NorthCreek Security Group

Security strategy and infrastructure modernization for the mid-market.

Veteran-owned consultancy delivering fractional CISO services, security program development, and infrastructure transformation for organizations across the TOLA+ region. Currently accepting select engagements.

Consulting engagements
Advisory & board seats
Speaking & conferences
Experience 25+ Years
CISO Roles 3 Previous
Region TOLA+
Veteran USMC

What we do.

Practical security and infrastructure guidance grounded in hands-on executive experience — not theoretical frameworks.

01 — vCISO

Fractional CISO

On-demand security leadership for organizations that need executive-level guidance without a full-time hire. Board reporting, security program development, risk management, compliance strategy, and incident response oversight built on real-world CISO experience across manufacturing, healthcare, and defense.

02 — Strategy

Security Program Development

Build or mature your security program from the ground up. Policy frameworks, team structure, vendor evaluation, tool consolidation, and roadmap development aligned with business objectives. We focus on programs that actually work in practice — not shelf-ready documentation.

03 — Infrastructure

Infrastructure Modernization

Strategic migration from legacy systems to modern, cloud-native architectures. Container orchestration, multi-cloud strategy, VMware-to-Kubernetes transitions, and infrastructure-as-code implementation. Designed for organizations running real workloads across multiple facilities and environments.

04 — Assessment

Security Assessments

Comprehensive vulnerability assessments and penetration testing that go beyond automated scanning. Attack surface mapping, risk-prioritized findings, and actionable remediation plans. We assess from an adversary's perspective, leveraging OSINT, open-source, and commercial tooling.

05 — Advisory

Executive Advisory

Confidential advisory services for C-suite executives and boards navigating technology risk, M&A technical due diligence, cyber insurance readiness, and regulatory compliance. A trusted sounding board with the technical depth to challenge assumptions and validate strategy.

06 — Architecture

Solution Architecture

Technical design and architecture review for complex environments spanning on-premises, cloud, and hybrid infrastructure. Identity and access management, network segmentation, zero trust implementation, and OT/IT convergence for manufacturing and industrial environments.

Background.

NorthCreek Security Group is the consulting practice of Andrew Healey — a technology executive with 25 years spanning infrastructure, cybersecurity, and operations leadership across manufacturing, defense, aerospace, healthcare, and cloud services.

With three previous CISO roles and experience leading large teams in both manufacturing, consulting, and cloud, NCSG brings a practitioner's perspective to every engagement. We've built security programs from scratch, modernized legacy infrastructure at scale, and led incident response for sophisticated threats — not from a consulting desk, but from inside the organizations we've served.

Based in Northwest Arkansas and serving the TOLA+ region, NCSG is particularly well-suited for mid-market manufacturers, food and agriculture companies, and regional enterprises navigating the transition from legacy systems to modern, secure infrastructure.

  • Three previous CISO roles across manufacturing, healthcare, and MSP
  • Sr. Director of Technology Infrastructure, Security, & Operations
  • AWS EC2 Professional Services — large-scale cloud operations
  • Enterprise architecture for defense and aerospace (General Dynamics, Aerojet Rocketdyne)
  • MSc Cybersecurity and Information Assurance
  • United States Marine Corps veteran — Operation Iraqi Freedom
  • Board Member for Infragard Arkansas — Joint Public FBI Partnership
CISSP OSCP CKA CKS KCNA KCSA AWS SAA CEH Linux+

Headquartered in Northwest Arkansas. Serving organizations across the TOLA+ corridor — from manufacturing floors to executive boardrooms.

TX · OK · LA · AR · KS · CO · MO

Start a conversation.

NCSG is currently accepting select consulting and advisory engagements. Whether you need a fractional CISO, a security assessment, or a trusted advisor for a specific initiative — reach out and let's talk.

Response time is typically within one business day.