Sutter Security Advisory

Cybersecurity advisory focused on improving security operations, cybersecurity program assessments, incident readiness, and managed security delivery quality.

PEOPLE. AI. PROCESS. TECHNOLOGY.

Modern security operations increasingly have two actors: people and AI. Process governs how their work is performed, while technology enables it.

Who / what does the work
People + AI. People remain accountable for security decisions. AI is increasingly a participant in analysis, investigation, documentation, and other security work, with defined boundaries and human oversight, rather than merely another technology category.
How the work is governed
Process. Responsibilities, decision rights, handoffs, escalation, quality controls, and review determine how work should be performed and where judgment belongs.
What enables the work
Technology. Telemetry, platforms, integrations, and infrastructure give people and AI the information and mechanisms needed to perform the work.

This is an operating lens, not an implementation sequence. AI and traditional automation are evaluated separately because they play different roles and introduce different control needs. Measurement and outcomes span all four dimensions.

Measured by outcomes.

Focused cybersecurity advisory services

Our work focuses on four areas: how cybersecurity programs are directed, how security operations perform, how organizations prepare for incidents, and how managed security services are delivered.

Security Operations Advisory

Assess and improve how security operations perform across people, AI, process, and technology.

Operating model, workforce, detection, alert lifecycle, investigation, escalation, AI, automation, technology, quality, and measurement.

View Details  →

Cybersecurity Program Assessments

Establish a broad, risk-informed view of cybersecurity governance, capabilities, gaps, dependencies, and priorities.

Program-level review aligned primarily to NIST CSF 2.0, including the governance and cyber-risk implications of AI.

View Details  →

Incident Response Readiness

Improve preparedness, decision-making, escalation, communications, technical readiness, and recovery before an incident.

Practical preparation and facilitated learning, not emergency response execution.

View Details  →

Managed Security Provider Advisory

Provider-side advisory for organizations delivering managed security services at scale.

Multi-client operations, service delivery, workforce, quality, customer experience, AI, automation, scalability, and efficiency.

View Details  →

Explore the Services

Explore how each service can be tailored to your organization's needs.

Security Operations Advisory

Overview

Security Operations Assessment & Roadmap

A deep assessment of how the security operation functions across People, AI, Process, and Technology. We examine whether the organization can consistently detect, investigate, escalate, and respond to threats while operating efficiently and producing measurable outcomes.

This is an operating assessment, not simply a review of the technology stack. Tools matter, but only in the context of the people, decisions, workflows, controls, and measurements they enable.

When this is useful

  • Alert volume, backlog, or low-value work is difficult to control.
  • Leadership lacks confidence in SOC performance or cannot see meaningful outcomes.
  • Staffing, tiers, shifts, coverage, investigations, or escalations no longer fit the workload.
  • SIEM, EDR, SOAR, or case-management investments are not producing expected results.
  • The organization is considering greater use of AI or automation and needs appropriate operating controls.
  • An internal SOC and external managed provider are not operating cohesively, or rapid growth has outpaced process maturity.

What we assess

Operating Model & Governance

Organizational structure, ownership, decision rights, tier and role design, operating cadence, and governance.

People & Coverage

Staffing, capacity, shifts, 24x7 or after-hours coverage, skills distribution, management span, handoffs, and on-call expectations.

Detection & Alerting

Detection strategy, telemetry alignment, content ownership and lifecycle, tuning, testing, and recurring false-positive or low-value alert patterns.

Triage & Investigation

Intake, enrichment, assignment, investigation workflow, case quality, disposition, and analyst consistency.

Escalation & Incident Handling

Severity, escalation thresholds, notification, handoffs, incident declaration, and coordination.

AI

Analyst augmentation, assisted triage and investigation, vendor-native AI, agentic workflows, human approval, data boundaries, auditability, failure modes, quality, and demonstrable value.

Automation

SOAR, deterministic workflows, orchestration, repetitive analyst tasks, automation opportunities, and failure points. AI and automation are evaluated separately.

Technology & Integration

SIEM, EDR or XDR, case management, telemetry, integrations, usability, and workflow fit.

Quality, Metrics & Improvement

QA, SLA and KPI design, backlog and aging, investigation quality, operational and executive reporting, and continuous improvement.

Managed Provider Integration

Where applicable, responsibility split, coverage, alert routing, escalation, detection ownership, handoffs, shared tooling, and performance.

What you receive

  • Executive current-state summary.
  • Prioritized findings, strengths, and operational gaps.
  • Target-state operating recommendations.
  • Practical improvement roadmap.
  • Executive readout focused on decisions, risk, and priorities.

Focused reviews

When the problem is already understood, the engagement can be narrowed to a defined operating challenge. Examples include:

  • Managed Security Provider Effectiveness & IntegrationA customer-side review of operational coverage, workflows, detection, handoffs, escalation, tooling, quality, and provider integration.
  • SOC Workforce, Capacity & CoverageWorkload, staffing, skills, scheduling, coverage, handoffs, and sustainability.
  • Detection Coverage & ContentDetection objectives, telemetry, content lifecycle, testing, tuning, coverage, and measurement.
  • Alert Lifecycle & EscalationIntake, triage, investigation, ownership, escalation, documentation, and closure.

