RedOps Cyber Intelligence — Regulated Mid-Market AI Security
About

The practice behind RedOps.

A deliberately small AI security and fractional CISO practice for regulated mid-market firms — so the person advising your board is the person doing the work.

Founder & Principal

Dr. Sam Wertheim, D.Cybersecurity

D.CybersecurityFractional CISOGenAI Threat ResearchNYDFS Part 500NIST AI RMF · ISO 42001SOC 2 · ISO 27001MITRE ATLAS

Sam Wertheim is a Doctor of Cybersecurity whose research focuses on generative-AI social engineering and behavioral threat intelligence — the same threat model RedOps engagements are built around. He founded RedOps to bring that work to the mid-market firms most exposed to it and least likely to have a full-time security executive.

Why a boutique practice

Small on purpose.

Most mid-market firms don't need a large consultancy or a full-time CISO. They need a senior practitioner who can stand up a defensible program, translate it for the board, and stay accountable for it — without the overhead of either. That's the gap RedOps is built to fill.

RedOps Cyber Intelligence Group secures regulated mid-market firms across the full enterprise AI security lifecycle — governance, risk, model defense, and adversarial testing. Engagements are productized into named programs with clear deliverables, because open-ended hourly consulting rarely produces the artifact a board or an auditor actually needs.

What we believe

Three principles
  • A human signs off on risk. AI accelerates the analysis, drafts the policy, and parses the vendor report — but accepting risk on behalf of a business is a human responsibility a board needs a named person to own.
  • Context is the job. Your culture, your board's risk tolerance, your regulators, and your customers are specific. Generic playbooks don't survive contact with them; good security leadership is mostly judgment applied to your situation.
  • Outcomes over labels. Clients buy board-ready outcomes — a certification, a governance memo, a defensible decision — not frameworks for their own sake. The methodology stays behind the curtain; the result is what we put in front of you.
Focus

The verticals where AI risk is now regulated.

Insurance

Insurance

P&C, life, and health carriers under NYDFS, NAIC model bulletins, and state AI rules.

Fintech

Fintech

Regulated and EU-facing fintech where SOC 2 and AI governance now arrive together.

SaaS

SaaS

B2B platforms shipping AI features to enterprise buyers who expect proof, not promises.

Work with RedOps

Let's talk about where your program stands.

Book a 30-minute consultation. No pitch deck — just a direct conversation about your AI security and compliance posture and the fastest defensible path forward.