CMBNetworks LLC — United States — Remote
Washington DC • Miami, FL • Philadelphia, PA
Fractional CISO & Cybersecurity Advisory
Senior security leadership for organizations that need executive-level judgment without a full-time hire. HIPAA/HITRUST, PCI-DSS, SOC 2, NIST, and AI/LLM Governance.
Start a Conversation View Services
Programs that pass audits the first time.
Frameworks that hold up under real scrutiny.
Security leadership without the full-time overhead.
Compliance programs built by someone who has been on both sides of the assessment table.
Board-ready risk reporting that executives actually understand.
AI governance programs built before regulators started asking.
Security that enables the business instead of slowing it down.
HITRUST readiness from a credentialed lead assessor, not a generalist.
PCI-DSS compliance from someone who has run QSA audits.
A fractional CISO who can still read the firewall logs.
About Us
Who We Are

CMBNetworks is the independent practice of Corey Bobb, a cybersecurity executive with 20 plus years leading security programs across Fortune 15 enterprise, critical infrastructure, financial services, and healthcare organizations. Former CISO, Former CTO, HIPAA/HITRUST Lead Assessor, PCI-DSS QSA, ISO 42001 AIMS Lead Auditor.

Twenty years of executive and hands-on cybersecurity leadership across critical infrastructure, Fortune 15 enterprise, financial services, and healthcare. Former CISO at WMATA, the second largest transportation organization in America. Lead HIPAA/HITRUST assessor across 25 plus healthcare organizations. AI governance program architect at a Fortune 15 enterprise. Congressional testimony on enterprise security risk.

The technical foundation is equally deep. Python automation tools built and deployed in production. Hands-on experience across Palo Alto, Cisco, Juniper, Splunk, CrowdStrike, Azure, and AWS. Capable of operating at the board level and in the technical details of an engagement.

Private sector only. Remote-first. Available for select engagements in healthcare, financial services, technology, legal services, and government contractors.

Partner With Us Today
CISO Experience
Former CISO at WMATA, 2nd largest transportation organization in the United States
Healthcare GRC
Fortune 15 enterprise, HIPAA/HITRUST expert
AI Governance
ISO 42001 AIMS Lead Auditor, built at enterprise scale
PCI-DSS QSA
Former qualified security assessor
Python Automation
Production tools, not just policy writing
Congressional Testimony
Testified before U.S. legislative subcommittees on enterprise security risk
What We Do
Our Services

Fractional CISO Retainer

Part-time security leadership including strategy, executive reporting, policy ownership, vendor risk, incident response oversight, and board-level communication. Aligned to NIST CSF, ISO 27001, and applicable regulatory frameworks.

Starting at $5,000/month — 10 to 20 hrs/month

HIPAA / HITRUST Readiness

Full readiness assessment and remediation roadmap for HITRUST r2 certification. Delivered by a credentialed HITRUST CCSFP with lead assessor experience across 25 plus healthcare organizations and all 19 control domains.

Fixed-scope — from $15,000

SOC 2 Readiness

Gap assessment, policy development, evidence framework, and audit preparation for SOC 2 Type I or Type II. Control mapping, vendor assessment support, and auditor liaison included.

Fixed-scope — from $12,000

AI / LLM Governance

End-to-end AI governance program aligned to ISO 42001 AIMS and NIST AI RMF. Toolchain risk assessment, data intake controls, prompt injection awareness, usage policy design, and executive reporting.

Fixed-scope — from $10,000

PCI-DSS Compliance

Scoping, gap assessment, remediation roadmap, and audit preparation. Delivered by a former PCI-DSS QSA. Covers cardholder data environment scoping, control validation, and evidence packaging.

Fixed-scope — from $8,000

NIST Compliance

NIST CSF, NIST 800-53, and NIST 800-171 program assessment and implementation for commercial organizations, government agencies, and federal contractors. Includes gap assessment, control mapping, SSP development, and POA&M management.

Fixed-scope — from $10,000

Security Program Advisory

Targeted advisory for specific security challenges. M&A due diligence, incident response planning, third-party risk program build, security architecture review, or board-level risk reporting.

$200 to $350/hr or fixed-scope
Credentials
Certifications
CISSP — (ISC)2
Active
C-CISO — EC-Council
Active
HIPAA/HITRUST CCSFP — HITRUST Alliance
Active — Lead Assessor Experience
ISO 42001 AIMS Lead Auditor
AI Management Systems — Active
CCNA — Cisco
Routing and Switching — Active
Former PCI-DSS QSA
Former SOC Auditor — SOC 1 and SOC 2
Frameworks
Coverage

HIPAA, HITRUST CSF, PCI-DSS, SOC 2, NIST CSF, NIST 800-53, NIST 800-171, ISO 27001, ISO 42001, CIS Controls, GLBA, DFS 23 NYCRR 500, GDPR, CJIS, DHS/SCADA.

Whether you are a healthcare organization preparing for HITRUST, a government contractor navigating CMMC and NIST 800-171, a fintech company under PCI-DSS scope, or a growth-stage company approaching your first SOC 2 audit, CMBNetworks brings direct assessor and practitioner experience across the frameworks that matter to your business.

Process
How It Works
01

Initial Conversation

Talk through what you are trying to solve and whether there is a fit. No charge. No obligation. Usually 30 minutes.

02

Scoped Proposal

A clear proposal with defined scope, deliverables, timeline, and pricing.

03

Engagement Begins

Work starts on a defined schedule. Retainer clients get a regular cadence. Project work moves toward the defined deliverable.

04

Delivered and Documented

Every engagement ends with documentation you own. Policies, frameworks, roadmaps, and evidence packages that outlast the engagement.

Ready to Talk?

Reach out directly or use the chat widget below.

corey@cmbnetworks.net 407.551.9139 LinkedIn
CMBNetworks
Ask about our services
Hi there. I am the CMBNetworks assistant. I can answer questions about our cybersecurity advisory services, pricing, and credentials. How can I help you?
Powered by AI — CMBNetworks LLC