NewSimpleSec — AI-orchestrated pentests, built on the tools auditors already trust.Visit simplesec.ai →

Summit Cyber Group · vCISO · GRC · Penetration testing

Security progress without hiring a full-time security team.

Penetration testing, exposure assessments, and ongoing security programs — mapped against your real attack surface, delivered by the person doing the work.

What we do

We test the doors you forgot existed.

The old VPN portal. The staging server nobody decommissioned. The contractor account that still works. We find the ways in before someone else does — and show you how to close them.

  • Pentesting
  • vCISO
  • Risk & Compliance
  • Security Advisory

Services

Senior security leadership, on your schedule.

Strategy, compliance, and offensive testing from the same small team of practitioners — so the people setting your roadmap are the ones who've broken into networks like yours.

01Fractional CISO

vCISO

Virtual · Fractional · On-demand CISO

A seasoned security leader embedded in your business for a fraction of a full-time hire. We own the security program, report to leadership, and keep it moving quarter after quarter.

  • Security strategy & 12-month roadmap
  • Board and executive reporting
  • Policies, standards & procedures
  • Vendor and third-party risk
  • Incident response planning
  • Security questionnaires & customer audits
  • Annual penetration test
  • Ongoing automated pentesting · SimpleSec
  • Code repository testing
  • Vulnerability scanning
  • PCI DSS support
  • Monthly retainer
  • Part-time embedded
  • Leadership reporting
02Governance, risk & compliance

GRC & Compliance

Readiness · Gap assessments · Audit support

Get audit-ready without the consultancy sprawl. We map your current controls to the framework you need, close the gaps, and stay with you through the audit.

  • Gap assessments & readiness
  • Risk register & risk assessments
  • Control implementation guidance
  • Evidence collection & audit support
  • SOC 2
  • ISO 27001
  • HIPAA
  • PCI DSS
  • NIST CSF
  • CMMC
03Offensive security

Penetration Testing

Human-led · AI-augmented

Real attackers think laterally. Every Summit engagement is scoped, run, and validated by a human pentester. For clients who subscribe, SimpleSec adds on-demand automated, AI-orchestrated penetration testing — and our team can review and certify those results, too.

  • External & internal network
  • Web application & API
  • Cloud configuration review
  • Social engineering & phishing
  • Remediation retesting
  • Evidence-backed findings
  • Executive + technical report
Not sure where to start? Most clients begin with a Security Baseline Engagement.Talk to a consultant

Engagements

Structured engagements that reduce risk.

01One-time

Security Baseline Engagement

Starting at$5,000

  • External attack surface mapping
  • Targeted web and API penetration testing
  • Credential exposure analysis
  • Executive and technical reporting
Discuss this engagement
02Ongoing

Security Progress Program

Starting at$3,000/ month

  • Quarterly targeted testing
  • Continuous dark web monitoring
  • Remediation validation
  • Monthly advisory call
Discuss this engagement

Direct access.
No middle layer.

Summit is a US-based firm headquartered in Colorado, with testers across the country — and you work directly with the security professional performing the engagement. No subcontractors, no layered project management, no third-party markup — structured security delivered with clarity and accountability.

  1. Your teamscope · access · context
  2. Summit engineertests · validates · reports
  3. Your findingsprioritized · evidence-backed
  • subcontractors
  • account managers
  • third-party markup

Credentials

The person doing the work is certified to do it.

Our vCISO and pentesting team holds the certifications that matter at every level of the job — from the boardroom to the command line, the web app to the wireless network.

Security leadership

  • CISSPCertified Information Systems Security ProfessionalISC2
  • CCISOCertified Chief Information Security OfficerEC-Council

Pentesting & red team

  • OSCPOffSec Certified ProfessionalOffSec
  • CPTSCertified Penetration Testing SpecialistHack The Box
  • CRTOCertified Red Team OperatorZero-Point Security
  • CEHCertified Ethical HackerEC-Council

Web & wireless

  • BSCPBurp Suite Certified PractitionerPortSwigger
  • CWESCertified Web Exploitation SpecialistHack The Box
  • OSWPOffSec Wireless ProfessionalOffSec

Forensics & identity

  • CFCECertified Forensic Computer ExaminerIACIS
  • CIAMCertified Identity and Access ManagerIdentity Management Institute

CREST PathwayIssued by CREST to Summit Cyber Group, LLC. View on Credly →

Our tooling · Just launched

Built by our pentesters. Available to yours.

