No two organizations face the same cybersecurity and compliance challenges. Optic Cyber brings the clarity, expertise, and vision needed to understand your unique environment and define a path forward that fits the full complexity of your business.
Clarity & Vision for Non-Standard Environments
Every Path Forward Starts with Clarity
Clarity comes first. You can’t move forward until you understand where you are now. By bringing your current state into focus—with all its complexity, unique requirements, and singular challenges—we set the foundation for meaningful progress.
Vision follows understanding. Once you have a clear view of where you are, we help you see where you can go and how to get there, defining an achievable path forward that aligns with your goals and the operational realities of your environment.
Your Challenges Are Unique. So Is Our Approach.
Insight informed by experience
Solutions that fit your reality
Plans that work in practice
Practical execution for every step
Meet your team
Work with experts who helped shape industry standards, understand complex environments, and remain your trusted advisors from start to finish.
Tom Conkle
CEO & Cybersecurity Engineer
Tom Conkle, CISSP, is a cybersecurity engineer with over 20 years of experience helping organizations mature and assess their cybersecurity capabilities. Tom has supported the implementation of industry standards such as the NIST Cybersecurity Framework (CSF), CMMC (NIST SP 800-171), FedRAMP/FISMA (NIST SP 800-53), and ISO 27001. As Lead CMMC Certified Assessor (CCA) and CMMC Credentialed Instructor (CCI), he specializes in guiding organizations through the preparation process for CMMC assessments.
He has also assisted dozens of commercial and governmental organizations in mitigating risks within their cybersecurity programs using the NIST CSF and is the co-author of ISACA’s guide for implementing the NIST Cybersecurity Framework. Additionally, as a principal architect of the CMMI Cybermaturity Platform, he developed a self-assessment SaaS tool that helps organizations create risk-informed cybersecurity programs and track their progress.
Kelly Hood
EVP & Cybersecurity Engineer
Kelly Hood, CISSP, specializes in helping organizations implement cybersecurity and privacy best practices, controls, and standards to effectively manage risks and achieve compliance objectives. Kelly supports the evolution and outreach of the Cybersecurity Framework (CSF) as part of the NIST Cybersecurity Framework team and continues to aid organizations in adopting the Framework to strengthen their cybersecurity posture.
Kelly also supports organizations across industries as a Lead CMMC Certified Assessor (CCA), CMMC Credential Instructor (CCI), and Registered Practitioner (RP) by developing and implementing cybersecurity strategies to help manage the risks to their business. Additionally, Kelly supported the development and expansion of ISACA’s CMMI Cybermaturity Platform (CMMI-CP). The patented approach she helped develop for ISACA translates cybersecurity risk to cybermaturity goals and identifies mitigation strategies to help organizations improve their cybersecurity capabilities.
Kevin Cook
Cybersecurity Engineer
Kevin Cook is a cybersecurity engineer and CMMC Assessor (CCA, CCP, CISSO) who guides organizations seeking certification through CMMC readiness and audits. He leads gap assessments, evidence validation, and scoring against CMMC practices, and builds mediation roadmaps that align policy and procedure with practical technical safeguards. Kevin facilitates multi-day workshops, readiness reviews, and supports C3PAO assessment engagements, with additional experience in SOC 1 attestations and ISO 27001/27002 audits.
A former U.S. Navy nuclear program leader, he is recognized for operational rigor, documentation discipline, and training for high-stakes evolutions, bringing a results-driven approach that helps organizations sustain compliance and strengthen cybersecurity maturity.
Kim Fanto
Cybersecurity Engineer
Kim Fanto is a strategic technology leader and cybersecurity professional specializing in the design and deployment of complex security frameworks. AS a CMMC Certified Professional (CCP), Kim serves as a dedicated partner to organizations within the Defense Industrial Base (DIB), navigating the intricacies of CMMC compliance and NIST-based security requirements. She has succesfully guided numerous organizations through Level 1 attestations, gap readiness, and Level 2 implementation planning, delivering solutions that are as operationally efficient as they are secure.
With a career rooted in technology leadership and architecture, Kim excels at bridging the gap between business objectives and technical execution. As a former Technology Manager and Solutions Architect, she spearheaded enterprise modernization projects that enhanced resiliency and scalability while ensuring alignment with NIST Cybersecurity Framework (CSF), PCI-DSS, and FFIEC standards.
Certifications & Credentials
-
Cyber AB RPOTrusted expertise for organizations preparing for CMMC certification
-
VSBE ProgramVeteran-owned small business serving government and industry in the State of Maryland
-
SBA Veteran-OwnedVeteran-owned small business certified at the federal level
-
GSA Schedule (HACS Qualified)Simplified procurement for federal cybersecurity and compliance services