Protection that doesn't wait for business hours.

Your competitors have a SOC.
Now you do too.

Texas businesses can't afford to be breached for 207 days. We make sure they never are. 24/7 cybersecurity for businesses that can't afford to be the headline.

24/7 SOC Monitoring
30-min Response SLA
30+ Years Experience
Get your free assessment → Compare us vs competitors →
Review-derived themes
Responsive when issues need attention
Technical expertise for complex security environments
Incident response when it matters
Compliance guidance for practical next steps
Proactive monitoring before problems escalate
Start your assessment

We're not an IT
company that added
"cybersecurity."

We were intelligence analysts, cyber architects, and combat operators before we ever took a single client. Security is not our service offering — it's the only thing we do.

CoreRecon was built to fill the gap that MSPs leave wide open: real cybersecurity expertise, not antivirus checklists and "we also do security" as a footnote in your IT contract.

"

In a world where a single cyber-attack can cripple businesses, damage reputations, and cost millions, can you afford to rely on just one or two layers of defense?

JM
John Martinez
CEO & Founder, CoreRecon
U.S. Marine Corps Veteran
AT&T vendor for State of Texas incident response
City of Carrollton cyber-attack recovery — credited publicly
11–50 employees, federal & commercial clients

Protection at every scale.

Sentinel
$89/endpoint/mo
Min 10 endpoints = $890/mo
  • 24/7 SOC monitoring
  • Threat detection & triage
  • Incident response
  • Monthly reporting
Command
$2,500/mo min
Enterprise-grade, co-managed
  • Co-managed SOC
  • Custom SLAs
  • 30-min response guarantee
  • Compliance automation

Free security posture assessment

Valued at $2,500 — no catch, no obligation. See exactly where your network is exposed before a real threat does.

Claim your free assessment →

Security that works
before the breach

24/7 Security Operations

Always-on monitoring through our SecurityCore+ platform. Real analysts hunting threats, not just tools running in the background.

CMMC & NIST Compliance

Gap assessments, SPRS scoring, Plan of Action & Milestones, and full CMMC 2.0 readiness. We speak DoD.

Penetration Testing

Internal and external assessments. We find the gaps before the attackers do — then we help you close them.

Incident Response

When a breach happens, every minute counts. Our team goes to work immediately — containment, investigation, recovery.

Also serving: HIPAA, DFARS, PCI-DSS, Texas SB 2610, SOC assessments, dark web monitoring, cyber policy design.
30+ Years combined team
cybersecurity experience
2015 Year CoreRecon
was founded
SDVOSB Service-Disabled Veteran-
Owned Small Business
9+ Compliance frameworks
we implement
CMMC NIST 800-171 DFARS HIPAA PCI DSS SOC 2
"We're the security guys who know security."

Three veterans, retired from the armed services, where we all worked in cybersecurity. That's who we are. Not a managed service provider that pivoted. Not a break-fix shop that rebranded. We built CoreRecon because we saw companies get destroyed by threats their IT team never saw coming. We decided to be the ones who see them.

30-minute response SLA.
Not next-business-day. 30 minutes.

We publish our pricing because we publish our results. Get a free security posture assessment — valued at $2,500 — and see exactly where your network stands before a real threat does.

Industries We Serve

Texas-specific threats.
Industry-specific coverage.

CoreRecon is purpose-built for the compliance and threat landscape of Texas organizations across 20 verticals.