Focused reviews are available when the operating challenge is already known.

Discuss Your Scope  →
Cybersecurity Program Assessments

Overview

Cybersecurity Program Assessment & Roadmap

Our broadest organizational assessment evaluates whether the cybersecurity program is appropriately managing material risk and where leadership should focus next. It is broader than the Security Operations Assessment, while intentionally providing less depth inside each individual technical domain.

The assessment is organized primarily around NIST Cybersecurity Framework 2.0:

  • Govern
  • Identify
  • Protect
  • Detect
  • Respond
  • Recover

When this is useful

  • Leadership wants an independent view of overall security posture and priorities.
  • The organization has grown while the security program has evolved informally.
  • A managed provider handles much of security and leadership wants independent validation.
  • Security spending, ownership, or responsibilities across IT, vendors, and internal teams are unclear.
  • Board, executive, insurance, customer, or regulatory pressure is increasing.
  • The organization needs a practical improvement roadmap rather than another checklist.

What we assess

Govern

Ownership, accountability, strategy, policy, risk governance, third-party governance, and executive reporting.

Identify

Assets, critical systems, data, business dependencies, and the organization’s understanding of cyber risk.

Protect

Identity and access, endpoint security, vulnerability and exposure management, data protection, awareness, and core preventive controls.

Detect

Logging, monitoring, detection capability, and managed-provider coverage.

Respond

Incident readiness, escalation, communication, coordination, and decision authority.

Recover

Backups, restoration, resilience, dependencies, and recovery planning.

AI Governance & Cyber Risk

A cross-cutting review of sanctioned and shadow AI, acceptable use, sensitive-data exposure, AI vendor risk, AI-enabled SaaS, agents and machine identities, security involvement in adoption, AI-enabled threats, and defensive AI use.

Scope boundary

Broad assessments identify. Domain assessments investigate. Focused reviews diagnose deeply.

This is a program-level, risk-informed assessment using interviews, documentation, representative evidence, and targeted validation. It is not automatically an exhaustive technical audit, penetration test, source-code review, full cloud configuration or identity architecture assessment, compliance certification, or audit opinion.

If a material issue is identified, we may recommend a deeper review or support from a qualified specialist.

What you receive

  • Executive posture summary.
  • Material strengths, gaps, and prioritized findings.
  • Business-aligned recommendations.
  • Target-state priorities and practical roadmap.
  • Executive readout focused on risk and decisions.

Areas for deeper review

  • Governance, Strategy & Executive Reporting
  • Managed Security Provider Effectiveness & IntegrationA customer-side program review of provider governance, scope, responsibility, performance, and value.
  • Third-Party Cyber Risk
  • Identity & Access Program
  • Vulnerability & Exposure Management Program
  • Resilience & Recovery
  • AI Governance & Cyber Risk

When deeper analysis is needed, reviews can focus on the specific area or decision at hand.

Discuss Your Scope  →
Incident Response Readiness

Overview

Incident Response Readiness prepares the organization before a serious cyber incident. We help leadership and technical teams clarify roles, improve decision-making, test assumptions, and identify gaps before they are forced to do so under pressure.

Engagement options

When this is useful

  • The incident response plan has not been tested recently.
  • Leadership is unclear about roles or decision authority during a breach.
  • Cyber-insurer, customer, or other stakeholder expectations are increasing.
  • Technical and executive teams have never practiced together.
  • Third-party dependencies, communications, or recovery responsibilities are unclear.
  • Major organizational, provider, or technology changes have occurred.

What we assess

Plans, Roles & Authority

Plans and playbooks, stakeholder responsibilities, severity, escalation thresholds, incident declaration, and executive decision rights.

Communications & Coordination

Internal and external communications, legal, insurance and vendor coordination points, emergency contacts, and cross-functional handoffs.

Technical Readiness

Detection and escalation inputs, evidence considerations, access, tooling, technical coordination, and operational dependencies.

Recovery & Learning

Recovery dependencies, restoration decisions, exercise observations, after-action review, and improvement ownership.

What you receive

Depending on the agreed scope, outputs can include:

  • Readiness findings and prioritized improvements.
  • Facilitated scenario-based exercise.
  • Exercise observations and after-action findings.
  • Practical improvement roadmap.
  • Executive readout.

Service boundary

This service focuses on preparedness and advisory. It does not include breach counsel, DFIR, forensic acquisition, malware analysis, ransomware negotiation, or 24x7 emergency response.

Discuss Your Scope  →
Managed Security Provider Advisory

Overview

Managed Security Operations & Service Delivery Assessment

Organizations delivering managed security services face operating challenges that an internal SOC assessment does not fully capture: multiple clients, service tiers, variable workloads, contractual SLAs, customer communications, multi-tenant technology, quality consistency, onboarding, and the need to scale without degrading outcomes.

