To make practical cybersecurity accessible to small and growing businesses, helping them operate securely, confidently and resiliently in a digital world.
To help businesses understand their cybersecurity risks and take practical action to protect their people, systems and data through security assessments, risk-focused solutions, security services and education.

Founder & Principal Cybersecurity Consultant
Kenny Vic is a cybersecurity professional with extensive hands-on experience across security operations, security engineering, vulnerability management, identity and access management, privileged access management, data protection, endpoint security, security monitoring and governance, risk and compliance.
His experience includes practical implementation, assessment, auditing and compliance work across security frameworks and programs, including ISO/IEC 27001 and PCI DSS.
Kenny's approach combines technical security experience with practical communication. Through The Cyber Guy, he explains cybersecurity using simple, real-world examples so that business owners, employees and everyday technology users can understand what the risks mean and what they can actually do about them.
Kennyvicops was created to take that practical approach from education into professional cybersecurity services.
Kennyvicops brings practical experience applying security frameworks, controls and compliance requirements to real-world security environments.
“Experience” is used intentionally. It reflects hands-on work with these frameworks — not certifications, and not an implication that Kennyvicops is a certification body.
Technology names listed reflect professional experience with these technologies and do not imply partnership, sponsorship, certification, or endorsement.
Small and growing businesses that need practical cybersecurity guidance, and organizations that need additional cybersecurity expertise alongside an existing IT team.
A structured review of your environment, current security controls, key risks and business priorities — followed by a prioritized set of practical improvements.
Yes. Smaller businesses are frequent targets precisely because attackers assume defenses are lighter. Practical controls make a measurable difference.
Continuously, in some form. The right cadence depends on your environment, exposure and business impact — that's part of what we help define.
MFA is one of the highest-impact, lowest-cost controls a business can put in place. It significantly reduces the risk of stolen passwords becoming full account takeovers.
It means giving each user and system only the access they truly need to do their job — no more. It limits the damage of a compromised account.
Have them, isolate them, protect them from being modified or deleted by attackers, and — critically — test that you can actually restore from them.
The impact depends on your controls: MFA, endpoint protection, monitoring and a clear incident reporting path can turn a click into a contained event instead of a breach.
Regular, practical, relevant training grounded in real-world examples — not a one-off lecture. The goal is a security-aware culture, not a memorized checklist.
Yes. We regularly work alongside internal IT teams and external providers to add security expertise where it's needed.
Yes. Most of our engagements can be delivered remotely, with on-site work when it adds value.