Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # Phoenix Cyber ## Sitemaps [XML Sitemap](https://phoenixcyber.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [Common Vulnerability Scoring System (CVSS): A Complete Guide to Vulnerability Scoring & Prioritization](https://phoenixcyber.com/blog/understanding-cvss-vulnerability-prioritization/): Understanding and managing vulnerabilities is critical for all organizations. One of the most widely recognized frameworks for evaluating and prioritizing vulnerabilities is the Common Vulnerability Scoring System (CVSS). This guide covers everything you need to know about the CVSS, including how vulnerability scoring works, how CVSS scores are calculated, what each metric group measures, and the advantages and limitations of the system. In a companion post, we explore how to extend your scoring and prioritization beyond CVSS with a threat-based approach to prioritize actions. - [When Should You Expand Your Security Automation? 8 Key Indicators](https://phoenixcyber.com/blog/expand-security-automation-capabilities/): The influx of security alerts and vulnerabilities in today's environment finds many organizations stretched thin, trying to monitor and respond. The average enterprise security operations center (SOC) now receives hundreds of thousands of alerts per day, a volume no human team can sustainably manage without technological assistance. Most organizations have some level of security automation running within their environment. It's a powerful solution to enhance speed, accuracy, and scale, but how can you tell when it's time to step up your automation game? Here are key indicators that it is time to implement more robust capabilities. - [Why a Strong Data Foundation Is Key to AI Success](https://phoenixcyber.com/blog/strong-data-foundation-ai/): Artificial intelligence (AI) transforms how organizations operate, from automating workflows to detecting threats in real time. Yet, despite billions invested in cutting-edge algorithms and platforms, up to 95% of AI projects fail to deliver on their promises, and the primary culprit is poor data quality. The real power of AI doesn’t come from algorithms alone; it’s built on the quality and structure of the data that feeds those algorithms. No matter the industry or use case, a robust data foundation anchored by consistent labeling, comprehensive tagging, and precise permissions determines whether your AI initiative will deliver value or fall short. - [How Security Tool Consolidation Can Deliver Results in 2025](https://phoenixcyber.com/blog/security-tool-consolidation-roi/): In summary, it's clear that security tool consolidation delivers measurable ROI while improving operational effectiveness. Organizations that act decisively will gain a significant competitive advantage over those that continue managing fragmented security stacks. - [Best Practices for Zero Trust Implementation with Automation](https://phoenixcyber.com/blog/zero-trust-implementation-automation/): Implementing a Zero Trust architecture involves more than deploying a collection of security tools. It requires a strategic shift toward intelligent automation that coordinates decisions across your entire security stack. Automation is not just a helpful enhancement; it’s the foundation making Zero Trust scalable, adaptive, and effective. In the first part of this blog series, we reviewed why zero trust depends on automation. In this post, we’ll put these theories into action and explain how to incorporate automation as the central hub of your zero trust implementation. - [Why Zero Trust Demands Automation](https://phoenixcyber.com/blog/why-automation-zero-trust/): Zero Trust represents a fundamental shift in security philosophy, moving from "trust but verify" to "never trust, always verify." This paradigm shift demands more than new tools. It's a complete operational transformation. The traditional security approach of manual processes, quarterly reviews, and change ticket workflows becomes not just inefficient but actively dangerous in a Zero Trust environment. - [Securing Hybrid Environments with Zero Trust](https://phoenixcyber.com/blog/securing-hybrid-environments-zero-trust/): "Never trust, always verify." It’s not just a slogan—it’s the foundation of the Zero Trust model. But when your organization runs on a hybrid IT environment with a mix of on-premises infrastructure, cloud services, and a distributed remote workforce, actually putting Zero Trust into practice gets complicated fast. Hybrid environments are messy. You’re dealing with legacy systems that weren’t designed with identity-based security in mind, multiple cloud platforms with different access control models, and users logging in from coffee shops, home offices, and mobile devices. - [Choosing Between AI or Automation in Security Operations What Actually Works](https://phoenixcyber.com/blog/ai-vs-automation-in-secops-how-to-choose/): 04/26/2025 - [How to Level Up Your Security Automation](https://phoenixcyber.com/blog/level-up-security-automation/): Security automation is no longer a nice-to-have—it’s a necessity. With cyber threats evolving at an alarming rate (especially as artificial intelligence takes off), manually responding to every incident just isn’t realistic. Security teams are stretched thin, dealing with endless alerts, compliance headaches, and the constant pressure to stay ahead of attackers. The solution? Smarter, more advanced security automation. - [Using a Threat-based Approach for Detections: Understanding Bad Actors](https://phoenixcyber.com/blog/threat-based-approach-detection/): 01/15/2025 - [From Theory to Practice: Testing Your Threat Hunting Hypotheses](https://phoenixcyber.com/blog/testing-threat-hunting-hypotheses/): Contact Phoenix Cyber now to learn how we can help you formulate, test, and fine-tune your threat hunting hypotheses. - [A Deep Dive