RGC Consulting LLC seal — an eight-point compass star on a navy field within a bronze ring, with an R monogram at center

Boutique IT Risk & Compliance

Boutique IT Risk & Compliance for Professional Services

You. Elevated.

RGC Consulting LLC helps solo and small law firms, CPA practices, and other professional services firms reduce regulatory exposure and financial risk — without the overhead of a full-time IT department.

Our Philosophy

Security Is a Feature. Risk Is the Business Problem.

Most IT providers sell you antivirus and a help desk ticket. We start from a different question: what does a breach, an audit, or a compliance failure actually cost your firm — in fines, malpractice exposure, and client trust? Then we build the controls that close that gap.

RGC Consulting is led by Rob Cook, a CISSP-certified cybersecurity professional with 8 years of enterprise Governance, Risk & Compliance (GRC) experience across complex, highly regulated organizations, and a CRISC-certified risk practitioner focused on translating technical controls into business risk your partners and clients actually understand.

Why It Matters

  • Cyber-insurance carriers now require documented controls
  • State bars increasingly expect written security policies
  • A single breach can mean malpractice exposure, not just downtime
  • Small firms are targeted more, not less — attackers know controls are thin

Who We Work With

Solo & Small Law Firms

2–20 attorney practices handling privileged client data, PII, and financial records that can’t afford a compliance misstep.

CPA & Accounting Firms

Small firms managing tax data and financial records under increasing regulatory and cyber-insurance scrutiny.

Professional Services Firms

Any practice with remote or hybrid administrative staff handling sensitive client information.

How We Help

IT Risk & Compliance Management

Risk assessments, ITGC evaluations, policy development, vendor risk reviews, and audit-ready documentation — aligned to NIST CSF / 800-53 principles, scaled for small firms.

Network & Security Services

Secure remote access, MFA, endpoint protection standards, backup validation, and email security hardening — a strong baseline, not a 24/7 SOC you don’t need.

Controlled-Scope Helpdesk

Ticket-based, remote-only support, scoped in the engagement agreement rather than left open-ended — so both sides know what is covered.

Packages Built for Firms Your Size

Three tiers, scoped to the firm rather than sold from a fixed menu.

Compliance Lite

Annual risk assessment, policy templates, quarterly check-ins.

Secure Firm Package

MFA enforcement, access reviews, backup testing, vendor risk review.

Compliance + IT Managed

Security monitoring oversight, monthly reporting, incident response advisory.

Serving Firms Across the West Coast & Mountain West

California · Washington · Oregon · Nevada · Arizona · Colorado