Continuum Improvement now offers cybersecurity, information security, and AI-governance consulting — led by Richard Phung, a veteran security leader and virtual CISO with 20+ years across higher education, healthcare, and enterprise IT.
Book a consultation All servicesGood security isn't a product you buy — it's a program you build: the policies, controls, monitoring, and habits that protect your data, your customers, and your ability to operate. Most organizations know they need it but don't have a full-time security executive to lead the way.
That's where we come in. From a fractional virtual CISO who sets your strategy, to hands-on work standing up monitoring, incident response, and compliance, we meet you where you are and mature your security posture at a pace that fits your size and risk — including responsible governance of the AI tools your team is starting to adopt.
Fractional, executive-level security leadership — strategy, roadmap, risk management, and board-ready reporting without a full-time hire.
Policies, procedures, and a risk-management program that fits your organization and stands up to customer and auditor scrutiny.
Readiness and gap assessments across NIST 800-53, NIST 800-171, HIPAA, and information security aligned to ISO/IEC 27001.
SIEM/SOC design and tuning (Splunk, Google Security Operations), monitoring, and incident-response and BCDR planning.
Phishing simulation and human-focused training that turns your staff into your strongest layer of defense.
Responsible-AI assessments aligned to the NIST AI Risk Management Framework, so you can adopt AI with the right guardrails.
Richard is a career technologist, security leader, and educator with more than two decades protecting organizations across higher education, healthcare, and enterprise IT. He has served as a virtual CISO and information security officer, built and run security operations teams, and led SIEM, incident response, and compliance programs for institutions and businesses alike.
He is an active member of ISC2 and the IAPP, works fluently across NIST frameworks (800-53, 800-171, and the AI RMF) and HIPAA, and founded AI-governance venture q52.ai. Explore his work at career.richardphung.com.
A virtual CISO gives your organization executive-level security leadership on a fractional basis — setting strategy, building your security program, managing risk, and guiding compliance — without the cost of a full-time chief information security officer.
We work across NIST 800-53, NIST 800-171, the NIST AI Risk Management Framework, HIPAA, and information-security management aligned to ISO/IEC 27001. We map your current controls to the framework your customers or regulators require.
Yes. We right-size the security program to your size and risk. Many small and mid-sized organizations get the most value from a fractional vCISO engagement rather than a full security hire.
Yes. We run AI-governance and risk assessments aligned to the NIST AI Risk Management Framework, so you can adopt AI tools responsibly with the right policies, controls, and oversight in place.
Bring a seasoned virtual CISO and security team to your organization — without a full-time hire. Continuum Improvement now offers cybersecurity, information security, and AI-governance consulting led by Richard Phung.
Get in touch