Compliance Training That Doesn't Suck

Practical. Punchy. Sticks.

Your team clicks the wrong link. Prints CUI at Kinko's. Reply-alls the salary spreadsheet. We make training they'll actually watch — and remember.

Three Classes · More Coming

Training your team actually watches.

Don't Be Dave

CMMC / CUI

CMMC L1 / L2 training for the humans who touch federal contract data. Even after the July 2026 Phase 2 suspension, self-assessment stays required — and your team has to defend it.

  • CUI handling for people who aren't security folks
  • DFARS 252.204-7012 obligations in plain English
  • Attestation prep that doesn't put anyone to sleep
  • Canned or custom class fit — you pick after the assessment

Don't Be Karen

Security Awareness

Data-handling training for the humans who send the email, share the drive link, and hit Reply-All at the worst possible moment. Because one $3M mistake is enough.

  • Data classification for non-security teams
  • Email + collaboration tool discipline (before the recall dialog fails you)
  • PII / HR / financial data handling in plain English
  • Insider-risk basics — accident vs malice, both cost the same

Don't Be Donna

AI Compliance · Beta

AI-use training for the humans who paste the customer list into a public chatbot, ship the model card with the risk row still blank, or wave off ISO 42001 as "the AI team's problem." Built to NIST AI RMF and ISO 42001 — beta cohorts help shape the final curriculum.

  • NIST AI RMF + ISO 42001 obligations in plain English
  • Prompt hygiene — what not to paste into a public chatbot
  • Model cards, risk rows, and the documentation auditors actually read
  • Beta cohort pricing — help shape the final curriculum
Free · No Sales Pitch · 30 Minutes

Compliance Readiness Assessment

One call. We figure out where you are, where your framework says you need to be, and whether a canned class or a custom build is the right fit. You walk away with a plan whether you hire us or not.

30 minutes No hard sell Plan you keep Canned or custom fit
Book Your Assessment →
Free · Straight to Inbox

Not ready to talk? Start here.

🎯

CMMC Level 1 Quick Guide

The 17 controls that self-assessment actually cares about. One page. Post-it density.

🤖

AI Governance Readiness Checklist

The NIST AI RMF + ISO 42001 crossover checklist your procurement team will actually read.

Who's Behind This

Alex del Rio — the practitioner customers keep on speed dial.

Most security programs get built by people who have never sat across the table from a customer under real pressure — a breach in progress, a failed audit, a board asking why the last incident happened. Alex has spent three decades on that side of the table.

He is not a vendor pitching a platform. He is not a course marketer selling awareness training by the seat. He is the practitioner CISOs, CTOs, and CIOs hand a problem to when they need judgment, not a slide deck.

Verticals worked, deeply: healthcare and medical systems across Southern California (Scripps, Sharp, Hoag, UCI Health, Rady Children's, Banner, St. Joseph's), biopharma in San Diego, utilities in SoCal, financial institutions, gaming and entertainment, and defense contractors.

Frameworks: HIPAA, PCI-DSS, NERC-CIP, CMMC, NIST (CSF, 800-53, 800-171, 800-81r3, AI RMF), ISO 27001, ISO 42001, SOX, FedRAMP. Frameworks are the language of compliance — the point is a program that would actually survive an incident and actually pass an audit. Alex builds and advises to that standard.

Technical depth: DNS security (offense and defense — ten years of practitioner-level tradecraft demonstrating DNS tunneling exfil through commercial next-gen firewalls in live customer POCs), incident response leadership (malware, business email compromise, cryptocurrency fraud), multi-vendor architecture across AI security, network, cloud (AWS/Azure/GCP), IAM, SIEM/SOAR, XDR, and zero trust.

Teaching is the DNA of SecurityROX. Thirty years of training and mentoring technical people, and almost twenty of those as a seminar leader focused on the human element — the most important aspect of cybersecurity. Former Microsoft Certified Trainer (MCT) and Citrix Certified Instructor (CCI). Presenting complex concepts accessibly has been the core of his professional practice for most of his career, and he has built and led a formal training program for a team of security architects. The classes here — CMMC Level 1, AI compliance, workforce awareness — are built the same way: take the hardest concept, make it the plainest thing in the room, hand the human on the other side something they can use on Monday.

CISSP · since 2005
RSA Conference Presenter
CMMC · HIPAA · NERC-CIP · PCI · NIST · ISO
Fractional vCISO · Field CISO · Advisory

Read the full bio →