Founder
Experience That Connects Cybersecurity, Compliance, and Insurance
Infosec Check was built on more than 25 years of experience across technology, cybersecurity, business operations, and insurance. Joseph Boyd helps business leaders understand the obligations, documentation, training, and decisions that shape an organization's cyber risk posture.
What does Joseph Boyd bring to cybersecurity compliance consulting?
His perspective is informed by firsthand experience with cybersecurity incidents, a major commercial first-party loss involving a bad actor, the insurance claim process, legal proceedings, audits, and identity fraud. That experience shapes how Infosec Check approaches governance, regulatory applicability, documentation, awareness training, and insurance readiness. It informs advisory work only. It does not create a guarantee of coverage, claim payment, legal outcome, or regulatory result.
Perspective
Experience That Changed How I View Risk
A serious problem rarely stays inside one department. It usually crosses several boundaries at the same time.
- Technology and access controls
- Employee actions and awareness
- Business operations
- Documentation and accountability
- Regulatory obligations
- Insurance requirements
- Communications after an incident
That is why Infosec Check looks beyond isolated technical tools and asks whether leadership can demonstrate what was required, what was implemented, who was responsible, and what evidence exists.
When a serious problem reaches the executive desk, experience matters. Preparation matters more.
Firsthand experience
Where the Perspective Came From
Commercial Loss Experience
Joseph Boyd has firsthand experience with a major commercial first-party loss involving a bad actor. That experience informs the importance of preparation, documentation, communication, and understanding the responsibilities that may arise after an incident.
Insurance Claim Experience
Experience with the insurance claim process and related legal proceedings provides practical perspective on why organizations should not wait until a loss occurs to understand their records, controls, responsibilities, and policy-related questions.
Audit Experience
Joseph Boyd has navigated an audit that concluded with no wrongdoing. That experience reinforced the value of organized records, accurate explanations, documented procedures, and the ability to show how decisions were made.
Identity Fraud Experience
Joseph Boyd has also navigated a fraudulent SBA PPP loan filed in his name, despite having done nothing to cause the fraud. That experience deepened his understanding of identity misuse, documentation, escalation, and the burden placed on an innocent person when records are wrong.
These experiences inform Joseph Boyd's professional perspective. They are not presented as guarantees of insurance coverage, claim payment, legal outcomes, or regulatory results.
For leadership
What This Means for Your Organization
A useful cybersecurity program answers practical questions an owner or executive can act on.
- What information must be protected?
- Which laws, regulations, contracts, and insurance requirements may apply?
- Who is responsible for each safeguard and decision?
- What cybersecurity awareness training has actually occurred?
- Can the organization produce evidence of its program?
- What happens when a vendor, employee, account, or system fails?
- What questions should be taken to the IT provider, lawyer, insurance professional, or other specialist?
Infosec Check helps organize the governance and accountability side of these questions. Determining which cybersecurity regulations apply to a business usually comes first, followed by the documentation and evidence that support cyber insurance readiness.
It does not replace legal counsel, an IT provider, an incident response firm, a forensic investigator, or an insurance carrier.
Role clarity
A Governance and Compliance Adviser, Not Your IT Department
Each of these roles is valuable. They are different, and confusing them tends to leave gaps nobody owns.
- An IT provider
- may implement and maintain technology.
- An MSP
- may manage technology and support operations.
- An MSSP
- may monitor and respond to security events.
- A lawyer
- may provide legal advice and legal representation.
- An insurance professional
- may address insurance products, policy questions, and insurance-related matters within the scope of the applicable license and engagement.
- Infosec Check
- focuses on cybersecurity governance, regulatory compliance consulting, documentation, awareness training, executive accountability, risk questions, and coordination with the specialists the organization already uses or may need.
Method
The Infosec Check Approach
- Step 1
Understand the organization, its data, its operations, and its obligations.
- Step 2
Identify gaps in governance, documentation, training, vendor oversight, and accountability.
- Step 3
Build practical priorities that leadership can understand and assign.
- Step 4
Maintain evidence that demonstrates what the organization is doing and why.
Practical starting points include Ante Up cybersecurity awareness training, a review of awareness training requirements by regulation, and, for regulated specialties, the IRS cybersecurity requirements for tax preparers or Virginia's insurance data security requirements. Insurance agencies and their principals often begin with insurance consulting.
Leadership
Founder and Principal Advisor
Joseph Boyd, MBA
Infosec Check is the public brand and a registered fictitious name of MainBoard, LLC in Virginia. Joseph Boyd is the founder and principal associated with Infosec Check, and a Virginia-licensed insurance consultant and insurance producer.
