Alana Vestergaard
Co-founder & Chief Executive
Incident responder by trade. Led the DFIR practice at a national consultancy before co-founding NCPS. CISSP, GCFA.
About NCPS InfoSec
NCPS Information Security, Inc. — trading as NCPS InfoSec — was incorporated in Delaware in 2011 and has run continuously ever since, privately held, under the same founding leadership, with no change of name and no pivot.
Continuous operation since 2011
Organisations currently under contract
Annual client renewal rate, three-year average
Employees — analysts, engineers, and advisors, all US-based
Our story
In 2011, three incident responders kept arriving at the same kind of scene: a 300-person credit union, a regional hospital group, a machine shop supplying a defense prime. Each had genuine regulatory obligations, a two-person IT department, and a security posture assembled from whatever their MSP happened to resell.
Enterprise security vendors would not serve them at that size. Managed IT providers sold them antivirus and called it a security programme. The gap was structural, and it was where the losses were happening.
So we built the thing that was missing: a security operation priced for the mid-market that behaves like an enterprise one. Staffed around the clock. Authorised to act. Measured on published service levels. Able to hand an examiner evidence without a scramble.
15 years later the model has not changed, and neither has the ownership. We have never taken outside capital, never been acquired, and never asked a client to sign a three-year lock-in. The renewal rate is the argument we would rather make.
What we will not do
Years of activity
Security providers appear and vanish on a three-year cycle. Here is every year of ours, and what changed in it.
Three founding incident responders open in Wilmington with six clients and an on-call rotation. First services: forensics and security assessments.
A regional credit union asks whether we can watch, not just investigate. The monitoring practice is built to answer that question.
GLBA and FFIEC work becomes a discipline of its own after our fourth NCUA examination engagement in a year.
Continuous shifts replace on-call. Pre-authorised containment authority is written into the standard agreement — unusual at the time, and the reason several clients joined.
PHI-aware monitoring launches after an OCR investigation at a client demonstrated what generic alerting misses.
Headcount passes 30. The evidence library — continuous compliance collection — is built to stop the annual screenshot scramble.
We put financial consequences behind the containment and response commitments. Nobody asked us to.
CREST-registered testers join in-house. In eight weeks we re-architect remote access for 61 clients and hold zero reportable incidents through the transition.
Nineteen intrusion attempts contained pre-encryption across the client base. The incident-response retainer becomes a standing product.
Passive industrial monitoring launches so containment on the IT estate never stops a production line.
We put ourselves through what we put clients through, annually, and share the report under NDA.
Defense-supplier readiness work begins ahead of the rule's phase-in, with enclave designs that keep CUI scope small.
Clients get read access to the rule set protecting them — including the detections written from our own testers' findings.
Still privately held. Still Delaware-incorporated. Still measured against the same published service levels.
Leadership
Every one of them still works engagements. You will meet the person accountable for your account before you sign anything.
Co-founder & Chief Executive
Incident responder by trade. Led the DFIR practice at a national consultancy before co-founding NCPS. CISSP, GCFA.
Co-founder & Chief Technology Officer
Built the detection platform and still writes rules. Twenty-two years in security engineering. GSE, GCIA.
Chief Information Security Officer
Former bank CISO and NCUA examination veteran. Leads the vCISO practice and sits on client audit committees. CISSP, CISA.
Director of Offensive Security
Runs the testing team. Ten years of red-team work across finance and critical infrastructure. OSCP, OSCE, CREST CCT.
Certifications & credentials
Individual credentials are verified at hire and re-verified annually. Our SOC 2 Type II report is available under NDA on request.
Service levels
These are contractual. Missing them earns you service credits automatically — you do not have to notice and file a claim.
| Commitment | Target | Measured | Remedy if missed |
|---|---|---|---|
| Critical detection containment | ≤ 15 minutes | Per event | 5% monthly credit |
| High-severity analyst triage | ≤ 30 minutes | Per event | 3% monthly credit |
| Incident-response engagement | ≤ 60 minutes | Per event | 10% retainer credit |
| Monitoring platform availability | 99.9% | Monthly | Tiered to 25% credit |
| Penetration-test report delivery | 10 business days | Per engagement | 10% fee credit |
| Evidence request turnaround | 2 business days | Per request | Escalation to CISO |
| Service review cadence | Per plan | Quarterly | Executive escalation |
Full definitions, measurement methodology, and exclusions are set out in the service-level schedule to the master services agreement, which we will send before you ask for it.
Headquarters
NCPS Information Security, Inc. is a Delaware corporation with its principal office in Wilmington and security operations delivered from US-based facilities. Analysts work in shift rotation across the country; monitoring, response, and data storage never leave the United States.
NCPS Information Security, Inc.
Sales (833) 761-0695 · SOC hotline (833) 761-0695
hello@ncpsinfosec.com
Corporate facts
Certificates of insurance, W-9, SOC 2 report, and standard MSA are available to prospective clients on request — usually the same day.
Next step
We run passive reconnaissance against your public perimeter, map exposed services and leaked credentials, and walk your team through the findings. No agents to install, no obligation.