NEW
Insurance Carriers & Brokers
NAIC Model Law · TIC Ch. 601 · TDI 72-hr · GLBA · HIPAA · SOC 2
Energy & Electric Utilities
NERC CIP · ERCOT Grid · Volt Typhoon · FERC Order 887 · SDVOSB
NEW
Private Equity
M&A Diligence · Portco SOC · Fund Dashboard · Exit Prep
NEW
SaaS & Tech
SOC 2 Type II · ISO 27001 · FedRAMP · TX-RAMP · Supply Chain
Fintech
PCI DSS v4.0.1 · NYDFS · SEC Disclosure · GLBA · SOC 2
Auto Dealers
FTC Safeguards · CDK/Reynolds · DMS · F&I PII · Floor Plan BEC
Transportation & Logistics
TSA SD · Volt Typhoon · Ports · Freight · 3PL · ELD
Title & Escrow
BEC Wire Fraud · ALTA Pillar 3 · GLBA · TX Ins. Code
Higher Education
FERPA · GLBA Safeguards · HIPAA · CMMC L2
Architecture, Engineering & Construction
CMMC L2 Flowdown · ITAR · BIM/CAD Ransomware · GC Supply Chain
School Districts
FERPA · CJIS (SRO) · ESSER III · TEA §11.175
Municipalities
CJIS v6.0 · FEMA BRIC · TX Data Privacy
Healthcare
HIPAA · TX HB 300 · OCR enforcement
Dental Practices & DSOs
HIPAA · TDPSA · DSO Multi-Location · PMS Credential Hardening
Defense Contractors
CMMC L2 · SPRS · DFARS · ITAR
Law Firms
Ethics Op 712 · Privilege · Attorney-client data
Credit Unions
NCUA Part 748 · GLBA · FFIEC CAT
Oil & Gas
TSA Pipeline SD · OT/ICS · SCADA security
Manufacturing
CMMC L2 flow-down · ITAR · OT/IT convergence
Water Utilities
AWIA §2013 · OT/SCADA · TCEQ · EPA
Accounting Firms
IRS WISP · FTC Safeguards · SOC 2
(V43) TX CPA Firms
IRS Pub 4557 · FTC Safeguards · PCAOB · SDVOSB
(V45) TX Veterinary Hospitals
HIPAA · DEA §1304–1305 · TVMDL · AVMA · AVImark/Cornerstone · SDVOSB
(V47) TX Construction & Engineering Firms
CMMC 2.0 · DIR/TxDOT · FTC Safeguards · TDPSA · BIM/CAD · SDVOSB
(V48) TX Automotive Dealerships
FTC Safeguards Dealer Rule · CDK/Reynolds DMS · TDPSA · PCI-DSS · GLBA · SDVOSB
NEW
(V49) TX Trucking & Logistics
FMCSA · CTPAT · DFARS/CMMC · TDPSA · ELD/TMS · SDVOSB
NEW
(V50) TX Behavioral Health & Mental Health Clinics
42 CFR Part 2 · HIPAA · TX HSC Ch. 611 · TDPSA · SDVOSB
NEW
(V52) TX Defense Contractors
CMMC L2 · DFARS · ITAR · SPRS · Volt Typhoon DIB · SDVOSB
NEW
(V53) TX Utilities
NERC CIP · AWIA · TX PUC §25.367 · CIRCIA · TDPSA · SDVOSB
NEW
(V55) TX Senior Living & Assisted Living
HIPAA · TX HSC §247 · CMS Conditions of Participation · TDPSA · SDVOSB
NEW
(V57) TX Oil & Gas Operators
TSA SD-02F · SEC Item 1.05 · CIRCIA · RRC 16 TAC §3.71 · TDPSA · SDVOSB
NEW
(V58) TX Law Firms (Next-Iteration)
State Bar of TX (Jan 2025) · ABA 1.6(c) · IOLTA wire fraud · TDPSA · SDVOSB
Virtual CISO
Board briefings · WISP · M&A diligence · $4K/mo
Published Threat Brief Verticals

Threat intelligence by vertical.

Explore CoreRecon’s published threat briefs for the industries facing Texas’ most specific cyber risks.