He founded Infosec Check to close a gap he saw across the cybersecurity, compliance and insurance industries: organizations were told what frameworks to adopt before anyone determined which regulations, contracts and insurance obligations actually applied to them.
Joseph has run his own technology and advisory practice since September 2000, when he founded Mainboard Computer Sales and Service as a sole proprietorship. He organized the business as MainBoard, LLC in 2004, and has served as Managing Member ever since. Over more than 25 years, he has conducted numerous technology, cybersecurity, operational, vendor and business-risk reviews, and has developed Written Information Security Programs (WISP), incident response policies and governance documentation for regulated professional-service environments.
He has advised regulated clients navigating the FTC Safeguards Rule, the IRS Taxpayer Protection Framework, HIPAA and NIST-aligned regulatory models, working directly with business owners to interpret regulatory obligations and build practical, defensible security programs. Client identities are never disclosed.
His licensure gives him a vantage point most cybersecurity consultants lack: licensed insight into insurance risk evaluation, policy structure, underwriting representations, and the relationship between documented controls and coverage questions. He previously held certification as a Virginia Private Investigator, with an ancillary Certified Expert in Cyber Investigations credential from the McAfee Institute, experience that informs his approach to incident documentation, evidence handling and investigative rigor. His academic background includes doctoral-level coursework in Computer Information Security, comprising five specialty courses in cyber forensics, critical infrastructure protection, information warfare, computer network auditing and advanced risk management in information assurance, an immersion in regulatory models including the NIST Cybersecurity Framework and NIST 800-53 that goes well beyond the scope of a standard certification exam. He also completed CISA-aligned coursework in information systems auditing and governance, holds prior CompTIA Network+ and Security+ credentials, and served as an adjunct instructor in cybersecurity and networking at Southwest Virginia Community College from 2020 to 2023.
Most governance consultants understand frameworks but not insurance mechanics. Most insurance professionals understand policy language but not technical controls. Joseph works where those worlds meet, which is where regulatory expectations, contract language, insurance representations and executive accountability tend to collide.
This experience applies directly to tax and accounting practices and to cyber insurance claim disputes.
He is based in Virginia and advises clients nationally.
Founder credentials
- Founder and Principal Advisor, Infosec Check
- More than 25 years across technology, business operations, and advisory work
- Doctoral-level coursework in Computer Information Security
- Virginia Insurance Consultant, Property and Casualty
- Former insurance producer and agency operator
- Cybersecurity governance, GRC, WISP, insurance-readiness, and vCISO advisory experience
- Adult instruction across cybersecurity, technology, emergency medicine, CPR, and applied professional subjects
FAQ
Questions Business Leaders Ask
What is Joseph Boyd's role at Infosec Check?
Joseph Boyd is the founder and principal associated with Infosec Check, a registered fictitious name of MainBoard, LLC. He provides cybersecurity governance, regulatory compliance consulting, cyber risk advisory, and cybersecurity awareness training within the scope of the engagement and applicable professional requirements.
Is Infosec Check an MSP or MSSP?
No. Infosec Check does not position itself as the client's IT department, network administrator, managed service provider, or managed security service provider. It works on governance, compliance, documentation, awareness, accountability, and coordination with technical providers.
Does Infosec Check provide legal advice?
No. Infosec Check does not provide legal advice or legal representation. Legal questions should be directed to qualified legal counsel.
Does Infosec Check guarantee that a cyber insurance claim will be paid?
No. No consultant can guarantee coverage or claim payment. Coverage depends on the policy language, facts, conditions, exclusions, representations, duties, and carrier decisions. Infosec Check can help an organization understand preparation and documentation questions within the scope of its engagement, but it does not determine coverage or bind an insurer.
Does Infosec Check replace an organization's IT provider?
No. Infosec Check can work alongside an organization's IT provider, MSP, MSSP, lawyer, insurance professional, and other advisers. The roles should be coordinated rather than confused.
Who is this work for?
The work is intended for business owners, executives, regulated businesses, independent insurance agencies, tax professionals, auto dealerships, and other organizations that need clearer cybersecurity governance, compliance documentation, awareness training, vendor oversight, and accountability.
Talk About Your Organization's Risk
If your organization handles regulated or sensitive information, Infosec Check can help leadership determine what applies, examine what can be proven, and identify what remains unresolved.
A brief conversation can help identify what may apply, what evidence should exist and what deserves a closer examination.
Call Infosec Check
(855) 624-6262
