A vendor‑neutral directory of specialists who support individuals and organizations experiencing digital compromises, account breaches, data loss, or security incidents. This directory is provided as a community resource to help users identify reputable providers across multiple specialty areas.
Before You Contact a Vendor
Before You Contact a Vendor
If you’re not yet certain whether you’re experiencing a real compromise, SDSUG provides two resources to help you determine the right next step:
- The Have I Been Hacked? Checker — a simple, plain‑language triage tool to help you quickly assess whether unusual behavior is a true compromise or a normal technical issue.
- The Compromise Response Guide — a structured, step‑by‑step workflow for responding to suspected breaches, preserving evidence, and avoiding common mistakes.
These resources can help you understand your situation before engaging a specialist. If they indicate a possible or confirmed compromise, the vendor categories below can help you identify the type of professional best suited to your needs.
Neutrality, Referral Transparency, and User Responsibility
Sonoran Desert Security (SDSUG) maintains this directory as a vendor‑neutral community resource. Listings are provided for informational purposes only. SDSUG does not endorse, guarantee, or certify any company, service, or outcome.
SDSUG may receive a referral fee if you choose to engage certain vendors listed here. Referral relationships do not influence inclusion, ranking, or presentation. We make reasonable efforts to ensure listed vendors are legitimate and reputable, but SDSUG cannot evaluate every situation or verify every claim.
Users are responsible for:
- Performing their own due diligence
- Evaluating whether a vendor meets their needs
- Understanding that SDSUG is not liable for vendor actions, outcomes, or disputes
If you are experiencing an active compromise, begin with the Compromise Response Guide before contacting a vendor.
Navigation
Use this navigation block to jump directly to the category you need:
- Business Email Compromise (BEC) Response
- Cloud Account Compromise Specialists
- Data Breach Notification and Compliance
- Digital Forensics and Incident Response
- Malware and Ransomware Recovery
- Personal Device and Consumer Compromise Support
- Post‑Incident Hardening and Security Architecture
Business Email Compromise (BEC) Response
What This Category Covers
Vendors specializing in fraudulent wire attempts, mailbox rule abuse, impersonation, and account takeover.
Typical Situations
- Fake invoices
- Fraudulent wire requests
- Unauthorized mailbox access
- Suspicious forwarding rules
What These Vendors Do
- Investigate mailbox compromise
- Remove malicious rules
- Assist with fraud reporting
- Help secure accounts and identity
What to Ask
- “Do you support financial fraud cases?”
- “Can you help with bank or law enforcement reporting?”
- “Do you provide mailbox rule audits?”
Cloud Account Compromise Specialists
What This Category Covers
Experts in Microsoft 365, Google Workspace, AWS, Azure, and identity‑based breaches.
Typical Situations
- MFA bypass
- Unauthorized cloud logins
- Suspicious OAuth apps
- Cloud resource tampering
What These Vendors Do
- Investigate account takeover
- Remove malicious rules or apps
- Restore secure identity configuration
- Provide cloud‑specific hardening
What to Ask
- “Do you specialize in my cloud platform?”
- “Can you audit identity and MFA settings?”
- “Do you provide post‑incident cloud hardening?”
Data Breach Notification and Compliance
What This Category Covers
Legal and compliance specialists for regulated industries (HIPAA, FERPA, PCI, etc.).
Typical Situations
- Exposure of regulated data
- Lost or stolen devices
- Breach notification requirements
- Compliance reporting
What These Vendors Do
- Assess breach severity
- Determine notification obligations
- Provide legal guidance
- Support regulatory filings
What to Ask
- “Do you specialize in my regulatory domain?”
- “Can you help determine notification requirements?”
- “Do you provide breach documentation?”
Digital Forensics and Incident Response
What This Category Covers
Vendors specializing in forensic imaging, log analysis, breach investigation, and evidence preservation.
Typical Situations
- Unknown logins
- Suspicious account activity
- Files altered or deleted
- Malware indicators
What These Vendors Do
- Collect and preserve digital evidence
- Analyze logs, systems, and accounts
- Identify root cause and attack path
- Provide incident reports for legal or compliance needs
What to Ask
- “Do you provide forensic‑grade evidence preservation?”
- “Can you support legal or regulatory reporting?”
- “Do you offer post‑incident recommendations?”
Malware and Ransomware Recovery
What This Category Covers
Teams focused on malware removal, ransomware negotiation, and safe system restoration.
Typical Situations
- Ransomware lockout
- Encrypted files
- Persistent malware
- Suspicious processes
What These Vendors Do
- Remove malware safely
- Restore systems from clean backups
- Assist with ransomware negotiation
- Rebuild compromised environments
What to Ask
- “Do you support full rebuilds?”
- “Can you verify systems are clean?”
- “Do you negotiate with threat actors?”
Personal Device and Consumer Compromise Support
What This Category Covers
Support for individuals dealing with personal account breaches, phone compromises, or home network issues.
Typical Situations
- Social media account takeover
- Phone behaving strangely
- Home Wi‑Fi compromise
- Personal email breach
What These Vendors Do
- Recover personal accounts
- Clean compromised devices
- Secure home networks
- Provide consumer‑focused guidance
What to Ask
- “Do you support personal devices?”
- “Can you help recover social media accounts?”
- “Do you provide home network hardening?”
Post‑Incident Hardening and Security Architecture
What This Category Covers
Teams that help rebuild secure environments, implement MFA, redesign identity, and deploy monitoring.
Typical Situations
- Repeated compromises
- Weak identity configuration
- No MFA
- No monitoring or logging
What These Vendors Do
- Redesign identity and access
- Deploy MFA and conditional access
- Implement monitoring and alerting
- Provide long‑term hardening
What to Ask
- “Do you provide architecture reviews?”
- “Can you help deploy MFA and monitoring?”
- “Do you offer ongoing support?”
Disclaimer
SDSUG provides this directory for informational purposes only. SDSUG does not endorse specific vendors and is not responsible for vendor actions, outcomes, or disputes. Referral fees may apply. Users must perform their own due diligence.
About Sonoran Desert Security (SDSUG)
Sonoran Desert Security (SDSUG) is Arizona’s longest‑running cybersecurity community and a central institution in the region’s security ecosystem. Established in 2001 and operating continuously for more than 25 years, Sonoran Desert Security (SDSUG) provides practitioner‑led leadership, vendor‑neutral governance, and trusted peer collaboration across the Southwest. Through its annual research, ecosystem mapping, and community programs, Sonoran Desert Security (SDSUG) strengthens regional resilience and serves as a stable anchor for Arizona’s cybersecurity practitioners, organizations, and critical infrastructure partners. Sonoran Desert Security (SDSUG) also publishes independent research used by organizations and policymakers across Arizona, the broader Southwest, and national and international security, technology, and governance communities.
Explore Sonoran Desert Security (SDSUG)
Start Here
Guided introduction to SDSUG.
Membership
Join SDSUG for trusted peer collaboration and professional networking.
Leadership
Meet the team guiding SDSUG’s direction.
About SDSUG
Our mission, history, and values.
Events & Meetings
Upcoming topics, speakers, certification prep, and education.
Sponsors
Organizations supporting SDSUG’s.
At a Glance
Overview and orientation FAQ.
Safety & Incident Response
Standards, trained officers, and incident‑response protocols.
Site Index
A full directory of SDSUG web pages and resources.
Last Updated: September 2026