into Black-Box, White-Box and Grey-Box Penetration Testing](https://phoenixcyber.com/blog/black-box-white-box-grey-box-penetration-testing/): Taking the time to understand adversary tools, techniques, and methodologies will help you gain confidence in your defense and know what to do in each situation. One way to do this is through penetration testing, as it gives incident responders a path to build knowledge into skills using practical application. Then, you constantly refine those skills through practice and more testing. This will help you improve each skill as well as help you integrate and interface different skill sets with more speed and accuracy. - [Adapting Penetration Testing Methods for Cloud Environments](https://phoenixcyber.com/blog/penetration-testing-methods-cloud/): Penetration testing and security assessments face unique challenges in cloud environments. The traditional network perimeter has largely disappeared, with resources distributed across both on-premises and cloud environments worldwide. Users access these resources via various devices and applications, often requiring only proof of identity such as a password, API key, or access token. - [Unlocking the Power of SIEM in Threat Hunting](https://phoenixcyber.com/blog/siem-threat-hunting/): Contact us today to learn how to unlock the full potential of your SIEM in threat hunting. - [Distinguishing Between Normal Network Behavior and Potential Cyber Threats](https://phoenixcyber.com/blog/normal-network-behavior-vs-cyber-threats/): 10/22/2024 - [How to Implement the Zero Trust Model](https://phoenixcyber.com/blog/implement-zero-trust-model/): The Zero Trust Maturity Model operates on a simple principle: never trust, always verify. Instead of assuming that everything inside of the network is safe and trustworthy, the Zero Trust Model treats every user, device, and connection as potentially untrustworthy, even if they are already inside the network. - [Four Intrusion Detection Methods for Countering Cyber Threats](https://phoenixcyber.com/blog/intrusion-detection-methods-cyber-threats/): Intrusion detection methods are used to identify intruders that are trying to or have breached your network. There are four main methods of detection, but two of them—threat behavioral analytics and configuration changes—are most likely to catch bad actors. The other two, modeling and threat indicators, have uses in certain situations. - [Getting Started with Active Defense Tools](https://phoenixcyber.com/blog/getting-started-active-defense-tools/): There is a lot of confusion around how to implement Active Defense tools. Part of the reason is because there is little guidance from governing bodies on how to actually use tactics such as denial and deception (D&D), counterdeception (CD), counterintelligence (CI), and offensive countermeasures (OCM). The other is a fear of legal action, since organizations are not protected if they use countermeasures to go after intruders. As we discussed in our previous blog post, there are ways to mitigate the risk of using Active Defense tools, and, in general, these are an effective, low-cost, low-risk way to better secure your network. - [Understanding the Business Impact of Active Defense Tools](https://phoenixcyber.com/blog/active-defense-tools-business-impact/): If your organization is grappling with whether or not to implement Active Defense tools to better protect your network, consider the business impacts of not implementing these tools. Actors are constantly upping their game—unlocking new capabilities and tactics all the time—and organizations are faced with the enormous challenge of trying to address these threats in a way that will be effective for a wide range of attack scenarios and objectives. - [Why Traditional Cyber Tools and Strategies Fail to Address the Threat of Intrusion](https://phoenixcyber.com/blog/traditional-cyber-tools-fail-intrusion-threat/): 08/21/2024 - [Leveraging Active Defense Tools to Protect Against Cyber Threats](https://phoenixcyber.com/blog/leveraging-active-defense-tools-cyber-threats/): When your network is compromised, your first priority is shutting down the intruder. While that might seem like the best course of action, there’s a better way to defend against bad actors and prevent future attacks. Enter: Active Defense tools. In this four-part series we will discuss the elements of Active Defense tools, why traditional tools fail to address the threat of intrusion, the business impact of using these tools, and how to get started using them. - [Extending Your Vulnerability Scoring and Prioritization Beyond the CVSS](https://phoenixcyber.com/blog/extending-vulnerability-scoring-prioritization-cvss/): The Common Vulnerability Scoring System (CVSS) certainly has its place in cyber security. In fact, it’s one of the most widely recognized frameworks for evaluating and prioritizing vulnerabilities for a couple reasons. One, it’s easy to use and two, it offers a check-in-the-box solution for those that need it. We previously did a deep dive into the CVSS and how it works here. However, the biggest problem with vulnerability scores is that they lack context. (It uses an algorithm to assign risk scores to vulnerabilities rather than using human judgment.) If you really want to compete against high level actors you have to learn their plays. - [What Federal Contractors Need to Know about the CMMC 2.0 Update](https://phoenixcyber.com/blog/federal-contractors-cmmc-2-updates/): The U.S. Department of Defense (DoD) is enhancing its cybersecurity requirements with the introduction of CMMC 2.0. For businesses aiming to secure and maintain contracts with the federal government, understanding and adapting to these changes is crucial. Although first announced in November 2021, the CMMC 2.0 now has an expected release in the first quarter of 2025. Thus, it’s imperative federal contractors begin the