Security and Compliance for Organizations That Cannot Afford a Second Chance
Most organizations pursuing federal contracts are not failing because of bad people or weak intentions. They are failing because their security posture, CUI governance, and compliance documentation were built for a different era, and nobody inside has the time or authority to fix it. That is the problem I solve, full time, in house, for a Defense Industrial Base consultancy, and on a selective basis for outside clients whose situations do not conflict with my in-house obligations.
Every inquiry is personally reviewed for mission fit. Accepted applicants typically hear back within one business day.
Security and technology investments are only worth what they produce. Here is what mine have produced across defense, healthcare, and enterprise operations.
Some Organizations Cannot Afford to Find Out Their Systems Were Wrong
When a contractor loses a federal contract because their CMMC documentation did not hold up, the organization does not get a warning. When a CUI boundary fails an assessment, there is no partial credit. When an incident goes undetected, the breach is already underway.
That zero-fail standard is not abstract to me. Before focusing full time on information security, I flew as an airline captain, hand-flying approaches in zero-visibility conditions where the systems, the checklists, and the person in the left seat all had to work the first time. Every flight. No exceptions.
Before that, I spent years as a first responder and Public Information Officer with the American Red Cross, logging nearly 4,000 hours responding to house fires, floods, and major incidents including the Bighorn Wildfire. I have pulled animals from burning structures. I have stood in front of cameras at an active disaster scene and had to make the right call about what to say to the public, right now, with incomplete information.
What those two environments produced is a specific way of building security programs: logging that cannot be altered, response postures rehearsed before the emergency, and stakeholder communications drafted before they are needed. The standard I hold this work to was established long before it applied to a network.
The Problems Organizations Bring to Me
Project-based consulting and advisory retainers, accepted case by case alongside my full-time in-house role at a Defense Industrial Base consultancy. Every service below is grounded in hands-on delivery inside that environment today, not past theory.
CMMC Level 2 and CUI Readiness
Most CMMC programs stall because the contractor hired outside consultants who documented controls they would never have to operate. I took over a program in exactly that condition and rebuilt it end to end: new SSP, complete policy documentation, full assessment objective coverage across all 110 NIST SP 800-171 controls, and POA&M governance, driven to C3PAO assessment and SPRS readiness. If your program is behind, stalled, or built on paper that will not survive an audit, that is the problem I know how to fix.
Apply for readiness support →Security Program Advisory
Many executives inherit a security function that was never built to do more than check a box. When that organization goes after a federal contract, the gaps surface fast. I provide advisory support for executives building or correcting a security program from the inside, covering policy and SOP review, vendor and third-party risk, audit response strategy, and board-ready reporting, informed by owning security and IT as one accountable function for a DoD contractor today.
Apply for advisory support →Incident Response and Crisis Communications
Organizations that have never run a real incident do not know what they are missing until one happens. I have detected and shut down live incidents across the DIB space, including unauthorized Microsoft 365 tenant access handled with formal notification procedures. Years as a FEMA ICS-certified first responder and Public Information Officer taught me to walk into an active incident with a plan already briefed. I build the logging, response posture, and stakeholder communications before they are needed, so your team is not improvising when it counts.
Request an incident readiness review →Legacy IT Modernization and MSP Transition
An 8-year-old IT environment built before your current compliance requirements existed is not a minor inconvenience. It is a liability that grows every time you add a federal client. I research, negotiate, and direct complete MSP replacements, including a recent migration of every system out of a legacy environment to full NIST 800-171 Rev 2 alignment with zero disruption to federal contract delivery and over $20,000 in annual savings. The result your team actually owns when the engagement ends is the only result that matters.
Scope a modernization project →Healthcare and Public-Sector IT Implementation
Regulated environments have a specific failure mode: technology gets deployed faster than the people and policies around it can absorb. I advised hospital leadership on IT systems implementation and patient-facing service design at Banner Boswell Medical Center, and led AI integration, telehealth implementation, and ATS automation in a regulated healthcare environment at CHS Healthcare. Secure adoption is the deliverable, not just deployment.
Plan a secure implementation →Security Training, Tooling, and Workforce Standards
Compliance training nobody can verify completed is not compliance. I built a CMMC access control and audit hub with immutable logging and a company-wide compliance training platform that auto-generates certificates and reports directly to compliance on every pass. As a CTE Education Quality Commissioner for the Arizona Department of Education, I validate the technical standards that feed the IT workforce pipeline. I build training programs and tooling that hold up to both auditors and educators.
