CMMC and NIST 800-171 Readiness
Scope your environment, assess controls against the 110 requirements, build the SSP and POA&M, and close gaps in a defensible order ahead of assessment.
Learn moreAtlanta, Georgia
Secure Technology Consultants helps government contractors and growing businesses reduce cyber risk, prepare for CMMC and NIST requirements, strengthen Microsoft 365, and build practical security programs without enterprise-level overhead.

Atlanta-based, practitioner-led advisory
CMMC and NIST 800-171 focused advisory
Microsoft 365 security and governance depth
Metro Atlanta on-site and remote engagements nationwide
Core services
Six engagement areas that can stand alone or work together as a single roadmap.
Scope your environment, assess controls against the 110 requirements, build the SSP and POA&M, and close gaps in a defensible order ahead of assessment.
Learn moreExecutive security leadership on a fractional basis: policy, roadmap, budget guidance, vendor oversight, and board-ready reporting.
Learn moreIdentify what would hurt the business most, rank exposures by likelihood and impact, and translate findings into a funded remediation plan.
Learn moreHarden identity and access, tune Defender and Purview configurations, and put data-sharing guardrails in place across Teams, SharePoint, and OneDrive.
Learn morePractical response playbooks, escalation paths, and tested recovery expectations so a bad day stays contained and documented.
Learn moreOngoing monitoring, patch and endpoint hygiene, and day-to-day IT support aligned to the same control set your compliance program depends on.
Learn moreFrameworks and capabilities
Framework alignment is a means to an end: fewer unmanaged risks, cleaner evidence, and faster answers when a customer asks how you protect their information.
Level 1 and Level 2 readiness planning, evidence organization, and assessment preparation support.
Control-by-control gap analysis, SSP and POA&M development, and CUI scoping guidance.
Profile development and maturity tracking across Govern, Identify, Protect, Detect, Respond, and Recover.
Categorization, control selection, and continuous monitoring practices adapted to smaller teams.
Identity, device, data, and tenant configuration baselines mapped back to your framework obligations.
Acceptable-use policy, data handling rules, model and vendor review, and human oversight for AI tools.
How STC works
Understand the business, systems, data flows, and obligations before recommending a single control.
Sequence work by risk reduction and compliance deadline so limited budget goes to what matters first.
Deploy controls, policies, and configurations with your team or ours, documented as we go.
Test that controls work as written and that evidence is complete enough to withstand review.
Review changes, threats, and audit findings on a regular cadence and adjust the roadmap.
Industries served
Municipalities, county governments, public agencies, and government partners requiring defensible security, risk, compliance, and IT operational oversight.
Prime contractors, subcontractors, and professional-services firms working toward DFARS, NIST SP 800-171, CMMC, and customer-driven security requirements.
Public-health, healthcare-support, research, and consulting organizations protecting sensitive operational, workforce, and program information.
Software developers, technology partners, MSPs, and cybersecurity providers requiring secure infrastructure, governance, service-delivery oversight, and client-data protection.
Organizations handling candidate, employee, customer, financial, and other sensitive personal information across cloud applications and distributed workforces.
Agencies, consultancies, and growing service businesses that need practical security leadership and reliable IT operations without building a full internal department.
AI-enabled solutions
Our AI work starts with policy, data boundaries, and oversight. Where STC evaluates partner-developed product concepts, we identify them clearly as pilots or private demonstrations rather than generally available software.
Evaluate where AI tools can help, what data they may touch, and the controls required before rollout.
Policy, review workflow, and oversight roles so AI use stays documented and defensible.
Reduce manual effort in security and compliance operations with reviewed, auditable automation.
Assess prospective AI tools, including vendor safeguards, data access, privacy, security, and contractual risk before adoption.
A test-ready demonstration exploring vehicle tracking, field activity visibility, and conversational operational reporting.

Pilot participation and private demonstrations are arranged case by case. Reach out to discuss fit, scope, and data handling.
Start the conversationWhy STC
You work directly with the person doing the assessment, not a handoff chain.
Programs built for the staff and budget you actually have, not an enterprise template.
Security decisions account for how your systems are supported and run day to day.
Findings and roadmaps written so leadership can act on them without translation.

Founder & Principal Consultant
Cybersecurity, Risk & Governance Leader
Derek Hardmon founded Secure Technology Consultants to give growing and regulated organizations direct access to experienced cybersecurity, risk, and technology leadership—without the cost or complexity of building every capability internally.
Before founding STC, Derek held senior technology and information security leadership positions in financial services, including Vice President of Information Technology and Vice President, Information Security Officer. His broader career has included cybersecurity, risk, technology operations, and advisory work supporting government, regulated organizations, managed service environments, and growing businesses.
Derek's approach connects cybersecurity decisions to business realities. Rather than treating security and compliance as separate technical exercises, he helps organizations understand what information and systems matter most, where meaningful risk exists, what requirements apply, and what should be addressed first. His work includes cybersecurity and technology assessments, NIST-aligned governance, CMMC readiness, Microsoft 365 security, identity and access management, policy development, incident-response planning, vendor risk management, security program development, and fractional cybersecurity leadership.
Every STC engagement includes Derek’s direct involvement—from discovery and risk prioritization through recommendations, implementation oversight, documentation, and executive reporting. When specialized expertise is required, STC coordinates with trusted technology partners while remaining directly accountable for the quality and outcome of the engagement.
Experience & Leadership
Former Vice President of Information Technology and Vice President, Information Security Officer in financial services.
Served for several years on the Information Systems Security Association (ISSA) Metro Atlanta Chapter Board of Directors, including as Treasurer and Conference Chairman.
Former Board Member of The Intown Academy, an Atlanta charter school, with experience contributing to organizational governance and community leadership.
Contact
A short introductory conversation is usually enough to identify your most pressing gap and the practical next step. No obligation, no scripted pitch.