We evaluate the operation as both a security function and a repeatable managed service. We work with MSSPs, MDR providers, managed SOC providers, and other organizations delivering managed security services.

This service is designed for organizations delivering managed security services. Organizations evaluating an external provider can instead engage us for a Managed Security Provider Effectiveness & Integration Review focused on scope, governance, integration, performance, and value.

When this is useful

  • Rapid client growth is stressing the operating model, workforce, or service quality.
  • Quality differs across analysts, shifts, teams, or customers.
  • Staffing and capacity planning are unclear, or SLAs do not reflect meaningful outcomes.
  • Client onboarding is inconsistent, slow, or difficult to transition into steady-state operations.
  • Tooling and workflows do not scale cleanly across customers, service tiers, or multiple SOCs.
  • Leadership is redesigning services or introducing AI and automation without sacrificing quality.

What we assess

Service Operating Model

Organization, roles, management structure, service ownership, governance, and operating cadence.

Client Segmentation & Service Tiers

Service definitions, customer segmentation, dedicated and shared models, responsibilities, and entitlement differences.

Workforce, Capacity & Coverage

Staffing model, workload distribution, 24x7 coverage, shifts, tiers, analyst capacity, management span, and growth assumptions.

Multi-Client Workflows

Alert routing, queues, case management, assignment, handoffs, client context, and standardization.

Detection Operations

Ownership, shared and client-specific content, tuning, content lifecycle, telemetry variability, and feedback loops.

Escalation & Client Notification

Severity, escalation, SLAs, notification, client-specific procedures, and emergency contacts.

Quality & Consistency

QA, case quality, rework, escalation quality, shift consistency, and service consistency across clients.

SLAs, KPIs & Reporting

Meaningful service measures, SLA structure, operational and customer reporting, and executive visibility.

Client Onboarding & Integration

Intake, requirements, telemetry, playbooks, escalation procedures, and handoff into steady-state operations.

Technology & Multi-Tenancy

SIEM, EDR, SOAR and case platforms, integrations, multi-tenant workflows, usability, and scalability.

AI

Analyst augmentation, triage and investigation assistance, consistency, customer-context handling, data segregation, human oversight, quality, and measurable operational value.

Automation

Orchestration, repetitive analyst work, enrichment, routing, notification, scalable deterministic workflows, and failure handling.

Scalability & Operational Efficiency

Bottlenecks, capacity constraints, process friction, standardization, operational leverage, and continuous improvement.

What you receive

  • Current-state service-delivery assessment.
  • Prioritized operational findings.
  • Scalability and consistency gaps.
  • Target-state operating recommendations.
  • Practical improvement roadmap.
  • Executive readout.

The work focuses on security operations and managed-service delivery, not M&A, valuation, or financial advisory.

Discuss Your Scope  →

Who We Help

Security Leaders, Teams & SOCs

Teams seeking a rigorous outside view of security operations, detection and response, readiness, AI adoption, or a specific performance challenge.

Growing & Mid-Market Organizations

Organizations that need a clearer view of program risk, priorities, provider arrangements, and the practical path to stronger cybersecurity capabilities.

Managed Security Providers

Security-service organizations improving multi-client operations, service delivery, scalability, quality, customer experience, AI use, or operational efficiency.

Consulting Firms & Technology Providers

Organizations that need senior security operations expertise for subcontract, white-label, subject-matter expertise, workshop, assessment, or client-facing work.

Flexible Ways to Engage

Drew Sutter

Led by Drew Sutter

I’ve spent my career building, scaling, and leading security operations.

I started in SIEM, detection, and security consulting before moving into SOC leadership and progressively larger operational mandates. That included leading North American SOC and NOC operations within a global follow-the-sun model, and later a 24x7 security operations organization of 50 supporting more than 250 enterprise clients.

Across those roles, the constant has been scale: larger teams, more complex environments, more clients, and higher expectations for operational maturity and performance.

Today, I work at the intersection of security operations and business risk, translating between the technical realities analysts face and the priorities executives need to understand.

View Drew's professional background

Selected operating scale from Drew Sutter's career

12+ Years
Cybersecurity & Security Operations
50-Person Operational Scale
Led a 50-person 24x7 SOC, with broader leadership spanning multiple SOCs, NOC operations, embedded analyst teams, and security consultants.
250+ Enterprise Clients
Led managed security services for 250+ enterprise clients, with additional enterprise and public-sector client leadership across prior roles.

Let's talk about what you're trying to solve.

Whether you need to improve security operations, assess a cybersecurity program, strengthen incident readiness, or improve managed security delivery quality, start with a conversation about the situation.

Share the challenge, the kind of support you are considering, and any relevant timing.

For your security, please don't send credentials or sensitive incident data by email.

San Diego, California · Remote and select on-site engagements available