Security builder & leader

6 Tips for Hiring and Working With Security Consultants

Before engaging security consultants, understand your requirements to stay in control. Reach out to multiple firms for perspectives and price validation, assess who specifically will work on the project, request milestones in the project plan, understand total costs beyond hourly rates, and dedicate time to oversight.

Sometimes organizations need outside help for getting their arms around information security challenges. That’s where security consultants come in. Here are a few tips for making sure that engaging a consultant—often in the form of a consulting company—brings the necessary benefits to justify the expense.

This advice isn’t specific to security consulting, but I present it on the basis of providing security consulting services for a fair bit of time:

If you’d like to share additional tips, either from a security consultant’s or a client’s perspective, please leave a comment.

About the Author

Lenny Zeltser is a cybersecurity executive with deep technical roots, product management experience, and a business mindset. As CISO at Axonius, he leads the security and IT program, focusing on trust and growth. He is also a Faculty Fellow at SANS Institute and the creator of REMnux, a popular Linux toolkit for malware analysis. Lenny shares his perspectives on security leadership and technology at zeltser.com.

Learn more →