compliance process. Here's a breakdown of the CMMC 2.0 updates and what they mean for your federal business. - [The Need for a Unified Dashboard in Vulnerability Management](https://phoenixcyber.com/blog/unified-dashboard-vulnerability-management/): Vulnerability management remains critical for organizations to safeguard sensitive data and maintain operational continuity, while increasing their security posture. In this context, all senior cybersecurity leaders play a pivotal role in steering the organization's vulnerability management strategy. While they may not be in the weeds working within the vulnerability management platform(s), senior leaders would greatly benefit from the adoption of a single, customized dashboard to oversee vulnerability management efforts and make better decisions on prioritization, remediation, and countermeasures. Here's why: - [A Comprehensive Guide to Building Data Protection Programs: Part 2](https://phoenixcyber.com/blog/guide-building-data-protection-programs-2/): 05/15/2024 - [A Phased Approach to Building Data Protection Programs](https://phoenixcyber.com/blog/guide-building-data-protection-programs-1/): 05/01/2024 - [Accelerating Security Breach Remediation with AI-Powered Incident Response](https://phoenixcyber.com/blog/accelerating-breach-remediation-with-ai-incident-response/): 04/24/2024 - [The Power of Automated Threat Hunting](https://phoenixcyber.com/blog/power-automated-threat-hunting/): Artificial intelligence is poised to take automated threat hunting even further than automation alone every could. AI-powered tools can process and correlate massive volumes of data far faster than traditional methods, identifying subtle patterns and connections that might otherwise go unnoticed. Machine learning models can continuously adapt to new attack techniques, improving detection accuracy over time without requiring manual rule updates. As large language models and generative AI continue to mature, they will also help analysts by summarizing complex threat data, recommending response actions, and even generating detection queries on the fly, dramatically reducing the time between hypothesis and action. - [Struggling Under the Barrage of SIEM Alerts? Automate SIEM Alert Triage Using SOAR](https://phoenixcyber.com/blog/siem-alerts-automation-soar/): So how do security leaders optimize their incident response times with the overwhelming number of alerts coming in and minimize the risk of a breach or stolen data? By leveraging standardized and automated responses to threats using a security orchestration, automation and response (SOAR) platform to automate SIEM alert triage. Key cybersecurity technologies (including your SIEM solution) are integrated into a SOAR platform to review, prioritize and triage alerts. Then based on the type of alert, a workflow is initiated for an automatic incident response. This enables a faster and more efficient response to threats and requires limited to no human interaction. In addition, when using a SOAR platform, data from multiple security tools can be integrated to provide a centralized view of all threats in a single location. This supports quicker visualization of an organization’s threats and response. - [Automating Incident Response: A Use Case for Streamlined Remediation of Phishing Attacks](https://phoenixcyber.com/blog/automated-incident-response-phishing/): Manual incident response processes are time-consuming, error-prone, and resource-intensive, which has resulted in security automation gaining in popularity. By combining the power of automation and orchestration, security orchestration, automation, and response (SOAR) platforms provide a comprehensive solution to streamline and enhance incident response processes. In this article, we will dive into a real-world use case that highlights the benefits of automating incident response and demonstrates how organizations can use automation to specifically improve the remediation of phishing attacks.   - [The Evolution of Threat Intelligence: Empowering Organizations with Security Orchestration, Automation and Response](https://phoenixcyber.com/blog/threat-intel-security-automation/): Threat intelligence is a critical component in the battle against cyber threats. As organizations face increasingly sophisticated attacks, they need to constantly adapt and strengthen their security measures. This evolution has given rise to security orchestration, automation, and response (SOAR) solutions, which are using security automation to revolutionize the way organizations approach threat intelligence. Combining threat intelligence and SOAR is one way to give organizations a competitive edge.  - [Engineering Principles for Developing Advanced Security Automations](https://phoenixcyber.com/blog/engineer-principles-security-automation/): When designing and implementing security automation workflows, there are a number of steps that should be followed to ensure effectiveness, accuracy, and adherence to best practices. Security automation can become complex, so it’s critical that you create a solid foundation prior to automating your first workflow.   - [Building Resilient Data Protection: The Benefits of Automated DLP](https://phoenixcyber.com/blog/dlp-security-automation/): However, there are numerous other benefits to combining the capabilities of SOAR with your favorite DLP solutions for automated DLP including:  ## Pages - [Phoenix Cyber Reduces Alert Noise by 100+ Alerts Per Hour with Security Automation for Leading MSSP](https://phoenixcyber.com/resources/reduce-alert-noise-100-alerts-per-hour-security-automation/): An industry-leading managed security service provider (MSSP) was encountering compounding operational challenges with their security automation platform that was impacting system reliability and eroding user confidence. Corrupted platform instances caused by library component failures disrupted workflows and introduced instability across the environment. At the same time, poor coding practices were generating excessive alert noise, overwhelming analysts, and reducing overall efficiency. - [Phoenix Cyber Helps an MSSP Migrate 70+ Clients to a Security Automation Platform Under Fixed Deadline](https://phoenixcyber.com/resources/mssp-migrate-70-clients-security-automation-platform/): A leading managed security service provider (MSSP) focused on critical infrastructure and regulated industries needed to transition over 70 clients onto Swimlane, a SOC automation solution, under a steep, inflexible deadline before the expiration of an existing contract. The migration needed to occur without disrupting current SOC operations, while integrating with newly developed API services that were still being built during the project. - [Phoenix Cyber Strengthens Security Automation Reliability and Maintainability at U.S. Healthcare Retailer](https://phoenixcyber.com/resources/security-automation-reliability-maintainability-us-healthcare-retailer/): A large U.S. healthcare retailer operates a large-scale, highly complex security automation environment built on the Swimlane security automation platform. While the retailer had invested significantly in tooling and internal capability, recurring technical and architectural issues were limiting its efficiency, scalability, and long-term maintainability. - [Phoenix Cyber Achieves CMMC Level 2 Certification](https://phoenixcyber.com/about/in-the-news/phoenix-cyber-achieves-cmmc-level-2-certification/): CMMC Level 2 certification requires organizations to implement and maintain all 110 security controls specified in NIST SP 800-171, along with documented procedures for cybersecurity functions across people, processes, and technology. Certification is granted only after an independent assessment by a C3PAO confirms that these controls are fully in place and operating as intended. - [Contact](https://phoenixcyber.com/contact/): Are you looking to modernize a security operations center, stand up a Zero Trust or data protection program, or scale automation across an enterprise? Contact us to talk to an expert — not a sales rep working from a script. - [Building a resilient data protection program.](https://phoenixcyber.com/data-protection-program-ebook/): Governance informs policy. Policy drives enforcement. Enforcement generates monitoring data. Monitoring fuels training and improvement. And then cycle continues for a resilient data protection program. - [Phoenix Cyber Wins 2026 Cybersecurity Service Provider of the Year Award](https://phoenixcyber.com/about/in-the-news/cybersecurity-service-provider-of-the-year-award/): PHOENIX, ARIZ., March 19, 2026 – Phoenix Cyber, a premier provider of cybersecurity professional services to enterprises and the federal government, announced today that it has been named a 2026 Gold Award winner in the Cybersecurity Service Provider of the Year category of the Cybersecurity Excellence Awards. Presented by Cybersecurity Insiders and supported by a community of more than 600,000 information security professionals, the awards program has recognized top cybersecurity achievements worldwide for more than a decade. - [Cloud & IT Services](https://phoenixcyber.com/services/cloud-it-services/): Consistent track record of on-time, high-quality IT services delivery with customer recognition and continued contract renewals. - [Security Operations Services](https://phoenixcyber.com/services/security-operations/): For federal agencies and large enterprises operating under high threat levels and strict compliance mandates, our security operations services provide end-to-end monitoring, detection, response, and continuous improvement. By harnessing automation and AI, we reduce risk exposure and ensure mission continuity. Backed by proven operational expertise, we integrate tools, processes, and people to defend critical systems, data, and mission capabilities. - [Federal Agency Automates Travel and Onboarding for Scalable Growth and Hidden Savings](https://phoenixcyber.com/resources/federal-agency-automates-travel-onboarding/): In 2024, a major U.S. Department of Defense (DoD) agency’s intelligence and security directorate grappled with severe inefficiencies in its personnel intelligence operations. The department was inundated with over 4,500 PDF forms with nearly 1,500 related to unofficial foreign travel from civilians and more than 3,000 contractor onboarding submissions from contracting officer representatives (CORs). These forms arrived via email and required manual re-entry into internal systems, resulting in hundreds of hours lost to repetitive data entry. The error-prone process led to frequent inaccuracies, triggering a cascade of corrective emails and delays. These inefficiencies strained resources, introduced compliance risks, and slowed mission-critical onboarding workflows. - [DevSecOps Services](https://phoenixcyber.com/services/devsecops/): Security breaches, compliance failures, and slow software delivery can cripple an organization’s ability to execute its mission. Teams must act to ensure their software development processes are secure, resilient, and built for speed. Phoenix Cyber's DevSecOps services eliminate security bottlenecks, accelerate innovation, and fortify your software supply chain—so you can deliver at the speed of business applications that are secure, mission-ready and aligned with federal mandates and cybersecurity frameworks. - [Zero Trust Services](https://phoenixcyber.com/services/zero-trust/): Zero Trust is a modern security framework that eliminates implicit trust and enforces continuous verification across all access requests. By leveraging automation, orchestration, and analytics, we help organizations secure their data, networks, devices, identities, and applications and workloads with adaptive security