CMBNetworks is the independent practice of Corey Bobb, a cybersecurity executive with 20 plus years leading security programs across Fortune 15 enterprise, critical infrastructure, financial services, and healthcare organizations. Former CISO, Former CTO, HIPAA/HITRUST Lead Assessor, PCI-DSS QSA, ISO 42001 AIMS Lead Auditor.
Twenty years of executive and hands-on cybersecurity leadership across critical infrastructure, Fortune 15 enterprise, financial services, and healthcare. Former CISO at WMATA, the second largest transportation organization in America. Lead HIPAA/HITRUST assessor across 25 plus healthcare organizations. AI governance program architect at a Fortune 15 enterprise. Congressional testimony on enterprise security risk.
The technical foundation is equally deep. Python automation tools built and deployed in production. Hands-on experience across Palo Alto, Cisco, Juniper, Splunk, CrowdStrike, Azure, and AWS. Capable of operating at the board level and in the technical details of an engagement.
Private sector only. Remote-first. Available for select engagements in healthcare, financial services, technology, legal services, and government contractors.
Partner With Us TodayPart-time security leadership including strategy, executive reporting, policy ownership, vendor risk, incident response oversight, and board-level communication. Aligned to NIST CSF, ISO 27001, and applicable regulatory frameworks.
Full readiness assessment and remediation roadmap for HITRUST r2 certification. Delivered by a credentialed HITRUST CCSFP with lead assessor experience across 25 plus healthcare organizations and all 19 control domains.
Gap assessment, policy development, evidence framework, and audit preparation for SOC 2 Type I or Type II. Control mapping, vendor assessment support, and auditor liaison included.
End-to-end AI governance program aligned to ISO 42001 AIMS and NIST AI RMF. Toolchain risk assessment, data intake controls, prompt injection awareness, usage policy design, and executive reporting.
Scoping, gap assessment, remediation roadmap, and audit preparation. Delivered by a former PCI-DSS QSA. Covers cardholder data environment scoping, control validation, and evidence packaging.
NIST CSF, NIST 800-53, and NIST 800-171 program assessment and implementation for commercial organizations, government agencies, and federal contractors. Includes gap assessment, control mapping, SSP development, and POA&M management.
Targeted advisory for specific security challenges. M&A due diligence, incident response planning, third-party risk program build, security architecture review, or board-level risk reporting.
HIPAA, HITRUST CSF, PCI-DSS, SOC 2, NIST CSF, NIST 800-53, NIST 800-171, ISO 27001, ISO 42001, CIS Controls, GLBA, DFS 23 NYCRR 500, GDPR, CJIS, DHS/SCADA.
Whether you are a healthcare organization preparing for HITRUST, a government contractor navigating CMMC and NIST 800-171, a fintech company under PCI-DSS scope, or a growth-stage company approaching your first SOC 2 audit, CMBNetworks brings direct assessor and practitioner experience across the frameworks that matter to your business.
Talk through what you are trying to solve and whether there is a fit. No charge. No obligation. Usually 30 minutes.
A clear proposal with defined scope, deliverables, timeline, and pricing.
Work starts on a defined schedule. Retainer clients get a regular cadence. Project work moves toward the defined deliverable.
Every engagement ends with documentation you own. Policies, frameworks, roadmaps, and evidence packages that outlast the engagement.
Reach out directly or use the chat widget below.