Utilities
TX Utilities Cybersecurity 2026
Texas multi-utility operators (gas + electric + water combined MUDs, special utility districts, gas LDCs, multi-utility OES firms) face NERC CIP-002 through CIP-014 (CIP-008 IR plan tri-clock + CIP-014 physical security + CIP-013 supply-chain), AWIA §2013 Risk & Resilience Assessment + Emergency Response Plan on 5-yr cycle, TSA SD-Pipeline-2021-01D (top 100+ gas LDCs + LNG), 49 CFR Part 192/195 (gas distribution + transmission), EPA RRAN-aligned RRA/ERP, AWWA G430/J100/DWFR, RRC 16 TAC §3.70 pipeline damage prevention, TX PUC Substantive Rule §25.367 (96-hr electric cyber-incident clock to PUCT — concurrent with CIRCIA 72-hr for NERC-registered entities), TDPSA §541 (utility customer billing + usage data enumeration), Volt Typhoon IT/OT pre-positioning in U.S. energy + water since 2021 (CISA/NSA AA24-038A), Muleshoe TX water-tank overflow (Jan 2024, CyberArmyofRussia/Unitronics PLC), Halliburton TX $35M RansomHub (Aug 2024), Brazos Electric $2.1B Ch.11 (2021 aftermath), City of Dumas TX SCADA ransomware (Nov 2024). Shared-MSP / vendor-IT / AMI headend / SCADA recloser / GIS / customer-portal BEC attack surface. CoreRecon tri-clock parallel-narrative SOC deliverable at $89–$129/endpoint + $2,500+/mo Command tier with AWIA RRA/ERP authorship + CIP-014 audit support + CIP-013 supply-chain plan + TDPSA enumeration coverage. SDVOSB-certified, 30-min CIP-008 SLA, TX-resident analysts, federal-grant procurement eligible (DWSRF/BRIC/RUS/DOE OE-000).
96-hr + 72-hr
TX PUC §25.367 + CIRCIA concurrent clocks — TX electric utility tri-narrative reports in parallel after every CIP-008 IR event
Dental Practices
TX Dental-TX Cybersecurity 2026
V54 Dental-TX anchor brief: MCNA Dental 8.9M records (TX Medicaid/CHIP dental administrator, 2023). Henry Schein BlackCat/ALPHV supply-chain (2023) — 1M+ records across Dentrix customer network, including TX practices. Change Healthcare 192M (Feb 2024). West Texas Oral Facial Surgery INC Ransom (Jun 2025). Pecan Tree Dental Grand Prairie TX — Sinobi variant confirmed Jan 2026. Professional Dental Alliance 170K+ via vendor phishing. Texas dental practices & DSOs face HIPAA Security Rule + TDPSA §541 + TX HB 300 (HSC Ch. 181) + TSBDE 22 TAC §108.7 record-retention four-layer compliance. DMS-attack surface: Dentrix / Eaglesoft / Open Dental / Curve Dental PMS credential paths, DSO multi-location shared-AD exposure, Weave / Demandforce patient-comms SaaS hijacking, DEXIS Imaging / Patterson file-server ACL gaps. Sentinel $89/ep, Fortress $129/ep, Command $2,500+/mo — SDVOSB-certified, TX-resident SOC, 30-min IR SLA. Includes V54 launch framing and the V54 Dental-TX gated-PDF CTA at /resources/threat-briefs/dental-practices.
8.9M records
MCNA Dental 2023 — TX Medicaid/CHIP dental administrator
Senior Living
TX Senior-Living-TX Cybersecurity 2026
V55 Senior-Living-TX anchor brief: Avamere Group 380,000+ records (ALPHV/BlackCat, 2023–2024, multi-state senior-living & SNF operator). Prospect Medical Holdings 1.3M records (Rhysida, 2023 — Texas-affiliated senior-care operations). Deer Oaks TX verified $225K ransom (2024, family-portal BEC pattern). Texas HHSC Medicaid breach (TX state-agency exposure path, 2024). Acuity Health 2.5M senior-care EHR supply-chain exposure (2024). Lifepoint Health TX senior-care multi-state breach (2024). Texas assisted-living facilities (ALFs), memory-care operators, and skilled-nursing facility (SNF) groups face five-layer compliance: HIPAA Security Rule + TX HSC §242 + TX HSC §247 (HHSC) + CMS Conditions of Participation (42 CFR §483) + TDPSA §541. Attack surface: MatrixCare / PointClickCare / American HealthTech credential paths, multi-facility shared-EHR-tenant segmentation gaps, family-portal BEC, MDS 3.0 eHR submission chain (CMS QIES ASAP), RUG score manipulation Medicare PDPM integrity, memory-care medication-management IoT devices. Sentinel $89/ep, Fortress $129/ep, Command $2,500+/mo — SDVOSB-certified, TX-resident SOC, 30-min IR SLA. Includes V55 launch framing and the V36 Senior-Living gated-PDF CTA at /resources/threat-briefs/senior-living.
