RedOps Cyber Intelligence Group
Executive security leadership for the AI era.
RedOps gives businesses of every size a fractional CISO who owns strategy, compliance, and AI risk — the security leadership boards, buyers, and regulators now expect, without the full-time executive price tag. Led by Dr. Sam Wertheim.
Focus areas — vCISO leadership · AI security & governance · SOC 2 · ISO 27001 · NYDFS §500 · HIPAA · Penetration testing
Doctorate
D.Cybersecurity — GenAI threat research
18+ years
in security leadership
Top 1%
Expert-Vetted CISO
7 frameworks
SOC 2 · ISO 27001 · NYDFS · HIPAA · GDPR · PCI · NIST AI RMF
The moment
AI changed the threat. Regulators noticed.
Attacks are AI-accelerated
Phishing emails, voice clones, and deepfakes are now machine-generated and convincing. 83% of organizations experienced a phishing attack in a single year (Proofpoint).
Breaches cost real money
The average breach runs $4.76M (IBM Cost of a Data Breach) — before the reputation damage and customer churn that follow.
Regulators moved first
EU AI Act obligations are phasing in, NYDFS has issued AI guidance, and incident-disclosure clocks are measured in days. "We're working on it" is no longer an answer.
What we do
Our services
Fractional CISO Leadership
A named security executive who owns your program — strategy, compliance, vendors, incidents — and answers for it to your board, your buyers, and your regulators.
Learn more → GRCGovernance, Risk & Compliance
Compliance that closes deals. SOC 2, ISO 27001, NYDFS §500, HIPAA — built around how your business actually operates, and maintained so audits stop being fire drills.
Learn more → AI SecurityAI Security & Governance
Your team is already using AI; your attackers are too. We put guardrails on the first and defenses against the second — policy, tool vetting, and deepfake-resistant operations.
Learn more → OffensiveRisk Assessment & Penetration Testing
Find the gaps before an adversary does. Real-world attack simulation across networks, web apps, and cloud — reported in language both engineers and boards can act on.
Learn more →How we engage
A program, not a pile of PDFs.
01
Assess
A baseline of your posture, obligations, and real risks — in the first 30 days.
02
Roadmap
A prioritized, right-sized plan mapped to the frameworks that actually apply to you.
03
Operate
We run the program — controls, vendors, incidents, evidence, and staff training.
04
Report
Quarterly board-ready reporting that stands up to auditors, buyers, and examiners.
// First consultation is free