologist; Author and Lecturer
Dan is willing to do hard work other people are not, is extremely reliable and responsible, and dedicates himself to every task at hand regardless of the situation or circumstances.
Lisa Martin
Executive Director, Companion Pets in Crisis
He is an impressive problem solver who is always looking to address issues with strategy. He put this skill set to work in order to increase our sales, improve our culture with his positivity, and creatively fix outdated policies.
Nicholas Beaird
General Manager, Westwind Air Service
No matter the road blocks or potential challenges a project may present, he is able to effectively strategize, produce, and execute any type of strategy, event, or project. Dan has my highest recommendation.
Bill Oberst Jr.
Emmy Award-Winning Actor
Speaking and Media

On Stage and On Air

Keynotes, workshops, and conversations on security, leadership, and communicating from the inside out.

Dan Weecks presenting on wearable technology for the City of Peoria

Wear With Care: When Accessibility Outpaces Awareness

Presented for the City of Peoria at Rio Vista, this session explores wearable technology and the growing gap between how easily connected devices enter our lives and how little we understand about the data they collect, transmit, and expose.

Book Dan to speak →
Dan Weecks lecturing at Grand Canyon University

Lecturing the Next Generation of STEM Leaders

Guest lecturer at Grand Canyon University for the Chief Science Officers, students in grades 6 through 12 elected by their peers as STEM and innovation liaisons through the SciTech Institute's international CSO program.

Book Dan to speak →
Dan Weecks on NBC's American Ninja Warrior season 10

From Ninja Warrior to The In-To-Out Show

That is me on NBC's American Ninja Warrior, season 10, competing as the Puppy Pilot Ninja. The same drive carries into the studio today, where I host The In-To-Out Show (ITO), connecting leaders and innovators through conversations on resilience and building from the inside out.

Listen on Spotify →
Think We Might Be a Fit?

If the Problem Is Real, Let's Find Out If This Is the Right Fit

Whether the need is CMMC readiness, security program advisory, incident response posture, legacy IT modernization, or secure technology implementation, the first step is a short application. Outside engagements are limited by design and accepted case by case. The ones I take get the same standard I hold my in-house work to.

Get In Touch

Start a Conversation

Apply to Work Together

Describe the problem, the environment, and the timeline. Outside engagements are conflict-checked first, then scoped. You will receive a direct answer either way, typically within one business day.

Name
Area of Need
Any pertinent and relevant details

This form is for outside consulting inquiries only. Every submission is conflict-checked against my in-house obligations before a response is sent.

Apply to Work Together