380K records
Avamere Group — 380K records ALPHV/BlackCat (2023–2024, largest senior-living breach in U.S. history)
Municipalities
TX Municipalities — CJIS v6.0 & SCADA
V56 Municipalities-TX anchor brief: City of Dallas Royal ransomware ($8.5M cost-recover, 2023 — CJI exposure triggering FBI notification). City of Mission / Borger / San Angelo Q4 2025 coordinated wave. Borger TX REvil-affiliate (2025, public works + utility systems). 22 municipalities hit by coordinated Q4 2025 ransomware campaign (collective $2.5M demand). Akbar 911-PSAP ransomware precedent (county 911 ComEx / CAD encryption). Muleshoe TX Unitronics PLC utility SCADA overflow (Jan 2024) re-applicable — most TX cities also run their own water/wastewater SCADA. Full four-track compliance pinch: FBI CJIS Security Policy v6.0 (auditing live Oct 2025; LEA audit enforcement Oct 1, 2027 deadline; 13 policy areas) + Tex. Gov't Code Ch. 552 (Texas Public Information Act breach liability + §552.136 PII exception) + Texas Business & Commerce Code §521.053 (TDPSA breach notification, 60-day clock) + federal CIRCIA 72-hr CISA reporting (where utility SCADA in scope). Attack surface: CJI admin plane (RMS/CAD/NCIC/III terminals), 911 CAD egress, city water/wastewater SCADA (DNP3/Modbus/Unitronics PLC), public-records-portal credential stuffing, citizen-payment BEC (utility billing / municipal court fines), SaaS scheduling platforms (the Mission TX 2025 vector). CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident analysts, CJIS-mapped SOC + offline CJI continuity playbook + TxDIR cooperative contracting posture. CTA at /v/municipalities-tx landing page.
22 municipalities
hit by coordinated Q4 2025 ransomware wave — CJIS v6.0 auditing live Oct 2025
Defense Contractors
TX Defense Contractors — ITAR & CMMC
Volt Typhoon (PRC state-sponsored) has pre-positioned inside the U.S. Defense Industrial Base since 2021 — Texas hosts the #2 US DIB and ~3,000 active TX defense suppliers per DoD OUSD(A&S) data. CMMC 2.0 32 CFR Part 170 Phase 2 enforcement begins November 2026. TX DIB ITAR §120–130 shop-floor angle: ITAR-tagged geometry on Solidworks / AutoCAD / Siemens NX / CATIA / Pro-E file servers represents the most frequent Volt Typhoon collection target — cyber exfiltration treated as a 22 CFR §127 unauthorized-export predicate. DFARS 252.204-7012 72-hr DIBNet clock from discovery (not detection) runs in parallel with a DDTC voluntary disclosure. DFARS 252.204-7021 makes CMMC certification a condition of award. DFARS 252.204-7019/7020 SPRS scoring ≤110 with 3-year refresh; DFARS 252.204-7020 sub-tier flow-down attaches prime CMMC + 22 CFR §127 exposure to Tier 2/3 ITAR incidents. NIST SP 800-171 Rev 2 — 110 controls across 14 families. False Claims Act qui tam exposure under 31 USC §§3729–3733 on unencrypted CUI per recent DoD cyber-fraud enforcement actions ($1.2M–$70M+ settlement range, 15–30% relator share). SDVOSB co-prime advantage counts toward DFARS 252.219-7003 SDVOSB utilization goals. CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident SOC, ITAR §120–130 DLP tagging on CAD/CAM file servers + DFARS 7012 72-hr disclosure workflow + DDTC voluntary disclosure workflow + sub-tier DFARS 7020 flow-down audit. CTA at /v/defense-contractors-tx landing page.
CMMC L2 Nov 2026
CMMC 2.0 32 CFR Part 170 Phase 2 enforcement begins — DoD will not award contracts if SPRS shows a gap
Oil & Gas
TX Oil & Gas OT/ICS Cybersecurity 2026
