Essex Junction, VT802-335-2662dkoran@davidkoran.com
DK
David Koran& Associates
Independent Cybersecurity & Compliance Advisory

Cybersecurity Advisory for Regulated Industries

CMMC  |  Maritime  |  C2M2  |  AI Governance  |  Cyber Insurance

David Koran & Associates advises organizations whose cybersecurity obligations are written into regulation and contract. The practice covers CMMC readiness for the Defense Industrial Base, maritime cybersecurity under 33 CFR Part 101 Subpart F, C2M2 maturity assessments, AI governance, and cyber insurance readiness, delivered by one senior practitioner with more than 30 years in technology and a cybersecurity specialization since 2002.

Who the Practice Serves

Organizations that have to prove their security, not just describe it

  • Defense contractors preparing for CMMC Level 2, and the counsel who advise them
  • Vessel and facility operators covered by the USCG maritime cybersecurity rule
  • Utilities and critical-infrastructure operators measuring maturity across IT and OT
  • Organizations deploying AI that need documented governance behind it
  • Businesses facing cyber insurance placement or renewal questions they cannot yet answer
30+
Years in Technology
2002
Cybersecurity Since
ISO 27001
Auditor and Implementer
ABA
Associate Member, Public Contract Law
CyberAB Registered Practitioner Advanced credential badge
Registered Practitioner Advanced
In Print National Defense Magazine viewpoint contributor, July 2026 | Forbes quoted on CMMC assessment capacity, September 2026
The Practice

Five service areas. One practitioner.

Each area below is delivered the same way: hands on, in the client's environment, with written findings throughout. The frameworks differ, but the discipline is constant. Establish the ground truth, document it, and build a security posture that holds up when someone outside the organization examines it.

Defense Industrial Base

CMMC Consulting Services

Readiness, enablement, and implementation support for defense contractors handling Controlled Unclassified Information, and technical support for the legal counsel who advise them.

  • CMMC Level 2 and NIST SP 800-171 gap analysis
  • CUI identification and scope reduction
  • System Security Plan and policy development
  • Supplier due diligence and findings memoranda for counsel
Explore CMMC Services →
Marine Transportation System

Maritime Cybersecurity

Cybersecurity readiness for owners and operators of US-flagged vessels, facilities, and Outer Continental Shelf facilities covered by 33 CFR Part 101 Subpart F.

  • Cybersecurity officer designation and program structure
  • Cybersecurity assessment and plan development
  • Training, drills, and exercise design
  • Alignment with existing FSP and VSP obligations
Explore Maritime Cybersecurity →
Maturity

C2M2 Maturity Assessments

Independent facilitated assessments using the Department of Energy Cybersecurity Capability Maturity Model, spanning IT and operational technology.

  • Facilitated self-evaluation across all ten domains
  • Maturity indicator level scoring and evidence review
  • Executive findings and a prioritized investment roadmap
  • Repeatable baseline for year-over-year measurement
Explore C2M2 Assessments →
Governance

AI Governance

Governance structure for organizations already using AI, aligned with the NIST AI Risk Management Framework and ISO/IEC 42001, and backed by a published research library.

  • AI use inventory and risk classification
  • Policy, acceptable-use, and oversight structure
  • Vendor and third-party AI risk review
  • Documentation that stands up to customer and regulator questions
Explore AI Governance →
Insurance

Cyber Insurance Readiness

Independent assessment for businesses facing cyber insurance placement or renewal, from the application questions through remediation and the evidence carriers expect to see.

  • Control audit mapped to carrier application questions
  • Gap findings with remediation priorities
  • Evidence package for underwriting review
  • Remediation support through to placement
Explore Cyber Insurance Readiness →
How the Practice Works

Deliberately independent. Deliberately senior.

This is a small practice by design, usually carrying two clients at a time. It is one senior practitioner with more than 30 years of technology breadth, which is what compliance work actually requires: the person doing the work has to understand the infrastructure, the software, the data, the operational constraints, and the regulation all at once, because the gaps between those specialties are where findings hide.

01 The person you brief is the person who does the work

No handoff from a partner to a project manager to a rotating bench. The practitioner you talk to on the first call is the one who walks your facility, reviews your evidence, and writes the report.

02 Breadth over specialization

Infrastructure, networking, Linux, software development, data, manufacturing systems, and cybersecurity in one person. See the experience page for the full range.

03 Written evidence, always

Findings, decisions, and status are documented in writing throughout. In compliance work the record is the product, and it has to survive review by an assessor, a regulator, or opposing counsel.

04 Fluent in the legal and contractual context

Associate membership in the ABA Section of Public Contract Law and years of work alongside defense counsel mean the technical findings are written for the people who have to rely on them.

What clients buy is my time, my attention, and a willingness to travel to the facility and do the work there.
David W. Koran, CyberAB Registered Practitioner Advanced
David W. Koran
CyberAB Registered Practitioner Advanced
ISO/IEC 27001 Auditor and Implementer
ABA Section of Public Contract Law
ISACA Professional Member
About

David W. Koran

"The difference between a defensible security posture and compliance theater is knowing what matters, and why."

I am the founder and principal of David Koran & Associates Inc., an independent cybersecurity and compliance advisory practice. My background is more than 30 years in information technology: infrastructure and networking, Linux and systems administration, software development, business and manufacturing systems, and a cybersecurity specialization dating to 2002, much of it inside manufacturing and other regulated operational environments.

I hold the CyberAB Registered Practitioner Advanced credential and ISO/IEC 27001 certifications as an auditor and in implementation. I am an Associate Member of the American Bar Association Section of Public Contract Law and a professional member of ISACA. I am the author of The CMMC Decision and Cybersecurity in the Marine Transportation System, along with a library of practitioner white papers. My viewpoint writing has appeared in National Defense Magazine, and my analysis of CMMC assessment capacity was featured in Forbes.

I work onsite because security is an onsite discipline. The environment, the data, the people, and the daily operation determine whether controls are real, and none of those can be fully understood from a remote session. I travel to client sites throughout the United States.

I am an independent consultant. I am not a reseller, a software vendor, or a staffing firm. What I offer is documented ground truth, defensible findings, and work that holds up under scrutiny.

Get In Touch

Start a Conversation

Inquiries may involve CMMC readiness, a maritime cybersecurity program, a C2M2 assessment, AI governance, cyber insurance readiness, or technical support for counsel advising a defense contractor. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.

Address
Essex Junction, VT

A 30-Minute Introductory Call

Whether you are a defense contractor working out where you stand, an operator covered by a new rule, or counsel building a technical record for a client, the first conversation carries no commitment and no pitch.

Start a Conversation →