About
Who you're actually hiring
I'm Tim Lyons. I started Nubivance because I kept running into organizations that had been sold something complicated when what they needed was someone to sit down, look at what they actually had, and tell them the truth about it.
That's most of what this practice is.
Prefer email or phone? info@nubivance.com or 207-358-0999.
The work behind it
For nearly eight years I worked inside a state transportation agency as a consultant - long enough to own outcomes rather than hand over recommendations and leave.
I rebuilt its vulnerability management program end to end: rebuilt the scanner fleet by hand onto RHEL, stood up the infrastructure to support it, and took coverage from a single monthly compliance scan to daily scanning of every asset. On the intelligent transportation systems side there had been no scanning at all - those are the networks running signals, cameras, and field devices, where you cannot reboot something to test a theory.
I designed and built its infrastructure-as-code foundation, administered its GitHub Enterprise security controls for four years, and integrated cloud security posture management into its AWS environment. I held the only break-glass administrative credentials in those accounts.
I served as a senior escalation point for incident response and as the primary digital forensics analyst. I ran purple team exercises against critical infrastructure and coordinated the external red teams that tested it on schedule. Earlier in my career I did red team work myself, which is where the instinct comes from.
Most of the security stack I ran, I brought in first - identified the gap, evaluated the options, drove the decision, deployed it, and then owned it in production.
Most of that happened without any authority to compel it. As a consultant you cannot order a standard into existence. You have to be right, and then convince people who do not report to you. That turns out to be the same job I do now.
Alongside that I have advised Fortune 500 companies, led projects across borders, built security operations from nothing, and spent a lot of time mentoring engineers who needed a map more than they needed instruction.
The through-line is that I have done the work I am advising on. Not read about it. Done it, in production, with something real on the line.
How Nubivance works
Nubivance is a principal-led practice. When you hire us, you get me - Tim Lyons, CISSP - on every engagement, from the first call through delivery. No account managers, no handoffs to junior staff you never met during the sales process.
When a project needs more hands or a specialty outside my lane - forensics, application security, a compliance framework I don't run daily - I bring in consultants from a vetted network of senior practitioners I've worked with across two decades in this industry. You approve who's on your project. I stay accountable for the work.
That model is deliberate. It means you're never paying enterprise overhead for bench time, and you're never getting whoever happened to be available. Every person who touches your environment is there because the work called for them.
What I believe, so you know whether we'll get along
Security that slows delivery down gets routed around. Controls belong in the architecture, where the secure path is also the fast path. Policy that fights the deadline loses to the deadline every time.
If your infrastructure lives in someone's head, you don't own it. Everything should be written down, versioned, and repeatable - so the practice you hire can eventually leave without taking the knowledge with it.
You should know what something costs before you commit to it. Fixed scope, fixed price, quoted in writing. No meter running.
Handoff is the point. The goal is a team that owns the result, not a consultant who becomes load-bearing.
Credentials
CISSP since 2002 - verify. AWS Partner. Rapid7 Registered Partner.
Nubivance is also a General Member of ARIN, the American Registry for Internet Numbers - the organization that allocates IP address space and autonomous system numbers across North America. We hold a direct IPv6 allocation and our own ASN (AS402598), with RPKI route origin authorizations in place. I cast Nubivance's vote in ARIN elections.
That is an unusual thing for a consulting practice to bother with. It matters because it means the infrastructure advice comes from someone who operates at that layer, not just someone who rents space on top of it. When a conversation turns to routing, addressing, or how traffic actually reaches your systems, it isn't theoretical.
The Rapid7 partnership is not a reseller badge. I ran their platform at depth for five years inside a state agency - vulnerability management across IT and operational technology, detection, and incident response - before there was a partnership. They know what I bring because I was their customer first.
Nubivance Consulting LLC is a Maine S-Corporation, registered with SAM.gov, Maine VSS, New Hampshire DAS, and COMMBUYS, with a distributor relationship through Carahsoft.
Where I am, and what else I do
I live and work in Brownfield, Maine, in the western foothills near the New Hampshire line. Most of the work happens remotely, but for clients in western Maine, the Mount Washington Valley, greater Portland, and the New Hampshire Seacoast, I'll come sit at your table.
I also build and publish OSINTSights, a cybersecurity news and analysis site running on a custom pipeline I wrote myself. It's partly a public service, partly how I stay current, and partly because I like building things.
Most of what I build ends up on GitHub. You can also find me on LinkedIn.
Start a conversation
Describe what's going on in a couple of sentences using the contact form, or email info@nubivance.com or call 207-358-0999 if you prefer. You'll get a straight answer about whether I can help.
Working out what you need? See small business security, cybersecurity for small towns, or the full list of services.