V51 Oil-Gas-TX anchor brief: 935% YoY ransomware surge against oil & gas (Zscaler 2025). Halliburton TX $35M direct loss (RansomHub, Aug 2024 — SEC 8-K confirmed). Colonial Pipeline (Houston-origin) DarkSide attack — entire East Coast fuel shut down for the first time ever (May 2021). Newpark Resources Woodlands TX ransomware (Oct 2024). ENGlobal Corp Houston TX 6-week business outage (Nov 2024 – Jan 2025 SEC update). HSE/SCADA death-pile: Muleshoe TX Jan 2024 Unitronics PLC tank-overflow template applies 1:1 to pipeline SCADA valves; Hanna UT Pump Station TX PLC ransomware proof-point; Volt Typhoon IT/OT pre-positioning in U.S. energy targets (Dragos VOLTZITE tracking — 2024-2025). Downtime cost framing: Halliburton Aug 2024 invoice/PO processing offline = multi-million-dollar per-day crew & vendor idle cost. Regulatory stack: TSA SD-Pipeline-2021-01 series + TSA SD-02F (effective May 3, 2025) + SEC Item 1.05 4-business-day cyber-incident disclosure + CIRCIA 72-hr + TDPSA §541 + TCEQ air-permit + RRC 16 TAC §3.71. OT/IT convergence attack surface: Modbus / DNP3 / OPC-UA / EtherNet-IP engineering workstation exposure, cellular RTU/SCADA gateways (VOLTZITE vector), VPN-credential reuse (Colonial trigger), PI historian exfil, Emerson DeltaV / Honeywell Experion / Rockwell ControlLogix vendor remote-access. CoreRecon SCADA-aware SOC at $89–$129/endpoint + $2,500+/mo Command tier with pre-authorized SCADA isolation playbook + 30-min IR SLA beating TSA 12-hr CISA clock + SD-02F Cybersecurity Implementation Plan authorship + OT-aware threat hunts. CTA at /v/oil-gas-tx landing page.
$35M loss
Halliburton — RansomHub ransomware, Aug 2024 (SEC 8-K Item 1.05 confirmed direct charges)
Community Banks
TX Community Banks — FFIEC CAT Sunsetting
FFIEC CAT retired Aug 31, 2025 — replacement is FFIEC CAT → NIST CSF 2.0 mapping per FIL-21-2025. Heartland Tri-State Bank $47.1M CEO-fraud collapse (Jul 2023 — social engineering + wire-authority escalation = total bank failure). Evolve Bank $185M LockBit demand / 7.6M records exfiltrated (2024 – public 2025; correspondent-banking / Pathward-Kemba impact). Texas Capital Bank class action filed Jul 2026 — 86,067 Texans affected by May 2026 breach. GLBA 16 CFR 314.4 nine-element Safeguards Rule (effective Jun 9, 2023; Qualified Individual required) + FDIC 12 CFR Part 304 36-hour computer-security-incident notification (effective May 1, 2022) + Texas Department of Banking SB 1961 cyber-incident reporting (effective Sep 1, 2025) + TDPSA §541 (60-day breach notice + 30-day cure + $50K flex-cap) + NIST CSF 2.0 (FFIEC replacement per FIL-21-2025) + FFIEC IT Examination Handbook InTRAC / CyFER. Pathward-Kemba / Kemba-Pathward fourth-party custodian / capital-stack / correspondent-channel vendor risk (voluntary receivership + waiver-of-successor-liability precedent). CDC CAL IC3 24k co $7 total community-bank-SEC top. CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident SOC, bank-aware 9-element GLBA artifact library + 36-hr FDIC notification workspace + correspondent-banking / core-processor / Pathward-Kemba fourth-party mapping + 14-day FFIEC-to-NIST CSF 2.0 posture delivery. V59 launch at /v/community-banks-tx → /verticals/tx-community-banks-tx.
$47.1M
Heartland Tri-State Bank CEO-fraud collapse — social engineering + wire-authority escalation = total bank failure
Law Firms
TX Law Firms — ABA 1.6(c) & IOLTA Wire Fraud
State Bar of TX hit by INC Ransom (Jan 2025) — 1.4M records. Orrick $8M OCR class-action settlement (2023). Mossing & Navarre Toledo ransomware. Bryan Cave Leighton Paisner CCG breach. ABA Model Rule 1.6(c) duty to make reasonable efforts + TX DR 1.05 + ABA Formal Opinion 483 (cyber incident response) + TDPSA §541 + IOLTA wire fraud kill chain (TX IOLTA §171.101–§171.203). Case management attack surface: Clio / MyCase / PracticePanther / iManage / NetDocuments credential paths. Ransomware targeting active case files, settlement escrow timing, and client trust accounts. 8 law-firm-specific controls. CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident SOC. CTA at /verticals/tx-law-firms-tx.
$8M settlement
Orrick Herrington — OCR class action settlement (2023), new professional-liability data-security standard
Free Interactive Tools
New — Post-Incident
Breach Notification Timeline Generator — TX + Federal + All 50 States

