Cybersecurity Consulting for SMBs

Enterprise Security Expertise,
Built for SMBs.

Senior practitioners with 30+ years of combined experience delivering incident response, compliance, and vCISO services to organizations in high-risk industries — at pricing built for your scale.

HIPAA PCI-DSS NIST CSF CMMC SATCOM
0%

of small businesses experienced a cyberattack in 2023

0%

of breached SMBs go out of business within 6 months

0+

years combined practitioner experience on your team

Who We Are

Real Practitioners.
Transparent Pricing.

Defense In Orbit is a cybersecurity consulting firm built for the gap in the market: organizations that face real threats and real regulatory risk, but can't access enterprise-level security help. Large vendors price them out. Generalist IT firms lack the depth. We fill that gap.

Our team brings hands-on expertise from the front lines of incident response, detection engineering, and security compliance at leading cybersecurity firms. We don't staff engagements with junior analysts — every client works directly with senior practitioners who have done this work in production environments.

Senior practitioners on every engagement — not junior analysts
Flat-fee and retainer pricing built for SMB budgets
Deep expertise across HIPAA, PCI-DSS, NIST, and CMMC
Emerging space cybersecurity practice — SATCOM & OT/ICS

Our Mission

"We provide future-forward, expert-level cybersecurity consulting services to SMBs — helping them mitigate real risk, achieve regulatory compliance, and build a security culture that holds up when it matters most."
Sec+ CySA+ CCNA Network+ A+ InsightVM

What We Do

Our Services

Every service is delivered by senior practitioners with direct, hands-on experience — not entry-level talent reading from a playbook.

Incident Response & Forensics

24/7 breach response, root cause analysis, remediation planning, and forensic reporting suitable for insurance claims and legal proceedings. IR retainers provide guaranteed SLAs and a pre-engaged team that already knows your environment.

24/7 Response Guaranteed SLAs Forensic Reporting

Compliance Consulting

Gap assessments, policy development, third-party risk management, and readiness work across HIPAA, PCI-DSS, NIST CSF, and CMMC. We deliver practical compliance programs — not paper exercises that won't hold up under an audit.

HIPAA PCI-DSS NIST CSF CMMC

Advisory & vCISO Services

Virtual CISO packages, quarterly security reviews, risk assessments, and ongoing improvement roadmaps. Senior-level security leadership for organizations that need consistent guidance without the cost of a full-time CISO hire.

vCISO Retainer Quarterly Reviews Risk Roadmaps

Security Awareness Training

Industry-tailored phishing simulations, monthly training modules, and custom sessions for executives and staff. Content is built around the specific threat landscape of your industry — not generic off-the-shelf material.

Phishing Simulations Executive Training Custom Modules

Who We Serve

Industries We Specialize In

Our clients are 10–250 person organizations in regulated, high-risk industries. We understand the threat landscape and compliance obligations specific to each sector.

Healthcare

HIPAA compliance, ransomware response, PHI protection, and vendor risk management.

Finance

PCI-DSS compliance, fraud detection posture, incident response, and regulatory readiness.

Legal

Client confidentiality protection, data loss prevention, secure communications, and access control.

Education

FERPA compliance, endpoint security, phishing defense, and student data protection.

Manufacturing

OT/ICS security, supply chain risk management, IP protection, and network segmentation.

Aerospace & Defense

SATCOM security, ground segment protection, CMMC compliance, and firmware analysis for space-adjacent systems.

Our Founders

The Team

Every engagement is staffed by the people who built this firm — senior practitioners who have done this work in production environments at leading cybersecurity organizations.

Liliana Albright

Co-Founder & Principal Consultant

10+ years in cybersecurity consulting spanning incident response, detection engineering, security awareness training, and compliance audits. Leads business operations, signals research, and client-facing engagements.

Sec+CySA+A+CCNA

Emily Grey

Co-Founder & Principal Consultant

10+ years in cybersecurity consulting with a background in incident response, compliance auditing, and infrastructure security. Leads threat research, consulting delivery, and technical infrastructure.

Sec+CySA+A+Network+

Jose Mejia

Co-Founder & Principal Consultant

10+ years in cybersecurity consulting with a background in incident response, compliance, and vulnerability management. Leads the vulnerability management practice and contributes to compliance consulting.

Sec+CySA+InsightVM

Knowledge Base

Latest Insights

Practical security intelligence from practitioners who work in the field.

Stay Sharp

Subscribe for Threat Intel

Get practical threat intelligence, compliance updates, and practitioner perspectives — no sales pitch, just signal.

Subscribe Below

Stay Informed

Threat Intel Briefings

Our monthly digest delivers curated advisories, emerging CVEs, and sector-specific alerts written by practitioners — not a marketing team. No sales pitch. Unsubscribe anytime.

  • Emerging CVEs and exploits relevant to SMB environments
  • Compliance deadline reminders and regulatory updates
  • Practitioner commentary on active threat campaigns

Monthly cadence. No spam. Unsubscribe at any time.

Common Questions

Frequently Asked Questions

Get In Touch

Schedule Your Free
30-Minute Consultation

Talk directly to a senior practitioner about your security challenges. No sales pitch — a real conversation about your risk posture and what it would take to address it.

No commitment required. You'll speak directly with a senior practitioner.