24/7/365 SOC — average triage time 4m 51s

About NCPS InfoSec

15 years of doing one thing.

NCPS Information Security, Inc. — trading as NCPS InfoSec — was incorporated in Delaware in 2011 and has run continuously ever since, privately held, under the same founding leadership, with no change of name and no pivot.

15yrs

Continuous operation since 2011

312+

Organisations currently under contract

96%

Annual client renewal rate, three-year average

74

Employees — analysts, engineers, and advisors, all US-based

Our story

We started because the same organisations kept getting hit.

In 2011, three incident responders kept arriving at the same kind of scene: a 300-person credit union, a regional hospital group, a machine shop supplying a defense prime. Each had genuine regulatory obligations, a two-person IT department, and a security posture assembled from whatever their MSP happened to resell.

Enterprise security vendors would not serve them at that size. Managed IT providers sold them antivirus and called it a security programme. The gap was structural, and it was where the losses were happening.

So we built the thing that was missing: a security operation priced for the mid-market that behaves like an enterprise one. Staffed around the clock. Authorised to act. Measured on published service levels. Able to hand an examiner evidence without a scramble.

15 years later the model has not changed, and neither has the ownership. We have never taken outside capital, never been acquired, and never asked a client to sign a three-year lock-in. The renewal rate is the argument we would rather make.

What we will not do

  • Resell what we would not run. If we would not put our own analysts behind a product, we do not sell it to you.
  • Audit and remediate the same control. We will not grade our own homework, and we will say so when asked.
  • Offshore your telemetry. All monitoring and response is performed by US-based employees, never subcontracted.
  • Hold your data hostage. Export on demand, in open formats, including on the way out the door.
  • Sell fear. If a control is not worth what it costs you, we will tell you not to buy it.

Years of activity

2011 to 2026, without a gap.

Security providers appear and vanish on a three-year cycle. Here is every year of ours, and what changed in it.

  1. 2011

    Incorporated in Delaware

    Three founding incident responders open in Wilmington with six clients and an on-call rotation. First services: forensics and security assessments.

  2. 2013

    First managed monitoring contract

    A regional credit union asks whether we can watch, not just investigate. The monitoring practice is built to answer that question.

  3. 2014

    Financial-services practice formed

    GLBA and FFIEC work becomes a discipline of its own after our fourth NCUA examination engagement in a year.

  4. 2016

    24/7 SOC goes live

    Continuous shifts replace on-call. Pre-authorised containment authority is written into the standard agreement — unusual at the time, and the reason several clients joined.

  5. 2017

    Healthcare practice and BAA programme

    PHI-aware monitoring launches after an OCR investigation at a client demonstrated what generic alerting misses.

  6. 2018

    100th client

    Headcount passes 30. The evidence library — continuous compliance collection — is built to stop the annual screenshot scramble.

  7. 2019

    Published SLAs with service credits

    We put financial consequences behind the containment and response commitments. Nobody asked us to.

  1. 2020

    Offensive practice formed; remote-work surge

    CREST-registered testers join in-house. In eight weeks we re-architect remote access for 61 clients and hold zero reportable incidents through the transition.

  2. 2021

    The ransomware years

    Nineteen intrusion attempts contained pre-encryption across the client base. The incident-response retainer becomes a standing product.

  3. 2022

    Manufacturing and OT practice

    Passive industrial monitoring launches so containment on the IT estate never stops a production line.

  4. 2023

    SOC 2 Type II on our own operation

    We put ourselves through what we put clients through, annually, and share the report under NDA.

  5. 2024

    CMMC Level 2 practice

    Defense-supplier readiness work begins ahead of the rule's phase-in, with enclave designs that keep CUI scope small.

  6. 2025

    Detection engineering opens to clients

    Clients get read access to the rule set protecting them — including the detections written from our own testers' findings.

  7. 2026

    312 organisations, 74 employees

    Still privately held. Still Delaware-incorporated. Still measured against the same published service levels.

Leadership

The people who sign the SLA.

Every one of them still works engagements. You will meet the person accountable for your account before you sign anything.

AV

Alana Vestergaard

Co-founder & Chief Executive

Incident responder by trade. Led the DFIR practice at a national consultancy before co-founding NCPS. CISSP, GCFA.

DO

Dmitri Okonkwo

Co-founder & Chief Technology Officer

Built the detection platform and still writes rules. Twenty-two years in security engineering. GSE, GCIA.

PR

Priya Raghunathan

Chief Information Security Officer

Former bank CISO and NCUA examination veteran. Leads the vCISO practice and sits on client audit committees. CISSP, CISA.

MC

Marcus Cheng

Director of Offensive Security

Runs the testing team. Ten years of red-team work across finance and critical infrastructure. OSCP, OSCE, CREST CCT.

Certifications & credentials

Held by the company, and by the people on your account.

SOC 2 Type II
Our own operation, annual
CREST
Registered testing team
CISSP
21 staff
OSCP / OSCE
Offensive practice
GCIH / GCIA
SOC analysts
GCFA
Forensics team
CISA
Compliance practice
HCISPP
Healthcare practice
CCSP
Cloud practice
CMMC RP
Registered Practitioners

Individual credentials are verified at hire and re-verified annually. Our SOC 2 Type II report is available under NDA on request.

Service levels

The commitments, with consequences attached.

These are contractual. Missing them earns you service credits automatically — you do not have to notice and file a claim.

Service level commitments and remedies
CommitmentTargetMeasuredRemedy if missed
Critical detection containment≤ 15 minutesPer event5% monthly credit
High-severity analyst triage≤ 30 minutesPer event3% monthly credit
Incident-response engagement≤ 60 minutesPer event10% retainer credit
Monitoring platform availability99.9%MonthlyTiered to 25% credit
Penetration-test report delivery10 business daysPer engagement10% fee credit
Evidence request turnaround2 business daysPer requestEscalation to CISO
Service review cadencePer planQuarterlyExecutive escalation

Full definitions, measurement methodology, and exclusions are set out in the service-level schedule to the master services agreement, which we will send before you ask for it.

Headquarters

Wilmington, Delaware.

NCPS Information Security, Inc. is a Delaware corporation with its principal office in Wilmington and security operations delivered from US-based facilities. Analysts work in shift rotation across the country; monitoring, response, and data storage never leave the United States.

NCPS Information Security, Inc.
1000 N. West Street, Suite 1200
Wilmington, DE 19801
US

Sales (833) 761-0695 · SOC hotline (833) 761-0695
hello@ncpsinfosec.com

Arrange a conversation

Corporate facts

Legal entity
NCPS Information Security, Inc.
Incorporated
Delaware, 2011
Ownership
Privately held
Employees
74
Data residency
United States
Insurance
E&O + cyber, $10M

Certificates of insurance, W-9, SOC 2 report, and standard MSA are available to prospective clients on request — usually the same day.

Next step

See what an attacker sees — in 30 minutes, at no cost.

We run passive reconnaissance against your public perimeter, map exposed services and leaked credentials, and walk your team through the findings. No agents to install, no obligation.

  • Findings report delivered in 3 business days
  • No sales engineer required to read it
  • Yours to keep, whether or not you hire us