How Many Hours Until Your First Notification Deadline?

Enter incident parameters and get a per-jurisdiction notification clock: DFARS 72-hour DoD report, SEC 8-K Item 1.05 (4 business days), HIPAA 60-day, TX SB 820, NYDFS, CCPA, and all 50 states — with countdowns, regulator contacts, and notification content checklists. Highest-conversion post-incident buyer state.

Generate My Timeline →
New
Cyber Insurance Premium Estimator — Marsh · Howden · Coalition 2025

How Much Are Your Control Gaps Inflating Your Premium?

Real-time premium estimate anchored to Marsh/Howden/Coalition 2025 benchmarks. 10-control checklist shows exactly which gaps inflate your rate (+18–32% each) or trigger denial. CoreRecon MSSP savings projection + carrier-question prep sheet — email-gated PDF. Highest-intent renewal moment in our market.

Estimate My Premium →
New
Vendor Risk Scorecard — CMMC · HIPAA · GLBA · CJIS · PCI DSS

How Exposed Is Your Third-Party Stack?

Score your vendor ecosystem against 5 compliance frameworks in 90 seconds. Get a 0–100 risk score, framework gap matrix (CMMC SCRM · HIPAA BA · GLBA · CJIS Appendix G · PCI DSS Req 12.8), top-5 remediation list, and email-gated PDF — the missing piece for every CMMC L2 and healthcare lead.

Score My Vendor Risk →
New
Phishing Resistance Score — Verizon DBIR · IBM CODB 2024 · CISA

How Exposed Is Your Organization to Phishing?

12 weighted controls. Live-updating 0–100 score with band labels. Top 3 weaknesses with fix rationale. IBM CODB breach cost exposure by industry. Email-gated 8-page remediation PDF. Universally urgent — every vertical is in scope.

Score My Phishing Risk →
New
SPRS Score Calculator — NIST 800-171 · DFARS 252.204-7012

Know Your SPRS Score Before DoD Does

Score all 110 NIST 800-171 controls. Get your official SPRS number (−203 to 110), control family heatmap, and prioritized remediation roadmap — free email-gated PDF. Required for every DFARS 252.204-7012 contract. Nov 2026 CMMC enforcement deadline.

Calculate My SPRS Score →
Start Here
Breach Cost Calculator — IBM 2024 · Verizon DBIR · FBI IC3

How Much Would a Breach Cost Your Organization?

Industry, endpoints, record count. Get your IBM 2024 breach cost range, TX penalty exposure (TDPSA/HIPAA/CMMC), 207-day dwell-time gap cost, and CoreRecon Fortress ROI — instantly. The number that makes $89/endpoint an easy yes.

Calculate My Risk →
Cyber Insurance Readiness Checker — New

Will Your Cyber Insurance Renew This Year?

38 carrier-aligned questions. See exactly where you'd fail Coalition, At-Bay, Travelers, Chubb, or Beazley before your broker does.

Check My Readiness →
HIPAA Readiness Quiz

Is Your Organization HIPAA Audit Ready?