controls. - [Phoenix Cyber Wins Task Order Award to Provide the Defense Logistics Agency with Enterprise Workflow Support Capability](https://phoenixcyber.com/about/in-the-news/task-order-dod-dla-ewsc/): PHOENIX, ARIZ., February 27, 2025– Phoenix Cyber, a premier provider of cybersecurity consulting services to enterprises and the federal government, announced today has received a Task Order award to provide professional services to assist with the Enterprise Workflow Support Capability to the Department of Defense's Defense Logistics Agency (DLA). This Task Order was awarded under the J-6 Enterprise Technology Services (JETS) 2.0 contract, which was awarded in 2024 to multiple vendors by DLA. - [SeaPort NxG Contract](https://phoenixcyber.com/government-contractor/seaport-nxg/): Phoenix Cyber has strong and relevant past performance in the delivery of cybersecurity and technology services to the Federal Government to support its many missions and responsibilities around the world. As part of SeaPort NxG, our team can deliver professional engineering, technical, and programmatic support services for the Naval Sea Systems Command, Space and Naval Warfare Systems Command, Naval Supply Systems Command, Military Sealift Command, Naval Facilities Command, Office of Naval Research, and the United States Marine Corps. - [Security Engineering and Architecture Services](https://phoenixcyber.com/services/security-engineering-architecture-services/): We understand that robust security engineering and architecture forms the backbone of effective cybersecurity strategy. Our security engineering and architecture services help organizations build and maintain resilient security infrastructures that align with your mission. - [Phoenix Cyber Appraised at CMMI Level 3](https://phoenixcyber.com/about/in-the-news/cmmi-level-3-appraisal/): Phoenix Cyber's CMMI Level 3 appraisal only enhances its ability to deliver tangible outcomes across all projects while also optimizing efficiency and minimizing risk. Complemented by the company's ISO 9001, ISO 27001, and ISO 20000 certifications, these accreditations reinforce the company’s adherence to internationally recognized standards, solidifying its position as a reliable and innovative partner to federal agencies in supporting its missions. - [Phoenix Cyber Awarded U.S. Navy SeaPort Next Generation Contract Vehicle](https://phoenixcyber.com/about/in-the-news/us-navy-seaport-nxg-contract-award/): PHOENIX, ARIZ., January 23, 2025 – Phoenix Data Security Inc., DBA Phoenix Cyber, a leading provider of cybersecurity and technology consulting services to the federal government, announced today it was named a prime contractor on the Navy SeaPort Next Generation (NxG) contract. This contract positions Phoenix Cyber to extend our commitment to serving the cybersecurity needs of the warfighter, including engineering and cybersecurity services, systems engineering, software development, and program management to support the Navy's missions.  - [Phoenix Cyber Streamlines Personnel Security Clearance Process for Federal Agency](https://phoenixcyber.com/resources/streamlining-personnel-security-clearance-process/): A Federal Agency was experiencing inefficiencies and delays in onboarding new civilian personnel, primarily due to a reliance on manual processes involving the Department of Defense’s (DoD) Form 1474. This form, required for all civilian applicants, was repeatedly emailed back and forth between human resources (HR) and Intelligence, where each department had separate responsibilities. HR managed candidate sourcing, while Intelligence handled background investigations. Data from the form also required manual entry into separate information systems, resulting in additional delays, increased potential for errors, and a cumbersome onboarding process. - [Phoenix Cyber Achieves ISO 27001 and ISO 20000 Certifications](https://phoenixcyber.com/about/in-the-news/iso-27001-iso-20000-achieved/): PHOENIX, ARIZ., November 13, 2024 – Phoenix Cyber, a premier provider of cybersecurity consulting services to enterprises and the federal government, announced today that it has achieved ISO/IEC 27001:2022 and ISO/IEC 20000-I:2018 certification. These accreditations underscore the company’s commitment to implementing and continually improving its robust information security practices and reinforce its dedication to providing secure, reliable information security solutions to its customers. - [Phoenix Cyber Delivers Rapid Application Modernization in Short Timeframe for Federal Agency](https://phoenixcyber.com/resources/application-modernization-federal-agency/): The Federal Agency's Office of the Inspector General (OIG) faced a significant challenge with three critical legacy applications used for tracking whistleblower submissions, criminal investigations, and trade security checks. These applications were running on outdated operating systems, making them difficult to maintain and prone to numerous bugs and errors. Additionally, the systems contained highly sensitive Personally Identifiable Information (PII) with complex security requirements and stored over 100,000 attachments. With a looming compliance deadline just months away, the Agency struggled to find a vendor capable of migrating these applications in time. - [Cloud Security Services](https://phoenixcyber.com/services/cloud-security/): As more data is transmitted and stored in the cloud, your attack surface has expanded exponentially and ensuring its security is vital. Phoenix Cyber offers comprehensive cloud security services designed to protect your cloud-based data, applications, and infrastructure from evolving cyber threats. Whether you're using public, private, or hybrid cloud environments, our team ensures that your cloud infrastructure, data, and applications remain secure, compliant, and resilient.  - [Phoenix Cyber Awarded GSA MAS Highly Adaptive Cybersecurity Services (HACS) Special Item Number](https://phoenixcyber.com/about/in-the-news/gsa-mas-hacs-sin-award/): PHOENIX, ARIZ., October 29, 2024 – Phoenix Data Security Inc., DBA Phoenix Cyber, a premier provider of cybersecurity consulting services to the federal government, announced today it was recently awarded a Highly Adaptive Cybersecurity Services (HACS) Special Item Number (SIN) under the General Services Administration's (GSA) Multiple Award Schedule (MAS). Phoenix Cyber has provided cybersecurity services to numerous DoD and civilian agencies since its inception in 2011. - [GSA MAS (HACS) Contract](https://phoenixcyber.com/government-contractor/gsa-mas-hacs-contract/): Phoenix Cyber has strong and relevant past performance in the delivery of cybersecurity and technology services to U.S. Federal Government agencies. We support the General Services Administration (GSA) Multiple Award Schedule (MAS) Highly Adaptive Cybersecurity (HACS) Special Item Number (SIN) with best in class, pre-vetted cybersecurity services. - [U.S. Department of Defense Awarded DLA JETS 2.0 Contract to Phoenix Cyber](https://phoenixcyber.com/about/in-the-news/dod-dla-jets-2-contract-award/): Additional details on the DLA JETS 2.0 award announcement can be found here.   - [DLA JETS 2.0 Contract](https://phoenixcyber.com/government-contractor/dla-jets-2/): Phoenix Cyber has strong and relevant past performance in the delivery of cybersecurity and technology services to U.S. Federal Government Agencies. We support the Defense Logistics Agency's (DLA) J6 Enterprise Technology Services (JETS) program by providing numerous technology and cybersecurity services. Our team of consultants have an extensive base of skilled and experienced technical and project management resources, many of whom maintain security clearances and advanced cybersecurity and technology certifications. - [Phoenix Cyber Secures Prime Position on GSA OASIS Plus Small Business IDIQ Contract](https://phoenixcyber.com/about/in-the-news/phoenix-cyber-gsa-oasis-plus-sb-contract/): The OASIS+ contract is the largest governmentwide, multi-agency contracting program that provides service-based solutions via six Indefinite Delivery, Indefinite Quantity (IDIQ) contract families. The OASIS+ Total Small Business (SB) is one of those six contract families. With a potential 10-year period of performance and no ceiling value, OASIS+ represents a tremendous opportunity for Phoenix Cyber to expand its solutions across federal customers. - [OASIS+ Contract](https://phoenixcyber.com/government-contractor/oasis-plus/): Phoenix Cyber has strong and relevant past performance in the delivery of cybersecurity services for U.S. Federal Government Agencies. The services we deliver in support of the One Acquisition Solution for Integrated Services + (OASIS+) contract include: Technical and Engineering (T&E) and Intelligence Services (INTEL). Our team of consultants have an extensive base of skilled and experienced technical and project management resources, many of whom maintain security clearances. - [Government](https://phoenixcyber.com/government-contractor/): Phoenix Data Security Inc., DBA Phoenix Cyber, has provided U.S. federal government cybersecurity services since 2011. During this time, we have successfully delivered projects across cybersecurity and IT to the Department of Defense, Department of Homeland Security, Department of Veterans Affairs, Defense Logistics Agency, and many others. - [Phoenix Cyber Achieves ISO 9001 Certification](https://phoenixcyber.com/about/in-the-news/phoenix-cyber-achieves-iso-9001-certification/): PHOENIX, ARIZ., August 20, 2024 – Phoenix Cyber, a premier provider of cybersecurity consulting services to enterprises and the federal government, announced today that it has received its ISO 9001 accreditation from ISO Registrar, American Global Standards, Inc. (AGS).  - [Swimlane Marketplace End-User License Agreement](https://phoenixcyber.com/swimlane-marketplace-end-user-license-agreement/): This privacy policy has been compiled to better serve those who are concerned with how their ‘Personally identifiable information’ (PII) is being used online. PII, as used in US privacy law and information security, is information that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context. Please read our privacy policy carefully to get a clear understanding of how we collect, use, protect or otherwise handle your Personally Identifiable Information in accordance with our website. - [Alleviate Your Security Talent and Staffing Challenges Panel Webinar](https://phoenixcyber.com/resources/alleviate-security-talent-staffing-challenges/): Watch this panel discussion surrounding the current state of security hiring and staffing with real-world examples of how different organizations are remedying these challenges without adding additional headcount. - [About Us](https://phoenixcyber.com/about/): Phoenix Cyber is a leading cybersecurity services company providing security engineering, operations, and technical cybersecurity expertise to organizations determined to mitigate risk and safeguard their business. - [In The News](https://phoenixcyber.com/about/in-the-news/): The news on this page reflects announcements regarding our services enhancements, certifications earned by our consultants and engineers, new U.S. Federal Government purchasing vehicles and contracts, and partnerships with other security providers.  - [DLP Event Management with Security Automation](https://phoenixcyber.com/resources/dlp-event-management-security-automation/): Watch this 10-minute demo, part of the "Security Ops Unplugged" demo series, where we showcase how to streamline your data loss prevention (DLP) event management process using a security orchestration, automation and response (SOAR) platform. - [Cybersecurity Project Management and Security Engineering Expertise | Integrated Health System Case Study](https://phoenixcyber.com/resources/cybersecurity-project-management-security-engineer-health-system/): A Southwestern U.S.