CMMC and NIST 800-171 Readiness
Scope your environment, assess controls against the 110 requirements, build the SSP and POA&M, and close gaps in a defensible order ahead of assessment.
Learn moreAtlanta, Georgia
Secure Technology Consultants helps government contractors and growing businesses reduce cyber risk, prepare for CMMC and NIST requirements, strengthen Microsoft 365, and build practical security programs without enterprise-level overhead.

Atlanta-based cybersecurity and technology advisory
CMMC and NIST 800-171 focused advisory
Microsoft 365 security and governance depth
Metro Atlanta on-site and remote engagements nationwide
Core services
Six engagement areas that can stand alone or work together as a single roadmap.
Scope your environment, assess controls against the 110 requirements, build the SSP and POA&M, and close gaps in a defensible order ahead of assessment.
Learn moreExecutive security leadership on a fractional basis: policy, roadmap, budget guidance, vendor oversight, and board-ready reporting.
Learn moreIdentify what would hurt the business most, rank exposures by likelihood and impact, and translate findings into a funded remediation plan.
Learn moreHarden identity and access, tune Defender and Purview configurations, and put data-sharing guardrails in place across Teams, SharePoint, and OneDrive.
Learn morePractical response playbooks, escalation paths, and tested recovery expectations so a bad day stays contained and documented.
Learn moreOngoing monitoring, patch and endpoint hygiene, and day-to-day IT support aligned to the same control set your compliance program depends on.
Learn moreFrameworks and capabilities
Framework alignment is a means to an end: fewer unmanaged risks, cleaner evidence, and faster answers when a customer asks how you protect their information.
Level 1 and Level 2 readiness planning, evidence organization, and assessment preparation support.
Control-by-control gap analysis, SSP and POA&M development, and CUI scoping guidance.
Profile development and maturity tracking across Govern, Identify, Protect, Detect, Respond, and Recover.
Categorization, control selection, and continuous monitoring practices adapted to smaller teams.
Identity, device, data, and tenant configuration baselines mapped back to your framework obligations.
Acceptable-use policy, data handling rules, model and vendor review, and human oversight for AI tools.
How STC works
Understand the business, systems, data flows, and obligations before recommending a single control.
Sequence work by risk reduction and compliance deadline so limited budget goes to what matters first.
Deploy controls, policies, and configurations with your team or ours, documented as we go.
Test that controls work as written and that evidence is complete enough to withstand review.
Review changes, threats, and audit findings on a regular cadence and adjust the roadmap.
Industries served
Municipalities, county governments, public agencies, and government partners requiring defensible security, risk, compliance, and IT operational oversight.
Prime contractors, subcontractors, and professional-services firms working toward DFARS, NIST SP 800-171, CMMC, and customer-driven security requirements.
Public-health, healthcare-support, research, and consulting organizations protecting sensitive operational, workforce, and program information.
Software developers, technology partners, MSPs, and cybersecurity providers requiring secure infrastructure, governance, service-delivery oversight, and client-data protection.
Organizations handling candidate, employee, customer, financial, and other sensitive personal information across cloud applications and distributed workforces.
Agencies, consultancies, and growing service businesses that need practical security leadership and reliable IT operations without building a full internal department.
AI-enabled solutions
Our AI work starts with policy, data boundaries, and oversight. Where STC evaluates partner-developed product concepts, we identify them clearly as pilots or private demonstrations rather than generally available software.
Evaluate where AI tools can help, what data they may touch, and the controls required before rollout.
Policy, review workflow, and oversight roles so AI use stays documented and defensible.
Reduce manual effort in security and compliance operations with reviewed, auditable automation.
Assess prospective AI tools, including vendor safeguards, data access, privacy, security, and contractual risk before adoption.
A test-ready demonstration exploring vehicle tracking, field activity visibility, and conversational operational reporting.

Pilot participation and private demonstrations are arranged case by case. Reach out to discuss fit, scope, and data handling.
Start the conversationWhy STC
Every engagement receives experienced leadership, defined accountability, and clear communication from initial discovery through final recommendations and ongoing service delivery.
STC aligns leadership, technical resources, and trusted service partners to the requirements, coverage, and specialized expertise of each engagement.
Services are designed around the client's actual environment, risk, staffing, and budget rather than imposed from a generic enterprise template.
Recommendations account for how technology is configured, supported, monitored, and used in day-to-day business operations.
Findings, priorities, responsibilities, and roadmaps are documented so leadership can make informed decisions and track progress.
Leadership
Founder and President
Derek Hardmon founded Secure Technology Consultants to help growing and regulated organizations strengthen cybersecurity, manage technology risk, and meet expanding contractual and compliance requirements.
Before founding STC, Derek held senior technology and information security leadership positions in financial services, including Vice President of Information Technology and Vice President, Information Security Officer. His experience also includes cybersecurity advisory, technology operations, risk management, governance, and security-program leadership across public-sector, regulated, managed-service, and commercial environments.
Under Derek's leadership, STC provides cybersecurity advisory, compliance readiness, Microsoft 365 security, managed security and IT operations, risk assessments, policy development, incident-response planning, vendor-risk management, and fractional security leadership.
STC uses a structured engagement model that defines scope, responsibilities, technical resources, escalation paths, documentation, and measurable outcomes. When an engagement requires additional capacity or specialized expertise, STC coordinates with qualified technology and service partners while maintaining clear accountability for delivery.
Selected delivery experience
Cybersecurity, risk, compliance, and technology-operations support for municipal, county, and other public-sector environments.
Control assessments, environment scoping, SSP and POA&M development, evidence organization, remediation planning, and assessment preparation.
Endpoint monitoring, patch and vulnerability management, identity and access controls, Microsoft 365 security, operational support, and service-delivery oversight.
Development and improvement of policies, governance processes, risk registers, incident-response procedures, vendor controls, executive reporting, and security roadmaps.
Experience coordinating multiple client engagements, technical priorities, stakeholder groups, and documentation requirements across public-sector and commercial environments.
Experience & Leadership
Former Vice President of Information Technology and Vice President, Information Security Officer in financial services.
Served for several years on the Information Systems Security Association (ISSA) Metro Atlanta Chapter Board of Directors, including as Treasurer and Conference Chairman.
Former Board Member of The Intown Academy, an Atlanta charter school, with experience contributing to organizational governance and community leadership.
Contact
A short introductory conversation is usually enough to identify your most pressing gap and the practical next step. No obligation, no scripted pitch.