18 questions across all HIPAA Security Rule standards. Find your OCR gaps before enforcement. TX HB 300 coverage included.

Take the Quiz →
CMMC Readiness Quiz

Are You CMMC Level 2 Ready?

14 questions across all CMMC L2 domains. Know your SPRS gaps before DoD enforcement begins November 2026.

Take the Quiz →
CJIS Readiness Quiz

Is Your Agency CJIS v6.0 Audit Ready?

13 questions across all CJIS policy areas. Find your gaps before FBI auditors arrive. Oct 2027 deadline.

Take the Quiz →
SOC Buildout Calculator

In-House SOC vs CoreRecon: Real Cost?

Staffing, tools, overhead — see the full in-house number vs CoreRecon Sentinel. Live model, shareable URL.

Run the Numbers →
New
Ransomware Tabletop Generator

Run a Board-Ready Tabletop Exercise

Custom 8-inject runbook in 2 minutes. Industry-specific scenario, comms templates, roles & responsibilities. Required by cyber insurers.

Generate My Runbook →
New
Compliance Regulation Finder

Which Regulations Apply to You?

7 questions. Ranked map of every federal and Texas regulation you're subject to — with deadlines, penalties, and the CoreRecon tier that covers each one.

Find My Regulations →
New
IR Plan Generator — NIST 800-61r3

Build Your Custom Incident Response Plan

8 inputs. A full 7-phase NIST IR plan with regulation-specific notification timelines, containment playbooks, and pre-populated contact trees — free, email-gated PDF.

Generate My IR Plan →
New
PCI DSS v4.0.1 Readiness Quiz

Are You PCI DSS v4.0.1 Ready?

16 questions across all 12 PCI Requirements. Know your QSA gaps before your next assessment. Final v4.0.1 enforcement landed March 31, 2025 — every CDE is in scope.

Take the Quiz →
New
CMMC POA&M Generator — DFARS 252.204-7020

Turn NIST 800-171 Gaps Into a DoD POA&M

Select gaps from all 110 controls. Auto-populate weakness descriptions, remediation steps, and target dates. Export PIEE-ready PDF + CSV — what your prime needs before CMMC certification.

Generate My POA&M →
New
CJIS Audit Readiness Checklist — v6.0

Turn CJIS Gaps Into an Auditor-Ready Checklist

Select gaps across all 13 CJIS v6.0 policy areas. Get plain-language requirements, remediation steps, evidence checklists, and target dates — what your IT director hands to the CSA before October 2027.

Build My Checklist →
New
vCISO ROI Calculator

Fractional vCISO vs. Full-Time CISO: Real 3-Year Cost

IBM CODB breach model + compliance penalty exposure + 3-year TCO chart. Know the math before your board asks the question.

Calculate vCISO ROI →
New
NIST CSF 2.0 Readiness Quiz

Where Do You Fall on the CSF 2.0 Maturity Scale?

23 questions. All 6 CSF 2.0 functions — Govern, Identify, Protect, Detect, Respond, Recover. Tier 1–4 maturity score + downloadable gap report. Right for manufacturers, professional services, and anyone not under a single compliance regime.

Take the CSF 2.0 Quiz →
New
Texas TDPSA Readiness Quiz — Tex. Bus. & Com. Code Ch. 541 · SaaS · Fintech · Healthcare · Retail

Are You Texas TDPSA Ready?

21 questions across all major TDPSA obligations — consumer rights (access, correction, deletion, portability, opt-out), universal opt-out / GPC recognition, privacy notice, sensitive data consent, Data Protection Assessments, processor contracts, data minimization, reasonable security, appeal process, and AG enforcement readiness. Industry selector for SaaS/tech, fintech, healthcare, marketing, retail, accounting, and higher ed. Email-gated 30/60/90 remediation roadmap. AG civil penalties up to $7,500/violation.

Take the TDPSA Quiz → FTC Safeguards Quiz →
⏱ Live Countdowns
Compliance Deadline Tracker — CMMC · CJIS · HB 300 · TSA · NCUA · FFIEC · ABA
View Deadlines →