Close the Gaps
We turn assessment findings into finished work: a vulnerability management plan, configuration baselines, an asset inventory and the procedures a score of 2 requires, tracked in the State's remediation plan format.
Maryland school systems, counties and towns must meet the State Minimum Cybersecurity Standards and prove it on a schedule. Free programs help you find the gaps. Ingenuus does the work that follows: written procedures, hardened settings, fixes and the evidence to certify.
A maturity score of 2 means a control is done consistently, from written plans and procedures. Most organizations do the work but haven't written it down. That's where we start.
We turn assessment findings into finished work: a vulnerability management plan, configuration baselines, an asset inventory and the procedures a score of 2 requires, tracked in the State's remediation plan format.
Your evidence folder built to DoIT's Local Cybersecurity Assessment Tool: every document gathered, typed, dated and owned, ready for DoIT, MABE or your state ISO.
Monthly checks of your internet-facing systems against CISA's Known Exploited Vulnerabilities catalog, on a 7-day fix standard, with a monthly report and quarterly evidence updates.
For nonprofits, professional offices and small organizations answering an insurer's, client's or funder's security questions. Three documents, written for how you work, in about three weeks.
Certification under SB 601 by June 30, 2027. We work alongside your MABE or state ISO assessment and do the written procedures and evidence it calls for.
Incident reporting, networkMaryland certification and MD-ISAC enrollment, often without a dedicated security team or a state ISO.
Policies and plans for nonprofits and small businesses, and compliance documentation that IT providers can offer their own clients.
Five stages, in order, so you always know where your program stands and what comes next.
Learn your environment, deadlines and funding. Confirm scope and independence.
Score each control against the State minimum and sort the gaps by priority.
Close the gaps: procedures, baselines and fixes, each with an owner and a date.
Build the evidence folder in DoIT's format, ready for review.
Monitor known exploited vulnerabilities and keep evidence current.
Sophia is a U.S. Army veteran who served in Iraq, and has more than 12 years in IT, including owning and leading baseline security configuration and vulnerability management compliance initiatives in financial services: the same kinds of controls Maryland now scores. She also spent 3 years in school-system administration at Alexandria City Public Schools, so she knows how a school district actually runs. She founded Ingenuus, a woman- and veteran-owned business, to bring that hands-on discipline to the public bodies and small organizations that need it most.

Maryland-certified Veteran-Owned Small Business Enterprise (VSBE)
Also a Maryland SBR-certified small business.
Tell us what's due and what you already have. We'll tell you plainly whether we can help, and what it would cost.