Adobe Stock 974892097

OSec

We Do Things Differently

We’re not bound by old thinking—and neither is your security.

Founded in 2010, we’re not your typical security firm.. We specialize in protecting the people, processes, data, and technology that drive your organization—without the gimmicks or one-size-fits-all solutions.

How We Work

  • We Listen First: Every organization has unique challenges. We start by understanding yours.
  • We Solve Real Problems: Our team has deep, operational experience. We don’t rely on guesswork or cookie-cutter fixes.
  • We Stay Independent: We never upsell or resell products you don’t need, so you can trust our recommendations.

Why It Matters

  • Fewer Surprises: By tailoring solutions to your exact environment, we reduce the risk of nasty surprises and keep costs under control.
  • Better Outcomes: You get security solutions that actually address your threats and fit your culture, not just something that looks good on paper.
  • Trusted by Global Clients: Organizations worldwide partner with us year after year because we deliver what we promise.

Our Commitment

  • Expertise That Works: We bring real-world know-how, not just theory.
  • Continual Learning: Threats evolve, so do we—constantly improving to keep you protected.
  • Your Success First: When we do our job well, you can keep doing yours.
Leadership arrows

Leadership Team

Our leaders combine deep operational experience with a passion for tackling complex security challenges. They’ve steered global initiatives, earned industry recognition, and consistently delivered measurable impact for our clients.

Together, they shape the vision, drive innovation, and uphold the high standards that define who we are—and how we protect what matters most to you.

Leadership Team

Mark Stamford

Founder & CEO

Mark started playing around with computers at age 8, eventually growing up and gaining over 25 years of experience in cybersecurity, operations, and more. Prior to founding OSec, he worked at UBS and KPMG.

+

Erin Murtha

Chief Operations Officer

Erin brings over 20 years of experience in ensuring optimal organizational performance, growth, and client success. Her prior experience includes work at Homeland Security managing projects of critical national importance.

+

Robbie Tyrie

Chief Technical Officer

Robbie leads our technology strategy, ensuring innovative solutions that align with our business goals. He drives our team to deliver cutting-edge, scalable technologies for success.

+

Christian Kimball

Technology Director

Christian has over 20 years of experience in IT, security, risk management, and implementing security risk programs. He has conducted offensive security engagements, and specializes in physical security and threat intelligence.

+

Cayce Mahon

CTI Director

Cayce leads the CTI Team. With over 10 years experience in offensive security operations, Cayce leads the threat intel and vulnerability research teams at OSec.

+

Spencer Lindgren

Operations Lead

Spencer has a background in healthcare technology, encryption, security, and compliance. He has held roles at telemedicine provider Vigilint, Patronus Medical, and assistant adjunct professor at UNC Chapel Hill.

+

Matt Landers

Assessment Director

Matt's career spans over 20 years focused on discovering and researching security vulnerabilities. He is passionate about finding unintended uses for common technology stacks.

+

Jimmy Fisher

CTEM Director

Jimmy Fisher is a cybersecurity practitioner and U.S. Army Veteran with multiple professional certifications, including OSCP, specializing in offensive security and penetration testing.

+

Advisory Board

Neil Bryden

Advisor

Neil has over 35 years of experience in IT risk and security, including CISO roles at KPMG and other global enterprises. He has also advised CISOs across various industries, and has experience across governance, architecture, and strategy.

+

Robert Hayes

Advisor

Robert holds board, director, and advisory roles at public and private organizations, helping mitigate security risks during complex business transformations. He is an acknowledged expert in cybersecurity, and former Microsoft senior fellow.

+

Philip Niedermair

Advisor

Philip has over 35 years of experience in helping companies expand their potential through corporate development, strategic alignment, and relationship building. Philip is a Senior Advisor to the Cyberspace Solarium Commission.

+

John Quigg

Advisor

John is a senior staff member at the Johns Hopkins University Applied Physics Laboratory, supporting the DoD’s security initiatives in cloud, 5G, and cyber situational awareness. His background is the Airborne Rangers and DoD.

+

Chris Reid

Advisor

Chris is the Chief of Staff for Elastic's US Public Sector. He retired last year after 36 years in the US Army where he served as a Brigadier General in Cyber and Special Operations assignments in the US and overseas.

+

Industries we work with

We’ve partnered with organizations across a wide range of sectors—each with its own unique challenges and regulatory demands.

Read on to see where we’ve made an impact—and how we can do the same for you.

Media

Media

Media organizations depend on complex broadcast systems and high-value content, making them prime targets for ransomware, data breaches, and operational disruptions that can halt live broadcasts, expose unreleased material, and erode brand trust. Proactive security measures—far cheaper than crisis management—safeguard revenue streams, protect reputations, and keep broadcasts on the air.

Education

Education

Education institutions hold vast amounts of sensitive student and financial records, making them prime targets for cyber threats that can erode trust, strain already tight budgets, and disrupt essential services. Schools and universities worldwide strengthen their defenses to protect critical data while remaining within budget constraints.

Industrial

Industrial

Industrial organizations span critical infrastructure sectors, where cyberattacks can halt production, jeopardize safety, and disrupt entire supply chains. In this environment, threats aren’t just digital—kinetic impacts can cause physical harm and facility damage. Organizations across the sector fortify operational technology, secure supply chains, and ensure business continuity to mitigate these risks.

Technology

Technology

Tech innovators power our digital world with products ranging from web services to mobile apps and complex infrastructure. We secure every stage—from development to deployment—so solutions meet industry standards and remain resilient against evolving threats. Through rigorous testing, proactive threat intelligence, and continuous monitoring, organizations protect customer data, safeguard intellectual property, and maintain trust.

Pubsecicon

Energy

Public sector organizations provide essential services—from public safety and healthcare to infrastructure and citizen services. They often face complex challenges like outdated systems, constrained budgets, and strict regulations that complicate security efforts. By adopting robust defensive measures, these agencies protect citizen data, ensure operational continuity, and maintain trust in government services.

Healthcare pharma

Healthcare / Pharma

Healthcare organizations manage critical patient data and deliver life-saving services, making them prime targets for sophisticated cyber threats. Breaches can undermine patient trust, disrupt care, and result in steep regulatory penalties. By rigorously protecting sensitive data and medical systems, healthcare providers maintain compliance, ensure patient safety, and safeguard operational continuity.

 

 

We protect what matters.
Lets talk about what matters to you!