Skip to main content

About

A senior-operator security consultancy.

We were built to close the gap between security theater and real, defensible programs.

What we believe

Compliance is a floor, not a ceiling. A program that passes audit but can't survive a real incident isn't a program, it's a liability.

Insurance underwriters, regulators, and enterprise buyers are all asking harder questions. The organizations that win are the ones whose answers are already true.

We staff every engagement with senior operators, no offshore delivery, no juniors learning on your program.

How we work

Small, focused, and independent. Every engagement is scoped tightly and delivered by the same operator who scoped it, no handoffs to a delivery pool.

We prefer relationships over transactions. Most clients start with a single engagement and stay on for the next regulatory or renewal cycle.

Leadership

Founder & Principal Advisor

Joseph Boyd, MBA

Joseph founded InfosecCheck to close a gap he saw across the cybersecurity, compliance and insurance industries: organizations were told what frameworks to adopt before anyone determined which regulations, contracts and insurance obligations actually applied to them.

Joseph has run his own technology and advisory practice since September 2000, when he founded Mainboard Computer Sales and Service as a sole proprietorship. He organized the business as Mainboard, LLC in 2004, and has served as Managing Member ever since. Over more than 25 years, he has conducted over 100 technology, cybersecurity, operational, vendor and business risk reviews, and has developed Written Information Security Programs (WISP), incident response policies and governance documentation for regulated professional-service environments.

Joseph has actively advised regulated clients navigating the FTC Safeguards Rule, the IRS Taxpayer Protection Framework, HIPAA and NIST-aligned regulatory models, working directly with business owners to interpret regulatory obligations and build practical, defensible security programs. Client identities are never disclosed.

Joseph is a licensed Virginia Insurance Consultant, which gives him a rare vantage point most cybersecurity consultants lack: direct, licensed insight into how insurers evaluate risk, underwrite policies and handle claims. He previously held certification as a Virginia Private Investigator, with an ancillary Certified Expert in Cyber Investigations credential from the McAfee Institute, experience that informs his approach to incident documentation, evidence handling and investigative rigor. His academic background includes doctoral-level studies (ABD) in Computer Information Security, comprising five specialty courses in cyber forensics, critical infrastructure protection, information warfare, computer network auditing and advanced risk management in information assurance, an immersion in regulatory models including the NIST Cybersecurity Framework and NIST 800-53 that goes well beyond the scope of a standard certification exam. He also completed CISA-aligned coursework in information systems auditing and governance, holds prior CompTIA Network+ and Security+ credentials, and served as an adjunct instructor in cybersecurity and networking at Southwest Virginia Community College from 2020 to 2023.

This combination, licensed insurance advisory experience, investigative training, direct regulated-client work and more than two decades of hands-on cybersecurity and GRC work, is unusual. Most GRC consultants understand frameworks but not insurance mechanics. Most insurance professionals understand policy language but not technical controls. Joseph works at the point where these worlds meet, which is exactly where audits fail, claims get denied and executives get exposed.

He is based in Virginia and advises clients nationally.

Ready to talk?

Book a 30-minute working session or send us a note. We'll come prepared.