
Proven Security Expertise.
Without the Enterprise Price Tag.
You've outgrown your current cybersecurity posture but you're not ready — or able — to hire a Big Four consulting firm or a full managed security provider.
Or you've got a business to run and don't have time to understand your "cybersecurity posture."
Or you know you're ready to improve your operations with modern artificial intelligence systems integration, but you need some trusted human intelligence to get you started in the right direction and keep your data and operations secure.
You need an experienced and trusted advisor who understands operations technology, the regulatory landscape and how to test and validate a firewall or data diode, AI integration risk and MCP server builds, and the real-world constraints of organizations like yours. That's what we do.
Who We Serve
At Sawtooth Digital Forensics, we are passionate about securing all corners of Cyberspace.
Don't assume that because you aren't a "big player" you aren't a big target. Let us help.

Municipalities and
Local Government
We support municipalites, water districts, law firms and law enforcement agencies, and public works. We can help you identify and prioritize risks and implement positive changes efficiently.

Nonprofits
Are you in health services, social services, or legal aid? Do you have a nonprofit that needs to manage data like business contacts, contracts, and employee/volunteer PII? We can help.

Critical Infrastructure
Small Businesses
Did your IT team inherit an OT environment that now needs to be compliant? Is your priority more about "keeping the lights on" than "patch everything, encrypt everything, reboot every month?" We get it, and we can help.
Advisory Services
IT/OT Security Assessment
We review your current network architecture, operational technology environment, and security controls against established frameworks (NIST CSF, NERC CIP, PCI DSS, HIPAA, etc. where applicable) and sector best practices and give you an honest picture of where you stand and what matters most to fix.
We can help with:
-
NIST CSF, 800-53, 800-82
-
NERC CIP
-
NRC 10 CFR 73.54, NRC RG 5.71
-
IEC 63096
-
PCI DSS, HIPAA, GDPR
Security Architecture & Design
New building? Expanding your network? Dealing with "bring your own device" and hybrid/remote employees? We advise on security-by-design for IT and OT infrastructure, including network segmentation, access control architecture, remote access strategy, and the IT/OT boundary — the zone where most industrial incidents begin.
Staff Training and
Table Top Exercises (TTX)
Custom cybersecurity training for your team and leadership — from awareness fundamentals to ICS-specific threat scenarios. Tabletop exercises help your team practice incident response before an incident happens. This is by far the best return on your investment.
AI Risk and Integration
Deploying AI tools into your operations — from AI-assisted dispatch to predictive maintenance to LLM-based document handling — introduces risks most vendors don't tell you about. We help you evaluate those risks, build appropriate policies, and integrate new capabilities without creating new exposures. Our framework aligns with the NIST AI Risk Management Framework and
emerging sector-specific guidance.
We can help with:
-
NIST AI Risk Management Framework
-
ISO/IEC 42001, 23894
-
EU AI Act
Policy, Governance, and Compliance Readiness
We develop cybersecurity policies, incident response plans, and governance frameworks scaled to your organization's actual size and risk profile. We don't give you a 200-page enterprise ISMS and leave you to implement it alone.
Grant & Funding Readiness
Cybersecurity and AI funding is increasingly available for municipalities and nonprofits through FEMA BRIC, USDA, DHS SLCGP, and sector-specific DOE and EPA programs. We help you assess readiness, structure projects, and position for awards.
What Our Clients Say


