
Closed
Posted
I am seeking a professional US-Based consultation to evaluate and potentially challenge a significant failure in Information Security governance and Incident Response (IR) at a major R1 university. I am currently navigating a situation involving a persistent, log-evasive intrusion where the institution has leveraged the significant power asymmetry inherent in large bureaucracies to circumvent accountability. I am looking for CISO-level expertise to dismantle a "no record found" defense that was manufactured through intentional administrative delay. **The core pillars of this case include:** * **Failure of Notice:** The institution was provided with explicit, immediate notice of a breach and data loss on 11/27. Despite this "on-notice" status, they remained unresponsive for **150 days**, allowing the forensic window to expire. * **Administrative Misclassification:** Following a formal escalation, the Executive Office misrouted the technical security report to a wellness-focused **"Student Advocacy"** division—a clear departure from NIST SP 800-61 standards. * **Refusal of Forensic Baselines:** The CISO’s office has dismissed high-fidelity technical indicators (including segment hopping and live data purging) and refused to provide a **managed, monitored device** to establish a forensic baseline, relying instead on server-side logs they allowed to age out. I am particularly interested in your help to address the **Administrative Attrition** at play here. The university is currently taking advantage of the time and financial burden required for an individual to procure independent forensic oversight. I require assistance in drafting a formal rebuttal to the University’s General Counsel that frames these failures as **Administrative Spoliation** and a breach of the **Duty of Care.** I have a documented paper trail—including the initial 11/27 notice and the subsequent "Wellness" referral—and would appreciate a brief initial discussion to see if you can provide the expert oversight needed to hold this institution to industry standards.
Project ID: 40372062
9 proposals
Remote project
Active 1 mo ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
9 freelancers are bidding on average $34 USD/hour for this job

With over a decade of experience in high-security systems and incident response, I understand the critical importance of addressing information security governance failures, like the one you're navigating at the major R1 university. Your project goal to challenge the "no record found" defense manufactured through intentional administrative delay aligns perfectly with my background in dismantling complex defense strategies. One strategic insight for addressing this challenge is to focus on establishing a clear forensic baseline through managed, monitored devices to counteract the institution's evasion tactics effectively. In a similar vein, I successfully handled a situation involving scaling a Telegram Mini App to serve over 1 million users, showcasing my ability to manage high-complexity security issues. I encourage you to reach out so we can discuss the roadmap for tackling this intricate situation and strategize on how to handle the administrative attrition present. Let's work together to hold the institution to industry standards and ensure accountability in information security governance.
$40 USD in 15 days
5.4
5.4

Hey, I noticed your project, Consultation for InfoSec Governance Failure and believe I can help. My work in Computer Security has prepared me well for this kind of project. Looking forward to hearing your thoughts.
$25 USD in 7 days
0.0
0.0

Hello, I understand that you are facing a serious issue with a major university's failure in Information Security governance and Incident Response. The main problem involves a delayed and evasive response to a breach notice, administrative misdirection away from proper technical review, and refusal to cooperate on forensic analysis. I can help by reviewing all documented evidence and crafting a strong, clear rebuttal to the university's General Counsel. This rebuttal will highlight the failure in duty of care, administrative spoliation, and refusal to meet industry standards. I will focus on clear, precise language to hold the institution accountable and suggest steps for further escalation if needed. I aim to make this process straightforward and thorough. Can you share the full documentation and any previous communications with the university's IT and legal teams so I can review the details thoroughly before we proceed? Thanks,
$25 USD in 20 days
0.0
0.0

Hi, I can help you assess the incident response timeline and governance breakdown, and translate your documented evidence into a structured, standards-aligned technical and administrative review. My approach focuses on evaluating gaps against frameworks like NIST SP 800-61, clarifying accountability issues, and preparing a clear, professional rebuttal for counsel review. I will organize your paper trail into a coherent narrative supported by technical findings and formal incident-response expectations to strengthen your position. Would you like the output framed strictly as a technical IR report, a legal-facing rebuttal letter, or both combined? I’m available to start immediately and work through the documentation efficiently. Best Regards, Fizza Nadeem K
$38 USD in 40 days
2.1
2.1

Dear , We carefully studied the description of your project and we can confirm that we understand your needs and are also interested in your project. Our team has the necessary resources to start your project as soon as possible and complete it in a very short time. We are 25 years in this business and our technical specialists have strong experience in Computer Security, Technical Writing, Report Writing, Research Writing, Compliance, Risk Management, Paralegal Services, Digital Forensics, Data Protection, Legal Consultation and other technologies relevant to your project. Please, review our profile https://www.freelancer.com/u/tangramua where you can find detailed information about our company, our portfolio, and the client's recent reviews. Please contact us via Freelancer Chat to discuss your project in details. Best regards, Sales department Tangram Canada Inc.
$30 USD in 5 days
0.0
0.0

Tempe, United States
Member since Oct 22, 2015
$15-25 USD / hour
$30-250 USD
$250-750 USD
$30-250 USD
$250-750 USD
$30-250 USD
€12-18 EUR / hour
$250-750 USD
$250-750 USD
$800-900 USD
₹600-1500 INR
₹100-400 INR / hour
$30-250 USD
$10-50 USD
$30-250 USD
₹600-1500 INR
$15-25 USD / hour
min £36 GBP / hour
€8-30 EUR
£20-250 GBP
$750-1500 USD
$30-250 USD