Cyberuptive

Resources

Practical guides, checklists, and analysis.

Free resources written for medium and large businesses, defense contractors, and regulated industries — by the people who run the SOC, not the marketing team.

Aloha, let's talk

Ready to talk to someone who actually answers the phone?

Whether you're scoping a CMMC assessment, evaluating a managed SOC, or just trying to get through your next audit — we can help. No sales theater. No offshore tier-1.

Industry cybersecurity assessments

Free industry-specific cybersecurity readiness assessments.

Five free self-assessments, each built around the specific compliance frameworks and examiner expectations your industry faces. About ten minutes each. Scoring runs locally in your browser — nothing leaves your device unless you explicitly request a written report. Each output maps to the maturity scale your regulators or auditors actually use, so the result is immediately usable in board reporting, vendor diligence response, or pre-audit gap planning.

  • Defense · CMMC 2.0

    CMMC Readiness Assessment

    Eighteen questions across the six NIST SP 800-171 control families that anchor CMMC 2.0 Level 2. Scoring maps to the SPRS construct DoD primes check during subcontractor diligence under DFARS 252.204-7012.

  • Financial Services · FFIEC / NCUA

    Financial Services Cybersecurity Assessment

    Built around the FFIEC Cybersecurity Assessment Tool, NCUA Information Security Examination, GLBA Safeguards Rule, and NYDFS Part 500 maturity expectations. For community banks, credit unions, and trust companies.

  • Healthcare · HIPAA / HITRUST

    HIPAA Compliance Assessment

    HIPAA Security Rule (45 CFR Part 164, Subpart C) administrative, physical, and technical safeguards plus HITRUST CSF v11 control mapping. For covered entities, business associates, and digital-health vendors.

  • Insurance · NAIC / NYDFS

    Insurance Security Assessment

    NAIC Insurance Data Security Model Law, NYDFS 23 NYCRR 500, and GLBA Safeguards Rule control coverage. For carriers, MGAs, brokers, third-party administrators, and insurtech vendors.

  • Manufacturing · NIST CSF / IEC 62443

    Manufacturing Cybersecurity Assessment

    NIST CSF 2.0 plus IEC 62443 zone-and-conduit OT/IT segmentation, ICS/SCADA controls, supply-chain risk, and CMMC overlay for defense manufacturers. The OT/IT convergence questions are where most manufacturing incidents now happen.

Community · Events

Practitioner events rooted in the Pacific cyber community.

Cyberuptive is rooted in the cybersecurity community. We help organize practitioner-led gatherings where defenders, researchers, students, and security leaders can learn from one another — not from a vendor pitch deck. If you’re building, defending, or studying in this space, we’d like to meet you at one of these.

  • Annual · Honolulu

    BSides Hawaii

    Our team helped found BSides Hawaii as part of the founding community — a practitioner-led space for defenders, researchers, students, and security leaders across the islands to share work and learn from each other. BSides events run worldwide; the Hawaii chapter exists to give the Pacific its own room at the table.

    Visit bsideshawaii.org
  • Coming soon · AI & cybersecurity

    CSides Hawaii

    CSides extends the community model into AI and cybersecurity. Hosted in Hawaii and named for the islands’ place surrounded by the sea, it’s a space for exploring the cyber sides of emerging AI risk, defense, governance, and hands-on practitioner learning. The site is live; the program and dates are being shaped now.

    Visit csideshawaii.com

Get involved

Speaking, sponsorship, or partnership?

If you’d like to speak, sponsor, or partner with us on BSides Hawaii or CSides — or you’re planning a community event we should know about — reach out.