Nightingale Digital Advisors logo Independent security assessments · Front Range, Colorado

Boutique security assessments for small firms across the Front Range.

See what your wireless, your network, your building, and your people actually expose. Assessed start to finish by me, and reported in plain language you can act on.

I don't sell a security product. I tell you what's actually exposed.

Most small firms get sold either nothing or a sprawling engagement they don't need. I do the unglamorous middle: look hard at what a practice your size actually has reachable, separate what matters from what doesn't, and right-size the work to your real risk.

A lot of what gets sold as a security assessment is scoped backward from the paperwork it needs to produce. The work begins from a position already inside your network. The harder question, whether someone could get in at all, is quietly assumed and answered yes. I'd rather test that assumption than write around it.

No fear-based pitch, no product menu, no theater. You'll get a clear picture and a short list of what to fix first, in plain terms you can hand to a partner, a board, or an underwriter.

A wireless assessment, scoped for a small firm.

Find out what someone standing outside your building can actually reach.

The wireless your staff and clients connect to every day is the easiest thing to overlook and one of the easiest ways in, sometimes from no closer than the parking lot. For most small practices, this is the assessment I'd recommend before anything bigger.

I look at every wireless network you're running, how they're separated, and what someone nearby could actually reach. Captured traffic gets triaged with AI-assisted tooling so I chase what matters first. I'm still the one deciding what's worth chasing. You get a plain-language report of what's exposed and what to close first, not a 60-page scan dump.

Radio doesn't travel over a VPN. How far past your walls the signal actually carries, whether the guest network is really separated from the one your files live on, whether there's an access point in a ceiling tile nobody remembers installing. Those get answered from inside the building, by someone standing in it.

It's also what your cyber insurer asks about. The application asks you to attest to specific controls, and a documented assessment is something you can put in front of your broker at renewal.

Just as important: an insurer has gone to court to rescind a policy because a control attested to on the application wasn't actually in place. An assessment tells you what you actually have, not what you hoped you had.

The fuller picture

Three layers of exposure.

The wireless assessment is the front door. Behind it are three layers, each with a small set of scoped, repeatable assessments. I'll tell you straight which ones you need and which you can skip.

What someone can see and touch from the open internet, and what they could reach once they're on your network. You get a plain-language map of your exposed surface and a short, ranked list of what to close first.

Network exposure assessment

The separation between your networks gets tested rather than assumed.

What it is
A look at what your firm exposes to the internet and what a device on your network can actually reach.
What you get
A plain-language map of the exposed surface and a short, ranked list of what to close first.
Pricing
Scoped per engagement. Usually bundled with the wireless assessment.
>I usually scope this together with the wireless assessment. Ask when you reach out.

A walk through your space for the things software can't see. Whether your badges are the kind that can be copied, and whether your readers would notice. Who can get where, and who holds the door for a stranger whose hands are full. Whether someone can reach a live network port from your lobby or an empty conference room — the point where this assessment and the wireless one meet. The server closet that's locked, with the key sitting on top of the frame. The whiteboard nobody wiped, the sticky note under the keyboard, the privileged file left face-up on a desk. This is a walkthrough, not a forensic bug-sweep. But it's the layer no remote assessment can reach, and the one most firms have never had anyone look at.

Physical access assessment

I walk your building the way someone looking for a way in would walk it. When something opens, I open it while you watch. Saying a door needs a bar on it is one thing. Slipping an under-door tool through and opening it in front of you is another.

What it is
Two demonstrations, done in the open while you watch. Your badges first: I read a credential you issue me for the day, clone it, and present the copy to your own reader. Most proximity cards a small office hands out can be copied in seconds — this shows whether yours are among them. Then the door itself: the lever handle that can be slipped, the latch that never quite catches, the motion sensor that unlocks for anyone leaving and can be tripped from the wrong side.
What you get
A written account of what opened and what didn't: which credentials could be copied, which readers and doors let me through, and the specific change that closes each one.
What I need from you
A guest badge and a mock employee badge, issued by you on the day.
Not offered
Covert entry. Every visit is announced, scheduled, and escorted — I don't need to break in to show you how someone would.
Pricing
Scoped per engagement.
>Non-destructive — nothing forced, cut, or broken.

The people side is the layer that decides whether everything else holds. Two ways I work on it: an assessment that finds out whether one specific attack would succeed, and a program that makes the training you already own worth running.

Objective-based social engineering assessment Single engagement

One agreed objective, a handful of pretexts built by hand from open-source research, and a straight answer about whether it worked. Not a mass-mailer simulation.

What it tests
Whether your MFA actually holds against the way credentials are stolen now: a login page that proxies the real one and steals the session, or a consent prompt that hands over a mailbox without a password ever changing hands. Not whether someone clicks.
What you get
A written attack narrative stating whether the objective was reached and exactly how, followed by what to change.
Pricing
Scoped and priced per engagement.
How the assessment works ↓

Phishing program refresh Recurring

For firms that already own an awareness platform, often bundled through an MSP or a cyber policy, and never took it past the defaults. I run it on your existing license, alongside your IT provider. No gotcha theater; the point is a staff that's a little harder to fool every quarter.

What it is
Audience segmentation, a rotating set of pretexts written for your firm, a sensible campaign cadence, and a quarterly readout you can hand to a partner or an underwriter.
What it measures
Report rate and time-to-report, the numbers that show whether people speak up. Not click rate.
Who it's for
Firms with a platform already in place. It complements your MSP or IT provider; it doesn't replace them.
Pricing
Recurring. Scoped per engagement.
>Either one stands on its own. The assessment tells you where you are; the refresh keeps you moving.
The harder question

A social engineering assessment with one objective.

