THANK YOU FOR SUBSCRIBING


Justin Henderson, CEO"We will eventually fall into on-going technical advisory roles which will further improve our core business— providing tailored solutions; not products"
Despite having access to a plethora of security solutions along with a well-informed workforce, companies still struggle to secure their organization from cyber attacks. So what is the missing link here? History shows the answer. Having advanced technologies in place with an army of employees running them does not necessarily translate into “being secure.” It is important to understand three vitals aspects before implementing any security solution— defining the goal, tools, and strategy to achieving it. Unfortunately, it has become a herculean effort for businesses to stay abreast of all the spiraling developments in the security landscape, let alone manage their own organizational processes. Security assurance has become a desperate race against time which no company can afford to lose.
Offering a way for enterprises to reroute around this stressful predicament, H&A Security Solutions, an Effingham, Illinois based security services company, offers tailored, vendor-agnostic services that help their clients meet the needs of the ever-changing cybersecurity landscape.
“We help clients by thoroughly understanding their security goals, setting up their defenses accordingly, training their staff on how to use and maintain it, and ultimately, letting them run it— giving them complete control over their security,” says Justin Henderson, the CEO of H&A Security Solutions.
Consult, Implement, Educate, and Evacuate
Henderson highlights that oftentimes, organizations have all the right resources in place but still struggle to stay on par with the ever-changing business landscape. It isn’t about having the most cutting-edge security technologies or personnel onboard; firms need to understand how to go about to be atop rather than blindly applying “one formula” that works well for the majority. In essence, a technology that might work well for one company need not necessarily fit the bill for others.
Josh Awalt, COO“Everybody wants the best technology, but if that were the case then everybody would be driving a Ferrari! But the point is those aren’t practical,” says Henderson. Unfortunately, many firms cannot even appropriately leverage training programs to make the most of their “latest and greatest” solely because these sessions focus on using a platform rather than implementing it correctly.
Housing a team of GIAC GSEs, SANS instructors and authors, H&A Security Solutions prides itself in offering their clients personalized and vendor agnostic solutions, curated and implemented by “best of breed” security professionals. “This is what we do best! We right size products, tune, and implement them,” says Henderson. He continues, “Above all, we train our clients in a way that they would never again need our services as they would know everything there is about their organization’s security.” Post implementation of their all-round security solutions, H&A also offers services on an ad-hoc basis for those in need as well as to ensure that clients are doing well and staying on the right track.
![]()
We help clients by thoroughly understanding their security goals, setting up their defenses accordingly, training their staff on how to use and maintain it, and ultimately, letting them run it—giving them complete control over their security
Buying a Product vs. Deploying a Solution
Over the years, the enterprise arena has primarily focused on preventive control to the point that organizations have simply gone “blind.” Despite having done regular pen tests, many firms either fail to find the problem in their systems or struggle to resolve it. Why does this happen so often? “People are buying products; not solutions. If you invest heavily in a Security Incident Event Management system (SIEM) and yet have to rely on the vendors to implement and maintain it, there is no point!” Henderson asserts.
For flaw and vulnerability detection, organizations require three fundamental things—“ the right tools, knowing what to look for, and then looking for it, and these need to happen in this order”—which is a huge struggle to achieve.
Initially, every client begins with a quick-start program wherein H&A does a simple onboarding of a SIEM product followed by rapid deployment and training. After this point, H&A lets the client decide what they want to do next as opposed to pushing new products “down their throats” as Henderson mentions. In the event these firms want additional training or want to customize their systems further to integrate it with other products, H&A helps them achieve it.
Vulnerability-Management-as-a-Service
Interestingly, H&A’s services, over time, have paved the way for another independent offering: Vulnerability Management as a Service. In a novel business delivery model, H&A extends a partnership to help organizations that understand their security is in the verge of being compromised but cannot hire people to change it or identify the changes that need to be made. With this alliance, the firm conducts assessments on its clients’ infrastructure on an on-going monthly basis rather than once a year. Not only does this strategy help resolve issues at a faster pace but it also works at a much lower cost when compared to buying one-time professional vulnerability management services.
Henderson states an example wherein, H&A helped a client resolve their security issues and lower their costs, by investing merely 10 hours a month in performing these ongoing assessments. In these working hours, the firm would spend time analyzing data from their partner’s vulnerability management systems and make recommendations on how to fix it. And within no time, even the most complex issues were fixed—all at a much lower price point when compared to annual professional security services from other vendors. Furthermore, for clients that cannot hire staff or do not have enough workforce, H&A offers staff augmentation to ensure that their clients never fall short in any way.
Entering a New Realm—the Cloud
With an impressive clientele and success streak over the years, H&A aims to enter the cloud services domain for SIEM platforms by Q2. “We often noticed that the people invest heavily in cloud-based security systems that cost a lot more than what we offer but carry out the same tasks as our solutions. And in many cases, most of our implementations have even performed better,” says Henderson. The firm envisions offering clients cloud-based services without long contracts, and completely tailored, helping them achieve their goals.
Also, H&A is currently working on scaling their vulnerability-management-as-a-service offering while enhancing all their cyber defense services. “We will eventually fall into on-going technical advisory roles which will further improve our core business— providing tailored solutions; not products,” concludes Henderson.
Company
H&A Security Solutions
Management
Justin Henderson, CEO and Josh Awalt, COO
Description
The firm offers tailored, vendor agnostic, security services that help organizations meet the needs of the ever-changing cyber security landscape