Cybersecurity Advisory for Regulated Industries
David Koran & Associates advises organizations whose cybersecurity obligations are written into regulation and contract. The practice covers CMMC readiness for the Defense Industrial Base, maritime cybersecurity under 33 CFR Part 101 Subpart F, C2M2 maturity assessments, AI governance, and cyber insurance readiness, delivered by one senior practitioner with more than 30 years in technology and a cybersecurity specialization since 2002.
Organizations that have to prove their security, not just describe it
- Defense contractors preparing for CMMC Level 2, and the counsel who advise them
- Vessel and facility operators covered by the USCG maritime cybersecurity rule
- Utilities and critical-infrastructure operators measuring maturity across IT and OT
- Organizations deploying AI that need documented governance behind it
- Businesses facing cyber insurance placement or renewal questions they cannot yet answer

Five service areas. One practitioner.
Each area below is delivered the same way: hands on, in the client's environment, with written findings throughout. The frameworks differ, but the discipline is constant. Establish the ground truth, document it, and build a security posture that holds up when someone outside the organization examines it.
CMMC Consulting Services
Readiness, enablement, and implementation support for defense contractors handling Controlled Unclassified Information, and technical support for the legal counsel who advise them.
- CMMC Level 2 and NIST SP 800-171 gap analysis
- CUI identification and scope reduction
- System Security Plan and policy development
- Supplier due diligence and findings memoranda for counsel
Maritime Cybersecurity
Cybersecurity readiness for owners and operators of US-flagged vessels, facilities, and Outer Continental Shelf facilities covered by 33 CFR Part 101 Subpart F.
- Cybersecurity officer designation and program structure
- Cybersecurity assessment and plan development
- Training, drills, and exercise design
- Alignment with existing FSP and VSP obligations
C2M2 Maturity Assessments
Independent facilitated assessments using the Department of Energy Cybersecurity Capability Maturity Model, spanning IT and operational technology.
- Facilitated self-evaluation across all ten domains
- Maturity indicator level scoring and evidence review
- Executive findings and a prioritized investment roadmap
- Repeatable baseline for year-over-year measurement
AI Governance
Governance structure for organizations already using AI, aligned with the NIST AI Risk Management Framework and ISO/IEC 42001, and backed by a published research library.
- AI use inventory and risk classification
- Policy, acceptable-use, and oversight structure
- Vendor and third-party AI risk review
- Documentation that stands up to customer and regulator questions
Cyber Insurance Readiness
Independent assessment for businesses facing cyber insurance placement or renewal, from the application questions through remediation and the evidence carriers expect to see.
- Control audit mapped to carrier application questions
- Gap findings with remediation priorities
- Evidence package for underwriting review
- Remediation support through to placement
Deliberately independent. Deliberately senior.
This is a small practice by design, usually carrying two clients at a time. It is one senior practitioner with more than 30 years of technology breadth, which is what compliance work actually requires: the person doing the work has to understand the infrastructure, the software, the data, the operational constraints, and the regulation all at once, because the gaps between those specialties are where findings hide.
01 The person you brief is the person who does the work
No handoff from a partner to a project manager to a rotating bench. The practitioner you talk to on the first call is the one who walks your facility, reviews your evidence, and writes the report.
02 Breadth over specialization
Infrastructure, networking, Linux, software development, data, manufacturing systems, and cybersecurity in one person. See the experience page for the full range.
03 Written evidence, always
Findings, decisions, and status are documented in writing throughout. In compliance work the record is the product, and it has to survive review by an assessor, a regulator, or opposing counsel.
04 Fluent in the legal and contractual context
Associate membership in the ABA Section of Public Contract Law and years of work alongside defense counsel mean the technical findings are written for the people who have to rely on them.
Two books, a control reference, and a working research library.
The practice publishes what it learns. Everything below is freely available and written for practitioners and executives rather than for search engines.
The CMMC Decision, Second Edition
The strategic framework for CEOs and senior executives of small and midsize defense contractors evaluating CMMC requirements and leading the organization through compliance.
Cybersecurity in the Marine Transportation System
A practitioner's guide to the USCG maritime cybersecurity rule and what it requires of vessel and facility operators.
The CMMC Guide
A control-by-control reference to all 110 NIST SP 800-171 requirements as assessed under CMMC Level 2.
Research Library
Cited practitioner white papers across defense, maritime, and AI governance.
Daily Cybersecurity Brief
Current threats, advisories, and regulatory developments translated into practical action.
Registered Practitioner Advanced
What the CyberAB RPA credential means and how it shapes the way this practice approaches CMMC work.
CyberAB Registered Practitioner Advanced
ISO/IEC 27001 Auditor and Implementer
ABA Section of Public Contract Law
ISACA Professional Member
David W. Koran
I am the founder and principal of David Koran & Associates Inc., an independent cybersecurity and compliance advisory practice. My background is more than 30 years in information technology: infrastructure and networking, Linux and systems administration, software development, business and manufacturing systems, and a cybersecurity specialization dating to 2002, much of it inside manufacturing and other regulated operational environments.
I hold the CyberAB Registered Practitioner Advanced credential and ISO/IEC 27001 certifications as an auditor and in implementation. I am an Associate Member of the American Bar Association Section of Public Contract Law and a professional member of ISACA. I am the author of The CMMC Decision and Cybersecurity in the Marine Transportation System, along with a library of practitioner white papers. My viewpoint writing has appeared in National Defense Magazine, and my analysis of CMMC assessment capacity was featured in Forbes.
I work onsite because security is an onsite discipline. The environment, the data, the people, and the daily operation determine whether controls are real, and none of those can be fully understood from a remote session. I travel to client sites throughout the United States.
I am an independent consultant. I am not a reseller, a software vendor, or a staffing firm. What I offer is documented ground truth, defensible findings, and work that holds up under scrutiny.
Start a Conversation
Inquiries may involve CMMC readiness, a maritime cybersecurity program, a C2M2 assessment, AI governance, cyber insurance readiness, or technical support for counsel advising a defense contractor. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.
A 30-Minute Introductory Call
Whether you are a defense contractor working out where you stand, an operator covered by a new rule, or counsel building a technical record for a client, the first conversation carries no commitment and no pitch.
Start a Conversation →