Managed information security services

Right-sized security for your organization.

PVInfoSec helps organizations in Fort Collins and across Northern Colorado build a practical security foundation, reduce operational risk, and make confident decisions without adding unnecessary complexity.

Focus Areas

Focused support where organizations need it most.

Virtual Information Security Officer (vISO) Advisory

Use PVInfoSec for planning sessions, roadmaps, control review, leadership support, vendor decisions, architecture conversations, client or regulatory preparation, and broader security strategy.

Security Foundation

Security awareness program creation, including phishing simulation, reporting on security culture improvement, and user-focused reinforcement that reduces the human risk.

Security Validation

Adversary-informed assessment for external exposure, internal attack paths, Active Directory risk, and audit readiness so organizations can strengthen defense with practical evidence.

Mission

Security that grows with the business.

PVInfoSec helps organizations build information security in practical stages, beginning with Security Foundation and expanding as operations, risk, client expectations, and regulatory needs mature. PVInfoSec provides cybersecurity services for small and medium-sized businesses across Northern Colorado, including Fort Collins, Loveland, Greeley, Windsor, Timnath, Wellington, and surrounding communities.

01

Start with a usable baseline

Establish clear policy expectations, incident readiness, awareness, and phishing preparedness so the business has a security foundation people can actually follow.

02

Enable secure operations

Turn security work into repeatable operating habits that support daily decisions, reduce avoidable risk, and keep teams moving without unnecessary friction.

03

Mature with intent

Add advisory support, control review, roadmaps, and managed security capabilities as the organization is ready for the next tier of protection and visibility.

Managed Information Security Services

A right-sized starting point for organizations that need clear expectations, prepared people, and practical readiness without unnecessary complexity.

Security Validation

Adversary-informed defense that validates exposure, identity risk, and audit readiness with practical remediation guidance.

  • External security assessment for internet-facing systems, exposed services, and perimeter risk
  • Internal security assessment for exposed systems, insecure services, and attack paths
  • Active Directory security review for identity risk, privilege exposure, and misconfigurations
  • Audit readiness review for technical evidence, control gaps, and outside expectations

Founder

Stephan Ruiz

Stephan Ruiz leads PVInfoSec as founder and principal security partner. His experience spans security operations, vulnerability management, incident handling, threat intelligence, cloud and infrastructure security, secure design, security awareness, governance support, and the operational work required to turn security commitments into reliable delivery.

That mix of technical depth and operational realism shapes how PVInfoSec works. The goal is not to flood clients with generic recommendations. It is to help them improve protection, strengthen visibility, meet client and regulatory expectations, and keep security work moving in a way their environment can actually sustain.

PVInfoSec is built for organizations that want practical managed security services and dependable support from someone who understands both the technical details and the business constraints wrapped around them.

Stephan also believes security work is strongest when it stays connected to the community it serves. He regularly volunteers with Good Life Refuge and the Food Bank of Larimer County, supporting local organizations that help people, families, and animals across Northern Colorado.

Stephan Ruiz, founder of PVInfoSec

Contact

Tell PVInfoSec what you need help with

Tell us if you are interested in Security Foundation for policy, incident readiness, security awareness, and phishing simulation support; Security Validation for internal assessment, Active Directory review, or audit readiness; or vISO advisory for broader planning and security strategy.