Discuss training and tooling →Outside Work Is Limited and Screened for Conflicts First
My primary obligation is securing a Defense Industrial Base consultancy. Outside engagements exist because the problems I solve there appear elsewhere, and sometimes I can help. Every inquiry is conflict-checked before anything else moves forward.
The work I take on
- Defense Industrial Base contractors pursuing CMMC Level 2 or maturing NIST SP 800-171 programs
- Organizations ready to treat security and IT as one accountable function, not a checkbox
- Leadership teams with executive sponsorship and the authority to act on findings
- Regulated and mission-driven environments where systems must work the first time, every time
- Teams that want documented systems, SOPs, and training they will own after the engagement ends
The work I decline
- Paper-only compliance with no intention of operational change
- Engagements without a decision-maker at the table
- Scopes built around shortcuts that put federal contracts or CUI at risk
- Anything that conflicts with my in-house role, my employer's interests, or existing client commitments
- Timelines my full-time obligations cannot honestly support
If you are unsure whether your situation qualifies, apply anyway. A direct no with a referral is still a useful answer, and you will get one quickly.
What Happens After You Apply
Clear expectations from the first message. No ambiguity, no scope drift.
Apply
Submit the inquiry form with a short description of the problem, the environment, and the timeline. Every application is read personally.
Fit and Conflict Review
Before anything else, the application is checked against my in-house obligations and screened for conflicts of interest. Cleared inquiries move to a focused discovery call. The rest receive a direct no with a referral where possible.
Scoped Proposal and Delivery
A written scope with deliverables, timeline, and pricing, followed by execution with documented systems, SOPs, and training that your team owns when the engagement ends.
The Experience Behind the Work
Federal and state government, civilian aviation, disaster operations, and communications leadership, not as a background story, but as the foundation the current work stands on.
What Happens When the Work Is Done
From U.S. ambassadors to emergency response directors to Fortune 500 operators, the people who have worked with me speak to one consistent pattern: the job got done, the first time, the way it was supposed to.
I especially appreciated that you anticipated challenges and you arrived early enough to resolve every possible glitch before it became a problem.
Weecks Productions consistently delivered high quality service, took the time to understand our industry and our company's brand, and always delivered on time and budget.
Not only are you an engaging, dynamic speaker but authentic as well. Students really responded and connected with you. After your instruction, students were energized and put what they learned into action.
I only hire and re-hire people who can think on their feet, keep their eye on the goal and get the project finished the first time, on time and in a professional manner.
Dan is willing to do hard work other people are not, is extremely reliable and responsible, and dedicates himself to every task at hand regardless of the situation or circumstances.
He is an impressive problem solver who is always looking to address issues with strategy. He put this skill set to work in order to increase our sales, improve our culture with his positivity, and creatively fix outdated policies.
No matter the road blocks or potential challenges a project may present, he is able to effectively strategize, produce, and execute any type of strategy, event, or project. Dan has my highest recommendation.
On Stage and On Air
Keynotes, workshops, and conversations on security, leadership, and communicating from the inside out.
Wear With Care: When Accessibility Outpaces Awareness
Presented for the City of Peoria at Rio Vista, this session explores wearable technology and the growing gap between how easily connected devices enter our lives and how little we understand about the data they collect, transmit, and expose.
Book Dan to speak →
Lecturing the Next Generation of STEM Leaders
Guest lecturer at Grand Canyon University for the Chief Science Officers, students in grades 6 through 12 elected by their peers as STEM and innovation liaisons through the SciTech Institute's international CSO program.
Book Dan to speak →
From Ninja Warrior to The In-To-Out Show
That is me on NBC's American Ninja Warrior, season 10, competing as the Puppy Pilot Ninja. The same drive carries into the studio today, where I host The In-To-Out Show (ITO), connecting leaders and innovators through conversations on resilience and building from the inside out.
Listen on Spotify →If the Problem Is Real, Let's Find Out If This Is the Right Fit
Whether the need is CMMC readiness, security program advisory, incident response posture, legacy IT modernization, or secure technology implementation, the first step is a short application. Outside engagements are limited by design and accepted case by case. The ones I take get the same standard I hold my in-house work to.
Start a Conversation
Apply to Work Together
Describe the problem, the environment, and the timeline. Outside engagements are conflict-checked first, then scoped. You will receive a direct answer either way, typically within one business day.
This form is for outside consulting inquiries only. Every submission is conflict-checked against my in-house obligations before a response is sent.