
Boutique IT Risk & Compliance
Boutique IT Risk & Compliance for Professional Services
You. Elevated.
RGC Consulting LLC helps solo and small law firms, CPA practices, and other professional services firms reduce regulatory exposure and financial risk — without the overhead of a full-time IT department.
Our Philosophy
Security Is a Feature. Risk Is the Business Problem.
Most IT providers sell you antivirus and a help desk ticket. We start from a different question: what does a breach, an audit, or a compliance failure actually cost your firm — in fines, malpractice exposure, and client trust? Then we build the controls that close that gap.
RGC Consulting is led by Rob Cook, a CISSP-certified cybersecurity professional with 8 years of enterprise Governance, Risk & Compliance (GRC) experience across complex, highly regulated organizations, and a CRISC-certified risk practitioner focused on translating technical controls into business risk your partners and clients actually understand.
Why It Matters
- Cyber-insurance carriers now require documented controls
- State bars increasingly expect written security policies
- A single breach can mean malpractice exposure, not just downtime
- Small firms are targeted more, not less — attackers know controls are thin
Who We Work With
Solo & Small Law Firms
2–20 attorney practices handling privileged client data, PII, and financial records that can’t afford a compliance misstep.
CPA & Accounting Firms
Small firms managing tax data and financial records under increasing regulatory and cyber-insurance scrutiny.
Professional Services Firms
Any practice with remote or hybrid administrative staff handling sensitive client information.
How We Help
IT Risk & Compliance Management
Risk assessments, ITGC evaluations, policy development, vendor risk reviews, and audit-ready documentation — aligned to NIST CSF / 800-53 principles, scaled for small firms.
Network & Security Services
Secure remote access, MFA, endpoint protection standards, backup validation, and email security hardening — a strong baseline, not a 24/7 SOC you don’t need.
Controlled-Scope Helpdesk
Ticket-based, remote-only support, scoped in the engagement agreement rather than left open-ended — so both sides know what is covered.
Packages Built for Firms Your Size
Three tiers, scoped to the firm rather than sold from a fixed menu.
Compliance Lite
Annual risk assessment, policy templates, quarterly check-ins.
Secure Firm Package
MFA enforcement, access reviews, backup testing, vendor risk review.
Compliance + IT Managed
Security monitoring oversight, monthly reporting, incident response advisory.
Serving Firms Across the West Coast & Mountain West
California · Washington · Oregon · Nevada · Arizona · Colorado