Most phishing tests measure clicks. Clicks stopped being the point a while ago. The attacks that matter now are built to get past multifactor authentication: a login page that proxies the real one and steals the session (adversary-in-the-middle), or a consent prompt that hands an attacker a mailbox without a password ever changing hands (OAuth or device-code consent abuse). This assessment finds out whether those work against you.

I agree one objective with you up front. Reading a partner's mailbox. Getting a payment instruction changed. Reaching a client file. Then I research your firm and the people in it from open sources, the way an attacker would, and build a small number of pretexts by hand. No mass mailer, no template library. A few messages specific enough to be plausible, sent under written rules of engagement.

What you get is a written attack narrative: what I tried, what worked, whether the objective was reached, and exactly how, followed by what to change so it doesn't work next time. If it didn't work, the report says so. That's a result, not a failure.

How the work gets done

AI-assisted. Human-run, every time.

Most of this work is still slow and manual: reading logs, cross-referencing OSINT, staring at a packet capture. The same class of AI tooling showing up in attacker playbooks is worth having on the defending side, too. Used to find and prioritize, never to act on its own. I build AI-assisted tooling into the parts of the process where it actually helps, and I'm the one deciding everything that matters.

The tooling narrows and organizes. It doesn't choose what to attack, and nothing reaches you unreviewed. Every decision in the field and every line in your report is made by me before it goes anywhere.

Vetted for this work by Anthropic and OpenAI
Vetted access

Vetted for security work by both labs whose models I use.

Plenty of firms will call themselves "AI-powered." Almost none of them have had anyone check what that actually means. Anthropic and OpenAI each run their own review for practitioners who use their models in real security work. Nightingale was approved by both.

Anthropic

Cyber Verification Program

Nightingale is accepted into Anthropic's Cyber Verification Program (CVP), an application-based review Anthropic runs for security firms that use Claude in their assessment work. Anthropic reviewed how I actually use their models for this kind of work and granted the verification directly.

A verification of how I use Claude. Not a partnership, certification, or endorsement.

OpenAI

Daybreak Blue

Nightingale is approved for OpenAI Daybreak Blue, a trusted-access tier for vetted defenders with legitimate cybersecurity requirements. It provides OpenAI's most cyber-capable model for this kind of work, subject to OpenAI's usage policies.

An access approval. Not a partnership, certification, or endorsement.

Both are approvals I applied for and had to qualify for. Neither changes how I work.

Ask what that means for your assessment
Who you're hiring

The technical work, done directly.

I'm Brandon Flanigin. I spent two years in domain and DNS management and two more in email marketing. That's infrastructure and delivery work, and it trains you to notice the small misconfiguration that breaks everything downstream. After that came several years brewing professionally, a craft built on patience, precise process, and catching the one variable that's quietly off before it ruins the batch. That discipline is most of what security work actually is.

I'm building this practice the way I'd want it built for my own family: close to home, hands-on, one real engagement at a time. That includes free security checkups for nonprofits and community organizations across the Front Range.

Every finding in your report reflects work I actually did on your network, not a summarized scan dump, and I stand behind it personally, because I did it myself, in the community I actually live in. That's true of the AI-assisted side of the work, too. see how it fits

  • Technical workScoped, run, and reported directly
  • VettedAnthropic CVP · OpenAI Daybreak Blue
  • BasedBoulder–Lafayette, CO
Speaking and workshops

Security awareness for the age of AI.

  • TalkChambers, local business groups, and professional associations
  • CLEBar associations, where the association can accredit it
  • On-siteA working session for your own team, with an optional consented voice-clone demonstration

For years, security awareness meant teaching people to notice what's off: the odd phrasing, the voice that isn't quite right, the video that doesn't match. That training is now obsolete. Voice, video, and writing style no longer prove who is on the other end, and practice won't keep pace with the tools that fake them.

What replaces perception is procedure. An out-of-band callback before anything moves. A money-movement threshold above which one person is never enough. A verification word the office actually uses. None of it depends on anyone being clever in the moment, which is the point. This talk shows a room what's changed, then leaves them with the three or four procedures that hold.

I give it to local business groups, chambers, and bar associations, and on-site to client teams. With a volunteer's consent, an on-site session can include a demonstration: their own voice, cloned in the room, making the kind of call your office would probably take. It's the fastest way I know to turn a policy into a habit. I spent two years in email marketing before any of this, so I know what a convincing message looks like from the inside.

Book a talk
Give-back

One free checkup, every month.

Each month I give one local nonprofit a free wireless and security checkup. Churches, theaters, the places that hold a community together.

See the give-back program →
Start here

Tell me what's going on.

What you're worried about, what prompted this, what kind of firm you are. I'll tell you honestly whether I'm the right fit. If I'm not, I'll point you toward someone who is.

brandon@nightingaledigitaladvisors.com

If something is happening right now, this isn't the right door. Call your cyber insurer's breach line first; that's what it's for. I do proactive assessment, not incident response.

Personal and family security, for individuals rather than firms, is inquiry only for now. I take a small number of those conversations. Say so in your note and I'll tell you straight where it stands.

Every message gets a personal read. You'll usually hear back within a business day.