-based Integrated Health System that includes multiple hospitals, a multi-specialty medical group with nearly 1000 providers, and a statewide health plan, had many security tactics already in place to reactively defend against cyber threats and attacks. However, facing newly evolved threats and challenges to further ensure the security of their critical healthcare information and data, the integrated health system desired a more proactive approach. They sought out Phoenix Cyber’s technical expertise to assess their current security practices, build a framework to manage their overall security posture and maintain compliance with regulatory requirements, as well as provide direction for their day-to-day in-house cybersecurity projects. - [Next-Level Data Loss Prevention with Low-Code Security Automation](https://phoenixcyber.com/resources/data-loss-prevention-security-automation/): Watch this on-demand webinar replay to see how low-code security automation can help you streamline your DLP processes and reduce the risk of data loss. - [Jennifer Wesche](https://phoenixcyber.com/about/leadership/jennifer-wesche/): Director of Talent & Operations - [Erick Smith](https://phoenixcyber.com/about/leadership/erick-smith/): Director of Service Delivery - [Rus Shuler](https://phoenixcyber.com/about/leadership/rus-shuler/): Director of IT - [Matt Rodriguez](https://phoenixcyber.com/about/leadership/matt-rodriguez/): Director of Service Delivery - [Nelson Conard](https://phoenixcyber.com/about/leadership/nelson-conard/): Director of Service Delivery  - [Brian Kafenbaum](https://phoenixcyber.com/about/leadership/brian-kafenbaum/): Founder & Managing Partner - [Leadership](https://phoenixcyber.com/about/leadership/): Phoenix Cyber's mission is to provide superior cybersecurity solutions to our customers built on experience, vision, and integrity, while also creating a workplace for employees to share ideas, innovate, and maintain a high quality of life.  - [Phoenix Cyber Named Swimlane’s First SOAR Certified Delivery Partner](https://phoenixcyber.com/about/in-the-news/phoenix-cyber-named-swimlane-soar-certified-delivery-partner/): PHOENIX, ARIZ., April 5, 2023 – Phoenix Cyber, a premier provider of cybersecurity consulting services to enterprises and the federal government, announced today that it has been named Swimlane’s first Certified Delivery Partner as part of its Medley Partner Program to help organizations realize the immense benefits of the Swimlane Low-Code Security Automation platform. This partnership provides Swimlane customers with an opportunity to draw on Phoenix Cyber’s extensive experience in successfully delivering dozens of Swimlane deployments. Phoenix Cyber’s senior-level SOAR experts can help plan, implement, integrate, optimize, and operationalize Swimlane. - [Privacy Compliance Application | Federal Government Case Study](https://phoenixcyber.com/resources/privacy-compliance-case-study/): A very large component of the Department of Defense needed to streamline the process of managing privacy compliance across nearly 400 information technology systems, several of which contain personally identifiable information (PII). For those systems containing PII, the agency needed to prepare the proper privacy compliance documentation and then track and report on privacy compliance key performance indicators (KPIs) as those systems completed the various mandated privacy compliance documentation. Until the Phoenix Cyber solution was delivered, the Agency was using email to manage this process, which was slow, tedious, and difficult to track. The Agency’s Privacy Office did not have a real-time, accurate tracking and reporting system for this documentation, and it took searching through emails and shared file directories to find all of the necessary information. - [Phoenix Data Security, Inc. Modernizes “Phoenix Cybersecurity” Brand](https://phoenixcyber.com/about/in-the-news/phoenix-cyber-rebrand/): PHOENIX, Ariz. – Dec. 20, 2021 – Phoenix Data Security, Inc. modernizes its Phoenix Cybersecurity brand with a new streamlined logo, shorter company name, and matching domain name. The new "Phoenix Cyber" brand simplifies the user experience and streamlines engagement. - [Phoenix Cyber to Present at RSA Conference 2019 in Swimlane Booth](https://phoenixcyber.com/about/in-the-news/rsa-2019/): PHOENIX, Ariz. – Mar. 1, 2019 – Phoenix Cyber was invited to present in the Swimlane booth (#567) during RSA Conference 2019 at the Moscone Center in San Francisco on Tuesday, March 5th and Wednesday, March 6th. Phoenix Cyber’s Matt Rodriguez, Cybersecurity Solutions Architect, will deliver “Addressing SOAR Spots: Turning Pain into Gain” each day. During the presentation, he will discuss how a SOAR Modular App Framework leverages the strengths of an entire security operations team to improve efficiencies, produce automated workflows faster and reduce workflow maintenance. - [SOAR Engineering Principles | Phoenix Cyber](https://phoenixcyber.com/resources/engineering-principles-video/): Watch this 5-minute video to learn about 6 Engineering Principles that we follow when implementing security orchestration, automation and response solutions. - [Resources](https://phoenixcyber.com/resources/): Explore Phoenix Cyber’s curated cybersecurity resources for security operations teams. These guides, case studies, and technical materials provide actionable insights to improve SOC performance, streamline incident response, and maximize the impact of your security tools. Designed for SOC managers and analysts, our resources help you enhance your organization’s overall security posture. - [Phoenix Cyber Invited to Speak at IACD Integrated Cyber Fall 2018 