RGC Consulting LLC seal

Rob Cook, CISSP, CRISC

RGC Consulting LLC is led by a CISSP-certified cybersecurity professional with 8 years of enterprise Governance, Risk & Compliance (GRC) experience across complex, highly regulated organizations. That background means the frameworks used to protect billion-dollar organizations — NIST CSF, NIST 800-53, structured risk registers, formal control testing — are brought directly to firms with 2 to 20 people.

The CRISC certification is the core of how we work: identifying risk, quantifying it in terms a managing partner or firm administrator can act on, designing the right-sized controls, and monitoring them over time. Small firms don’t need to understand “security” — they need to understand risk and liability. That’s the lens every engagement starts from.

Our Philosophy

Why “Risk-First,” Not “IT-First”

Most IT providers lead with tools: antivirus, firewalls, backups. We lead with the question underneath all of it — what does this actually expose your firm to? A ransomware event isn’t just downtime; for a law firm or CPA practice, it can mean malpractice exposure, breach notification obligations, and lasting client trust damage. We build compliance and security programs around that reality, not around selling licenses.

Credentials

Certifications

  • CISSP — Certified Information Systems Security Professional (ISC2)
  • CRISC — Certified in Risk and Information Systems Control (ISACA)

How We Work

Direct Access, No Account Layer

A managing partner or firm administrator works directly with a CISSP/CRISC-certified advisor — not an account manager relaying questions to a technical team. Scheduling and coverage are agreed per engagement rather than fitted into a general support queue.

Risk First, Right-Sized

Enterprise risk and compliance methods, scaled honestly to a firm of two to twenty people — and never sold beyond what that firm actually needs.