SimpleSec is the AI-orchestrated platform our team uses to handle recon and enumeration at scale — so every hour of a Summit engagement goes to the work that takes a human. Your team can run it too.

A full external or internal pentest, end to end — recon, enumeration, validation — using 40+ industry-standard tools coordinated by an AI planner. Evidence-backed findings. No black box.

  • Internal network pentests via WireGuard agent
  • AttackForge, PDF, and CSV report exports
  • Approval gates and full audit log on every action
app.simplesec.ai
SimpleSec overview dashboard showing a live test, open findings by severity, and findings needing attention
  • nmap
  • nuclei
  • sqlmap
  • ffuf
  • subfinder
  • httpx
  • netexec
  • testssl
  • + 32 more

Free exposure snapshot

Reduce risk.
Gain relief.

Get a structured view of your external exposure and understand where to focus first.

Frequently asked

How much does penetration testing cost for a small business?

At Summit Cyber Group, penetration testing for a small business starts at $5,000 for a one-time Security Baseline Engagement; final cost depends on scope and exposure. For ongoing coverage, the Security Progress Program starts at $3,000 per month and includes quarterly targeted testing, continuous dark web monitoring, remediation validation, and a monthly advisory call.

What is a vCISO, and does a small business need one?

A vCISO (virtual or fractional Chief Information Security Officer) is a senior security leader who runs your security program part-time, for a fraction of the cost of a full-time hire. Summit's vCISO service covers a 12-month security roadmap, board and executive reporting, policies, vendor risk, incident response planning, security questionnaires and customer audits, and an annual penetration test. It suits businesses that need security leadership and accountability but not a full-time executive.

Which compliance frameworks do you help with?

Summit Cyber Group supports SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and CMMC. We run gap assessments and readiness reviews, build your risk register, guide control implementation, and help collect evidence and support you through the audit.

What is a Free Exposure Snapshot?

A Free Exposure Snapshot is a lightweight assessment of your external exposure signals, common misconfigurations, and credential exposure indicators. It gives leadership a quick, structured view of risk and where to focus first.

Do small businesses really need cybersecurity testing?

Yes. Small and mid-sized businesses are frequently targeted because their security resources are limited. Structured offensive testing identifies and prioritizes risk before it becomes an incident.

Do you work with companies that don't have dedicated security staff?

Yes. Summit Cyber Group is built for SMBs with limited IT and security staffing. We deliver structured, prioritized work your team can act on without adding a full-time security hire.

Is your penetration testing automated or done by people?

Both, depending on what each client needs. Every Summit penetration test is scoped, run, and validated by a human pentester on our team. Where it helps, we also use SimpleSec, our own AI-orchestrated platform, to handle reconnaissance and enumeration at scale — so our testers spend their time on exploitation and on chaining vulnerabilities together the way real attackers do. Clients who subscribe to SimpleSec can also run automated, AI-orchestrated tests on demand, which our team can review and certify.

Who will I actually work with?

You work directly with the security professional performing the engagement — no subcontractors, no account managers, and no third-party markup.

Where is Summit Cyber Group based?

Summit Cyber Group, LLC is a US-based cybersecurity firm headquartered in Colorado, with penetration testers in other states across the US. You work directly with the security professional performing your engagement — no subcontractors, no account managers, and no third-party markup.

Who founded Summit Cyber Group?

Summit Cyber Group, LLC was founded in 2025 by co-founders Tricia Bohm and Rick Bohm. The company is headquartered in Colorado and is not affiliated with Summit Cyber Group of Perth, Australia.

What certifications does the Summit Cyber Group team hold?

Summit Cyber Group's vCISO and penetration testing team holds CISSP, CCISO, OSCP, CPTS, CRTO, CEH, BSCP, CWES, OSWP, CFCE, and CIAM certifications — covering security leadership (CISSP, CCISO), hands-on penetration testing and red teaming (OSCP, CPTS, CRTO, CEH), web application and wireless testing (BSCP, CWES, OSWP), digital forensics (CFCE), and identity and access management (CIAM).