What we believe

01

Configure before you buy

About 90% of the security improvements small businesses need are configuration changes to tools they already own — especially Microsoft 365. We sell expertise, not licenses, and we don't take vendor commissions.

02

Complement, never replace

Your IT provider or MSP keeps the business running, and that's hard work worth respecting. We focus on security posture and work alongside them — many of our roadmaps are executed by the client's existing IT team.

03

No fear, just facts

The security industry loves scaring people into purchases. We don't. You get a measured score, plain-English explanations, and prioritized fixes — and where you're already strong, we'll say so.

04

Measure everything

Every engagement starts with a scored baseline and ends with a re-score. If we can't show improvement in numbers, we haven't done our job.

05

Built for 1–100

Enterprise consulting scales down badly. We only work with small and medium businesses, so everything — the reports, the recommendations, the pace — is sized for how you actually operate.

06

Leave you smarter

Every engagement includes knowledge transfer. We'd rather teach your team how the protections work than make ourselves indispensable. No black boxes, no lock-in.

How we work

Everything starts with the security assessment: a scored baseline of 29 controls across five domains — identity, email, devices, data, and backup — followed by 90 days of prioritized fixes. From there, clients who want a long-term partner move into the quarterly partnership or the embedded monthly program.

We've built particular depth in three industries: dental and healthcare practices, professional services and financial advisory firms, and small business and retail. When a compliance framework is part of your picture, we can run a security-focused gap analysis — but to be clear about scope: we handle the security and technology side only. We don't certify anyone, we don't run audits, and we don't give legal or compliance advice.

Who's behind it

Cyber Intelligence Consulting was founded by Lucas Christensen after years of working in IT and security, where the same pattern kept showing up: enterprises had security teams, tools, and budgets — and small businesses had none of the three, despite facing many of the same threats. The tools, it turned out, were usually already there in the software these businesses paid for every month. What was missing was someone to configure them. That gap is the reason this company exists.

Lucas holds a B.S. in Digital Forensics and Security, an M.S. in Cybersecurity, and the CompTIA Security+ certification. The company is based in Lehi, Utah, in the heart of Silicon Slopes — serving Utah County and Salt Lake County in person, and businesses nationwide remotely. You can find Lucas on LinkedIn.

We're deliberately small. You work directly with the person doing the analysis — not an account manager relaying messages to a team you'll never meet. That's also why our Diamond program has limited availability: embedded means embedded.

A note on our promises: nobody can guarantee you'll never have a security incident, and you should be suspicious of anyone who does. What we promise instead: you'll know exactly where you stand, the highest-impact gaps will get closed, and you'll be able to prove it — to insurers, regulators, clients, and yourself.

The practical details

Start with a conversation, not a contract.

Tell us about your business — we'll get back to you, and we'll tell you honestly if we're not the right fit. Or call (949) 802-4831.