Security builder & leader

6 Tips for Hiring and Working With Security Consultants

Before engaging security consultants, understand your requirements to stay in control. Reach out to multiple firms for perspectives and price validation, assess who specifically will work on the project, request milestones in the project plan, understand total costs beyond hourly rates, and dedicate time to oversight.

Sometimes organizations need outside help for getting their arms around information security challenges. That’s where security consultants come in. Here are a few tips for making sure that engaging a consultant—often in the form of a consulting company—brings the necessary benefits to justify the expense.

This advice isn’t specific to security consulting, but I present it on the basis of providing security consulting services for a fair bit of time:

If you’d like to share additional tips, either from a security consultant’s or a client’s perspective, please leave a comment.

About the Author

Lenny Zeltser is a cybersecurity leader with deep technical roots and product management experience. He created REMnux, an open-source malware analysis toolkit, and the reverse-engineering course at SANS Institute. As CISO at Axonius, he leads the security and IT program, focusing on trust and growth. He writes this blog to think out loud and share resources with the community.

Learn more →