enterprisesecuritymag

Enterprise Security Magazine

H&A Security Solutions
Security Solutions Fostering Self-Sufficiency

Justin Henderson, CEO, H&A Security SolutionsJustin Henderson, CEO
Recently, the hashtag #10YearChallenge took the internet by storm. From Twitter to Instagram to Facebook, millions of users clipped recent photographs of theirs with those taken more or less ten years back. Even though the fad mostly focused on displaying an individual’s personal growth over a period of time, it does inspire a thought of how things were a decade ago and how they are today. Isn’t it something worth pondering on? We have grown exponentially as a society due to rapid advancements in technology. On the hindside, we have also realized that “not all change is good.” In a decade, cyber attacks have evolved to be one of the biggest threats to our society, not to mention the devastating impact it could have on the enterprise-sphere. Now, isn’t that a real challenge? Remember the infamous Adobe and Equifax incidents? While the former fell victim to the theft of nearly 2.9 million user credentials, the latter, to a whopping 143 million. Organizations and end-users alike, such attacks adversely impact all stakeholders and continue to grow more destructive as the days pass—rendering themselves as a constant nightmare for enterprises across industries.

"We will eventually fall into on-going technical advisory roles which will further improve our core business— providing tailored solutions; not products"

Despite having access to a plethora of security solutions along with a well-informed workforce, companies still struggle to secure their organization from cyber attacks. So what is the missing link here? History shows the answer. Having advanced technologies in place with an army of employees running them does not necessarily translate into “being secure.” It is important to understand three vitals aspects before implementing any security solution— defining the goal, tools, and strategy to achieving it. Unfortunately, it has become a herculean effort for businesses to stay abreast of all the spiraling developments in the security landscape, let alone manage their own organizational processes. Security assurance has become a desperate race against time which no company can afford to lose.

Offering a way for enterprises to reroute around this stressful predicament, H&A Security Solutions, an Effingham, Illinois based security services company, offers tailored, vendor-agnostic services that help their clients meet the needs of the ever-changing cybersecurity landscape.

“We help clients by thoroughly understanding their security goals, setting up their defenses accordingly, training their staff on how to use and maintain it, and ultimately, letting them run it— giving them complete control over their security,” says Justin Henderson, the CEO of H&A Security Solutions.

Consult, Implement, Educate, and Evacuate

Henderson highlights that oftentimes, organizations have all the right resources in place but still struggle to stay on par with the ever-changing business landscape. It isn’t about having the most cutting-edge security technologies or personnel onboard; firms need to understand how to go about to be atop rather than blindly applying “one formula” that works well for the majority. In essence, a technology that might work well for one company need not necessarily fit the bill for others.

Josh Awalt, COO“Everybody wants the best technology, but if that were the case then everybody would be driving a Ferrari! But the point is those aren’t practical,” says Henderson. Unfortunately, many firms cannot even appropriately leverage training programs to make the most of their “latest and greatest” solely because these sessions focus on using a platform rather than implementing it correctly.

Housing a team of GIAC GSEs, SANS instructors and authors, H&A Security Solutions prides itself in offering their clients personalized and vendor agnostic solutions, curated and implemented by “best of breed” security professionals. “This is what we do best! We right size products, tune, and implement them,” says Henderson. He continues, “Above all, we train our clients in a way that they would never again need our services as they would know everything there is about their organization’s security.” Post implementation of their all-round security solutions, H&A also offers services on an ad-hoc basis for those in need as well as to ensure that clients are doing well and staying on the right track.


We help clients by thoroughly understanding their security goals, setting up their defenses accordingly, training their staff on how to use and maintain it, and ultimately, letting them run it—giving them complete control over their security


The company offers a broad range of security services that include Detection & Analytics, Security Assessments, and Team Training. Be it fully-managed services or hybrid management or even a short-term project, the firm ensures that clients have what they need to continue pushing forward towards a secure environment.

Buying a Product vs. Deploying a Solution

Over the years, the enterprise arena has primarily focused on preventive control to the point that organizations have simply gone “blind.” Despite having done regular pen tests, many firms either fail to find the problem in their systems or struggle to resolve it. Why does this happen so often? “People are buying products; not solutions. If you invest heavily in a Security Incident Event Management system (SIEM) and yet have to rely on the vendors to implement and maintain it, there is no point!” Henderson asserts.

For flaw and vulnerability detection, organizations require three fundamental things—“ the right tools, knowing what to look for, and then looking for it, and these need to happen in this order”—which is a huge struggle to achieve.

H&A helps organizations implement full-detection solutions with the flexibility to deploy systems of their choice. Henderson and his team guide clients toward the right platform by explaining to them what type of monitoring they’d need, what data to collect, and ultimately how to put them in use to detect unauthorized activities—keeping in mind their final goal and budget.“ Be it Splunk or an open source Elastic Stack, we get in their environment, implement it, train them how to use and maintain it, and give us the boot,” says Henderson.

Initially, every client begins with a quick-start program wherein H&A does a simple onboarding of a SIEM product followed by rapid deployment and training. After this point, H&A lets the client decide what they want to do next as opposed to pushing new products “down their throats” as Henderson mentions. In the event these firms want additional training or want to customize their systems further to integrate it with other products, H&A helps them achieve it.

Vulnerability-Management-as-a-Service

Interestingly, H&A’s services, over time, have paved the way for another independent offering: Vulnerability Management as a Service. In a novel business delivery model, H&A extends a partnership to help organizations that understand their security is in the verge of being compromised but cannot hire people to change it or identify the changes that need to be made. With this alliance, the firm conducts assessments on its clients’ infrastructure on an on-going monthly basis rather than once a year. Not only does this strategy help resolve issues at a faster pace but it also works at a much lower cost when compared to buying one-time professional vulnerability management services.

Henderson states an example wherein, H&A helped a client resolve their security issues and lower their costs, by investing merely 10 hours a month in performing these ongoing assessments. In these working hours, the firm would spend time analyzing data from their partner’s vulnerability management systems and make recommendations on how to fix it. And within no time, even the most complex issues were fixed—all at a much lower price point when compared to annual professional security services from other vendors. Furthermore, for clients that cannot hire staff or do not have enough workforce, H&A offers staff augmentation to ensure that their clients never fall short in any way.

Entering a New Realm—the Cloud

With an impressive clientele and success streak over the years, H&A aims to enter the cloud services domain for SIEM platforms by Q2. “We often noticed that the people invest heavily in cloud-based security systems that cost a lot more than what we offer but carry out the same tasks as our solutions. And in many cases, most of our implementations have even performed better,” says Henderson. The firm envisions offering clients cloud-based services without long contracts, and completely tailored, helping them achieve their goals.

Also, H&A is currently working on scaling their vulnerability-management-as-a-service offering while enhancing all their cyber defense services. “We will eventually fall into on-going technical advisory roles which will further improve our core business— providing tailored solutions; not products,” concludes Henderson.

- Aaron Pierce
    May 14, 2019

Company
H&A Security Solutions

Headquarters
Effingham, IL

Management
Justin Henderson, CEO and Josh Awalt, COO

Description
The firm offers tailored, vendor agnostic, security services that help organizations meet the needs of the ever-changing cyber security landscape

© 2026 Enterprise Security Magazine. All rights reserved. Headquartered in Fort Lauderdale, FL, USA.