Resources
Practical guides, checklists, and analysis.
Free resources written for medium and large businesses, defense contractors, and regulated industries — by the people who run the SOC, not the marketing team.
-
Lead magnet · CMMC
CMMC 2.0 Readiness Checklist
A 47-point checklist mapping NIST 800-171 controls to common gaps for defense subcontractors, with realistic remediation timelines for Pacific subcontractors.
Read it -
Lead magnet · SOC
Managed SOC Pricing Guide for Medium and Large Businesses
A practical breakdown of what 24/7 SOC services cost in 2026 — pricing models, what drives variance, and red flags to watch when comparing providers.
Read it -
Article · Buyer's guide
How Much Does a Managed SOC Cost in 2026?
A buyer's guide for medium and large businesses, MSPs, and DoW contractors evaluating SOC providers. What the price ranges actually mean and how to compare apples to apples.
Read it -
Article · CMMC
CMMC 2.0 Timeline for Pacific Contractors
The phased CMMC 2.0 timeline through November 2026, and what Hawaii defense subcontractors should be doing right now.
Read it -
Article · Pacific MSSP
Why Honolulu Defense Contractors Need a Pacific-Based MSSP
Time zone, US-persons handling, and INDOPACOM-AOR awareness are not optional. The structural reasons Pacific contractors should look local.
Read it
Aloha, let's talk
Ready to talk to someone who actually answers the phone?
Whether you're scoping a CMMC assessment, evaluating a managed SOC, or just trying to get through your next audit — we can help. No sales theater. No offshore tier-1.
Industry cybersecurity assessments
Free industry-specific cybersecurity readiness assessments.
Five free self-assessments, each built around the specific compliance frameworks and examiner expectations your industry faces. About ten minutes each. Scoring runs locally in your browser — nothing leaves your device unless you explicitly request a written report. Each output maps to the maturity scale your regulators or auditors actually use, so the result is immediately usable in board reporting, vendor diligence response, or pre-audit gap planning.
-
Defense · CMMC 2.0
CMMC Readiness Assessment
Eighteen questions across the six NIST SP 800-171 control families that anchor CMMC 2.0 Level 2. Scoring maps to the SPRS construct DoD primes check during subcontractor diligence under DFARS 252.204-7012.
-
Financial Services · FFIEC / NCUA
Financial Services Cybersecurity Assessment
Built around the FFIEC Cybersecurity Assessment Tool, NCUA Information Security Examination, GLBA Safeguards Rule, and NYDFS Part 500 maturity expectations. For community banks, credit unions, and trust companies.
-
Healthcare · HIPAA / HITRUST
HIPAA Compliance Assessment
HIPAA Security Rule (45 CFR Part 164, Subpart C) administrative, physical, and technical safeguards plus HITRUST CSF v11 control mapping. For covered entities, business associates, and digital-health vendors.
-
Insurance · NAIC / NYDFS
Insurance Security Assessment
NAIC Insurance Data Security Model Law, NYDFS 23 NYCRR 500, and GLBA Safeguards Rule control coverage. For carriers, MGAs, brokers, third-party administrators, and insurtech vendors.
-
Manufacturing · NIST CSF / IEC 62443
Manufacturing Cybersecurity Assessment
NIST CSF 2.0 plus IEC 62443 zone-and-conduit OT/IT segmentation, ICS/SCADA controls, supply-chain risk, and CMMC overlay for defense manufacturers. The OT/IT convergence questions are where most manufacturing incidents now happen.
Community · Events
Practitioner events rooted in the Pacific cyber community.
Cyberuptive is rooted in the cybersecurity community. We help organize practitioner-led gatherings where defenders, researchers, students, and security leaders can learn from one another — not from a vendor pitch deck. If you’re building, defending, or studying in this space, we’d like to meet you at one of these.
-
Annual · Honolulu
BSides Hawaii
Our team helped found BSides Hawaii as part of the founding community — a practitioner-led space for defenders, researchers, students, and security leaders across the islands to share work and learn from each other. BSides events run worldwide; the Hawaii chapter exists to give the Pacific its own room at the table.
Visit bsideshawaii.org -
Coming soon · AI & cybersecurity
CSides Hawaii
CSides extends the community model into AI and cybersecurity. Hosted in Hawaii and named for the islands’ place surrounded by the sea, it’s a space for exploring the cyber sides of emerging AI risk, defense, governance, and hands-on practitioner learning. The site is live; the program and dates are being shaped now.
Visit csideshawaii.com
Get involved
Speaking, sponsorship, or partnership?
If you’d like to speak, sponsor, or partner with us on BSides Hawaii or CSides — or you’re planning a community event we should know about — reach out.