Event](https://phoenixcyber.com/about/in-the-news/iacd-integrated-cyber-fall-2108/): PHOENIX, Ariz. – Sept 27, 2018 – Phoenix Cyber has been invited to present at the Integrated Adaptive Cyber Defense (IACD) Integrated Cyber Fall 2018 event next week at Johns Hopkins University in Maryland. The event provides a forum for collaboration and technical exchange to support the adoption of integrated, automated cyber defenses across the cyber ecosystem. - [Careers](https://phoenixcyber.com/careers/): Phoenix Cyber is a rapidly growing, fully remote cybersecurity consulting firm specializing in cybersecurity automation. While there are other important roles in cybersecurity, we’re usually looking for just two types of cybersecurity experts: - [Phoenix Cyber Joins IACD Integrator Directory for Framework Implementations](https://phoenixcyber.com/about/in-the-news/iacd-framework-cybersecurity-integrator/): PHOENIX, Ariz. – Aug. 9, 2018 – Phoenix Cyber (formerly Phoenix Data Security) joins the IACD Integrator Directory to help government and enterprise organizations deploy the IACD framework. Integrated Adaptive Cyber Defense (IACD) is a strategy and framework to adopt an extensible, adaptive, commercial off-the-shelf (COTS)-based approach to cybersecurity operations. This effort is sponsored by the Department of Homeland Security (DHS) and the National Security Agency (NSA) in collaboration with the Johns Hopkins University Applied Physics Laboratory (JHU/APL). IACD increases the speed and scale of cyber defenses by leveraging automation to enhance the effectiveness of human defenders, moving them outside the response loop into a response planning and approval role “on the loop” of cyber defense. - [Phoenix Cyber to Present Customer Use Cases at Black Hat USA 2018](https://phoenixcyber.com/about/in-the-news/black-hat-usa-2018/): PHOENIX, Ariz. – Aug. 2, 2018 – Phoenix Cyber was selected by Swimlane to present how Security Orchestration, Automation and Response (SOAR) provides real-world value to our clients. Phoenix will be presenting a series of quick, 7-minute presentations on Wednesday, August 8th and Thursday, August 9th in the Swimlane booth (#2304) at Black Hat USA 2018. Phoenix's own Tom Goetz and Matt Rodriguez, both seasoned cybersecurity professionals, will present two different use cases throughout each day. - [Security Operations Blog](https://phoenixcyber.com/blog/): Choosing Between AI or Automation in Security Operations What Actually Works - [Privacy](https://phoenixcyber.com/privacy/): This privacy policy has been compiled to better serve those who are concerned with how their ‘Personally identifiable information’ (PII) is being used online. PII, as used in US privacy law and information security, is information that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context. Please read our privacy policy carefully to get a clear understanding of how we collect, use, protect or otherwise handle your Personally Identifiable Information in accordance with our website. - [CIO-SP3 Contract](https://phoenixcyber.com/government-contractor/cio-sp3/): Phoenix Cyber has strong and relevant past performance in the delivery of cybersecurity services for U.S. Federal Government Agencies. The cybersecurity services we deliver in support of the CIO-SP3 Contract include: engineering, operations, optimization, sustainment and management. Team Phoenix has an extensive base of skilled and experienced technical and project management resources, many of whom maintain security clearances. - [Data Protection Services](https://phoenixcyber.com/services/data-protection/): Data protection refers to the tools, practices, and processes that safeguard sensitive data from unauthorized access, loss, corruption, or misuse. It ensures business continuity, prevents breaches, and keeps you compliant with regulations such as HIPAA, GDPR, PCI DSS, and NIST standards. - [Security Automation and Orchestration Services](https://phoenixcyber.com/services/security-orchestration-automation-response/): Accelerate threat detection, investigation, and response with intelligent security automation that scales your security operations and incident response. - [Phoenix Cyber Named to Federal CIO-SP3 Contract](https://phoenixcyber.com/about/in-the-news/federal-cio-sp3-contract/): PHOENIX, Ariz. – Feb. 28, 2018 – The Chief Information Officer–Solutions and Partners 3 (CIO-SP3) Small Business Government-Wide Acquisition Contract (GWAC) is a ten (10) year Indefinite Delivery/Indefinite Quantity (IDIQ) contract. This contract is intended to provide information technology (IT) solutions and services as defined in FAR 2.101(b) and further clarified in the Clinger – Cohen Act of 1996. These IT solutions and services include, but are not limited to, health and biomedical-related IT services to meet scientific, health, administrative, operational, managerial, and information management requirements. Phoenix Data Security (dba Phoenix Cyber) qualified as a Service Disabled Veteran Owned Small Business (SDVOSB) and will be delivering cybersecurity professional services, operational services, managed services and sustainment services for commercial off-the-shelf cybersecurity applications; and consulting services for cybersecurity strategy, assessments and operational process improvement. - [Services](https://phoenixcyber.com/services/): Phoenix Cyber's cybersecurity services are designed to enhance the overall security posture of your organization and protect it against cyber threats, attacks, and data loss. We assist organizations in identifying, assessing, and mitigating potential risks and vulnerabilities across your enterprise.  - [Home](https://phoenixcyber.com/): Since 2011, Fortune 500 enterprises, federal government agencies, and leading service providers have trusted us to deliver results-oriented, cybersecurity services in the most complex, highly regulated environments. ##