Someone has to own
security.
It doesn’t have to be
a full-time hire.

Cybersecurity is simply risk mitigation. Strip away the complexity and that's what's left.

I’m an independent security advisor for Louisiana healthcare organizations and the vendors who serve them. I sell no products, resell no tools, and hold no vendor relationships — so an assessment from me is a finding, not a sales pitch.

270,000
Patients exposed, Lake Charles Memorial
7
LSU Health sites hit via one mailbox
$103K
OCR penalty, 1,980-patient breach

Sources: LCMHS breach notice (2022) · LSU Health notice (2020) · HHS OCR settlement (Feb 2026)

For healthcare leaders
  • Your Security Risk Analysis is out of date, or you have never had one
  • MIPS attestation is due and the analysis has to be current
  • No security leader on staff, or one who is overwhelmed in the role
  • Your board or governing body needs to understand actual exposure
Book a Free Consultation
For cybersecurity professionals
  • Technical depth already, looking to add the programmatic layer
  • Reasoning about risk, frameworks, and compliance as systems, not checklists
  • Communicating with leadership, auditors, and external partners credibly
  • Building program-level credibility inside or outside your current organization
Explore Training Programs →

The reasons people call me
and the deadline attached to each one

Not hypotheticals. These are the situations that generate the call, stated plainly, with the rule or the number behind each one.

🔍

Your Security Risk Analysis is out of date, or you never had one

OCR runs a Risk Analysis Initiative and has designated at least fourteen enforcement actions under it since late 2024. In February 2026 it settled with a behavioral health provider for $103,000 over a breach affecting 1,980 patients. The penalty scales to the failure, not the patient count.

📋

MIPS attestation is due and the analysis has to be current

The Security Risk Analysis measure is pass/fail. Miss it and you forfeit the entire 25% Promoting Interoperability category — CMS says so explicitly, “regardless of whether other measures in this category are reported.” A prior-year analysis does not carry forward. And for performance year 2026 there are now two attestations: the analysis, and the risk management you did about it.

⚖️

In Louisiana, a HIPAA gap is also a licensing problem

LAC 48:I.9393 requires hospitals to protect records under HIPAA and any Louisiana standard that is more stringent. That turns a federal compliance failure into a state licensing deficiency an LDH surveyor can cite. Rural Health Clinics and behavioral health providers carry parallel provisions. Almost nobody selling into this state mentions it.

🧯

An incident response plan that has never been run is just a document

Every organization has one on paper. Almost none have put it under pressure, which is why the gaps surface during the actual incident. Your carrier will also ask whether you have run a tabletop in the last twelve months, and the after-action report is the artifact they want to see.

💸

A full-time CISO costs more than the risk you are managing

A qualified Chief Information Security Officer commands $250,000 or more a year. For a twenty-five person practice that is not a budget decision, it is an impossibility. Fractional leadership is the only way that function gets covered at all — and HIPAA lets you name someone outside your organization to hold it.

🤝

You are a business associate, and OCR is coming for you directly

Billing companies, EMR vendors, IT providers, data hosts. OCR has settled with all of them under the Risk Analysis Initiative — ambulance billing at $75,000, EMR and billing support at $80,000, a data hosting and IT support firm at $90,000. Your clients’ obligations flow down to you, and your BAA says so.

270,000
Patients exposed at Lake Charles Memorial Health System, 2022. The health system blocked the encryption. The data was already gone.
7
LSU Health facilities across Louisiana reached through a single compromised employee mailbox, 2020. Social Security numbers exposed.
5 months
How long St. Landry Parish schools waited to notify victims — past the 60-day legal deadline, and only after a newspaper investigation brought in the Attorney General.
14%
Of covered entities were substantially fulfilling the risk analysis requirement in OCR’s own audits. Five in six could not demonstrate one.

Three offerings. One mandate.
Reduce actual risk.

Fixed scope, fixed fee, fixed timeline — and the price is published, because you should not have to book a call to find out what something costs. As far as I can tell, no other firm in Louisiana publishes theirs.

Strategic Security Advisory
🎖️

vCISO and Executive Consulting Service

$2,500 – $7,500 / month

Senior security leadership without the overhead of a full-time hire. I hold the named role for organizations required to designate one — HIPAA Security Officer, GLBA Qualified Individual, Louisiana Insurance Data Security responsible person. Board and executive risk communication, security roadmap, governance, IR readiness, and correspondence with regulators and auditors. Three tiers depending on your size and how many frameworks you answer to.

Compliance Steward $2,500 · Fractional Security Officer $4,500 · Embedded Leadership $7,500. Initial 90 days, then 30 days’ notice.

Executive Leadership Board Reporting Security Posture IR Readiness Risk Governance Strategic Roadmap
Security Readiness

Policy, Frameworks, Risk, Tabletops

$2,750 – $12,500 fixed fee

Fixed-scope project work for organizations facing a deadline. Every engagement below is a published price, a defined deliverable, and a stated timeline.

HIPAA Security Risk Analysis — practice$6,500
HIPAA SRA — CAH, FQHC, multi-site$12,500
NIST CSF 2.0 gap assessment$8,500
Cyber insurance readiness review$3,500
Incident response tabletop exercise$2,750

Also working in NIST 800-53, NIST 800-171, CMMC 2.0, CJIS, IRS Publication 1075, FFIEC, FINRA, ISO 27001, and PCI-DSS. Scope changes are quoted before any work begins — there are no hourly surprises.

