Vendor-neutral guidance, open playbooks, and practical drills for U.S. municipal, utility, and healthcare organizations — built to protect the services communities depend on.
Aligned with federal frameworks
The Challenge
Municipalities, utilities, and healthcare providers operate complex IT/OT environments with limited security budgets, legacy systems, and shrinking staff — making them prime targets.
Most commercial solutions are vendor-driven and too costly. What these organizations need is practical, evidence-based guidance they can act on — not product pitches.
of U.S. municipalities lack dedicated cybersecurity staff
average cost of a healthcare ransomware incident
designates SLTT and healthcare as critical infrastructure
All our playbooks, checklists, and drill kits are free
What We Do
Actionable services aligned with NIST CSF 2.0 functions — built for organizations that need results, not overhead.
Gap analysis against CSF 2.0 and CISA CPGs. MFA coverage, asset inventory, segmentation, KEV patch hygiene — documented and prioritized.
IDENTIFY · PROTECTCross-jurisdiction tabletop exercises, open briefings for CIO/CISO/ops/clinical audiences, and practice labs — virtual or in-person.
RESPOND · RECOVERSecure remote access, network segmentation, logging and alerting for essential services — guidance that works in mixed IT/OT environments.
DETECT · GOVERNOpen License
All playbooks, checklists, and drill kits are openly licensed. Use them, adapt them, share them.
Step-by-step guide aligned with CSF 2.0 and CISA CPGs. Includes municipal, utility, and healthcare add-ons.
MFA, asset inventory, KEV patching, backup validation — one-pager for quick assessment.
Scenario templates, facilitator guides, and after-action report formats. Repeatable across jurisdictions.
About
Citadel Cyber Solutions was founded by a cybersecurity professional whose experience includes municipal-scale infrastructure leadership under active conflict conditions.
That operational background informs every framework and drill kit we produce: built for real-world constraints, not ideal conditions.
readiness uplift target within 12 months of engagement
MFA coverage target for privileged and remote access
All deliverables mapped to NIST CSF 2.0 functions
All public artifacts freely licensed for any jurisdiction
Get in Touch
Whether you need a baseline assessment, a tabletop drill, or just want to talk through your gaps — reach out. First conversation is always free.