Policy Sets Audit Readiness Gap Analysis Risk Assessment Tabletop / TTX Remediation Plan
Cybersecurity Workforce Upskilling
🎓

Programmatic Cybersecurity for Technical Professionals

Scoped per cohort

One curriculum, two delivery formats. The curriculum covers programmatic cybersecurity topics: risk, frameworks, compliance, governance, and the business layer of security. Built for technical professionals who already have the depth and want to extend their value into the program level. Sold to organizations as In-House Teams training, or to individuals and small groups as scheduled cohorts. See training details →

In-House Teams Individual Cohorts Risk Reasoning Framework Literacy Compliance Business Layer

From first call to
a functioning program

A structured process built for people who do not have time for a long one. No jargon, no surprises, no deliverable that sits in a drawer.

🗓
1

Discovery Call

Thirty minutes on your situation, your obligations, and whether I am the right fit. If you would be better served by someone else, I will tell you that on this call.

🔎
2

Assessment

Fixed fee, fixed scope, from the table above. Findings prioritized by business impact rather than scanner severity. You get a finished deliverable whether or not anything follows it.

📐
3

Roadmap

Every recommendation mapped to a business outcome and sequenced so you know what to do first and why. For HIPAA work this is the Risk Management Plan — OCR cites the failure to act as often as the failure to assess, so it is included, not upsold.

🚀
4

Execute & Mature

Optional, always. A retainer if you want the program owned and maintained — controls implemented, auditors satisfied, board briefed, and the program kept current as you and the threat environment change.

Built on operator
experience

I started Red Stick Cyber on a specific premise: security programs built around compliance theater and technical complexity for its own sake don't protect organizations. They just create the appearance of doing so.

Across 29 years in IT and cybersecurity — U.S. Army, government contracting, and the commercial sector, with organizations in government, defense, healthcare, financial services, and transportation — security has always had one job. Support the mission, not compete with it. You identify the risks that matter to what you are trying to accomplish, you reduce them to an acceptable level, and you maintain that posture. Everything else is overhead.

I built this as a Louisiana practice deliberately. The organizations here that most need security leadership — rural clinics, independent practices, small hospitals, the billing companies and IT shops that serve them — are the ones national firms will not staff and local IT companies cannot objectively advise, because they sold the equipment they would be assessing. I have nothing to sell but the assessment. That is the whole reason this exists.

That is the standard I hold every engagement to. No manufactured urgency, no vendor-aligned recommendations, no deliverable designed to justify the work. An honest assessment of where you are, where you need to be, and the most direct path between the two.

🛡️
Stanley Smith, Founder — CISSP
Certified Information Systems Security Professional
🎓
Master's & Bachelor's in Cybersecurity
Western Governors University, plus BBA
29 Years in IT and Cybersecurity
U.S. Army, government contracting, and commercial sector, working with organizations in government, defense, healthcare, financial services, and transportation
🏢
SDVOSB · LaVetBiz · Hudson Initiative
Service-Disabled Veteran-Owned Small Business via SBA VetCert. Louisiana veteran-owned and small entrepreneurship certified. SAM registered. UEI Z81WJ7YB4YQ7 · CAGE 1AQY6
Frameworks I work in
NIST CSF
2.0
HIPAA
Health Data
FINRA
Financial
FFIEC
Banking
NERC/FERC
Energy
ISO 27001
Info Security
ISO 42001
AI Management
CMMC
Defense
PCI-DSS
Payments
Based in
Prairieville, Louisiana
Serving Louisiana and the Gulf South

The technical depth you have.
The programmatic layer you build on top.

The substance of cybersecurity as a discipline lives at the program level. Risk, frameworks, compliance, governance, and the business layer of security decisions. This is what I teach. Built for cybersecurity and IT professionals who already have the technical depth and want to extend their value into the program layer.

🏢

In-House Teams

Multi-session intensive built around your organization's cybersecurity, IT, and adjacent staff. The organization sponsors. Staff are the students. Curriculum tuned to your environment. Suitable for IT and security directors building program capability across a team, or organizations that want their workforce to understand cybersecurity at the program level rather than the task level.

Org-Sponsored Custom Cases Team Capability Program Literacy
👥

Individual and Group Cohorts

Scheduled cohort program for individual professionals or small groups of up to twelve. Sessions run on a published schedule. Self-enrollment and small-group enrollment both supported. Suitable for individual cybersecurity and IT professionals who want to add the program-level layer to their existing technical depth.

Public Cohorts Self-Enroll Small Groups Scheduled Sessions

Ready to build the programmatic layer?

Training engagements are built around your situation. Where you are, where you want to operate, and what is standing between the two. Start with a conversation.

Get in Touch About Training

Find out where you stand.
No call required.

Would your Security Risk Analysis survive an OCR investigation? A fourteen-point self-check against the HIPAA Security Rule, with the exact CFR citation for every requirement and a plain explanation of what it actually demands. Including the three things most practices get wrong: that HIPAA does not require an annual risk analysis, that “addressable” does not mean optional, and that you can outsource the Security Officer role but not the liability.

No form. No follow-up sequence. Take it and use it.

Free Consultation, No Obligation

Ready to put security
leadership in place?

Thirty minutes on where you are, what a regulator would say about it, and what would make the most difference. You will be talking to the person who does the work, because there is only one of us. No vendor pitch, no obligation.

No commitment required
100% confidential
Executive-level conversation

Prefer to write first?

Send a message and I will respond within one business day. For training inquiries, mention your current role and where you're trying to take it.

General: info@redstickcyber.com

Training: training@redstickcyber.com

I respond within one business day. Your information stays with Red Stick Cyber, LLC.