The Petronella Team Real Credentials. Real Engineers. Built for Compliance.
Petronella Technology Group, Inc. is a Raleigh, North Carolina cybersecurity, compliance, and managed IT firm founded in 2002. Every engineer is CMMC Registered Practitioner certified. Founder Craig Petronella is a Licensed Digital Forensic Examiner (#604180), MIT-Certified in AI and Blockchain, and the #1 Amazon best-selling author of 14+ cybersecurity books. Twenty-four years on the same street. BBB A+ since 2003. No offshore triage, no nameless ticket queues, no vendor commissions hiding in the bill.
Compliance Is a People Problem Before It Is a Technology Problem
Most cybersecurity buying mistakes start the same way. A vendor sends a slide deck full of acronyms, the buyer agrees to a number that sounds reasonable, and a few months later an incident, an audit, or a contract renewal reveals that the people on the other end of the contract did not actually have the credentials, the chain-of-custody experience, or the accountability footprint to do the work. The technology never changed. The team did. That is why this page leads with names, licenses, and a continuous twenty-four-year presence at the same Raleigh address rather than another acronym list.
Petronella Technology Group, Inc. has been operating since 2002. The firm holds Registered Provider Organization status number 1449 with the Cyber-AB (formerly CMMC-AB), and every full-time engineer is a CMMC Registered Practitioner. The founder is the only person in the State of North Carolina you will encounter on most regulated engagements who simultaneously holds an active Digital Forensic Examiner license (number 604180), a published CMMC-RP credential, a Certified Wireless Network Expert designation, a Cisco CCNA certification, an MIT-Certified AI and Blockchain credential, and a 14-book authorship record on Amazon. None of those credentials operate a SOC by themselves. Together, they describe a team that produces evidence which holds up in front of a CMMC C3PAO, a HIPAA OCR investigator, a cyber insurance carrier, an attorney conducting a 30(b)(6) deposition, or a federal contracting officer who needs to know whether the subcontractor was operating in a documented compliance posture before the breach window opened.
This page introduces the people who actually do the work, the credentials they hold, the methodology they follow, the industries they have built repeatable plays for, and the press and recognition that backs the public story. The first hire we ever make and the last one we ever lose has to pass the same single test: would you be comfortable putting this person in the room with a federal auditor, a court reporter, a CFO, and a board, all on the same day, all asking different questions, and have them speak credibly. If the answer is anything other than yes, the seat stays open.
Craig Petronella - Founder, CEO, and AI Architect
Twenty-plus years of professional cybersecurity work. A 14-book authorship record. A live NC Digital Forensic Examiner license. The full credential roster - real, current, verifiable.
Craig Petronella
Founder . CEO . AI Architect . DFE #604180Craig Petronella founded Petronella Technology Group, Inc. in 2002 with a single working idea - that a small or mid-sized business that handles defense, healthcare, legal, or financial data deserves the same caliber of cybersecurity operation as a Fortune 500 contractor, scaled to fit. What began as a one-person IT consultancy in Raleigh has grown into a full-service AI, cybersecurity, compliance, managed IT, and digital forensics firm serving regulated SMBs across North Carolina and nationally. The firm has held a Better Business Bureau A+ rating continuously since 2003, a 23-year record without a single rating reduction.
Craig brings 30+ years of professional IT experience and 20+ years of focused cybersecurity work. He is an NC Licensed Digital Forensic Examiner (license #604180), a CMMC Registered Practitioner, a Cisco Certified Network Associate (CCNA, CSCO13961360), a Certified Wireless Network Expert (CWNE), MIT-Certified in AI and Blockchain, a graduate of MIT Sloan Executive Education in Cybersecurity for Managers, and a Hyperledger Certified blockchain practitioner. He is a court-recognized cybersecurity expert witness who has supported attorneys, insurance carriers, and law enforcement on cryptocurrency fraud, SIM swap, ransomware, business email compromise, and cybercrime matters where chain-of-custody, evidence preservation, and qualified testimony decide the outcome.
Craig is an Amazon #1 best-selling author of 14+ cybersecurity books covering ransomware, HIPAA, AI security, blockchain, social engineering, and crypto fraud. He hosts the Encrypted Ambition podcast with more than 95 episodes published. He serves as Contributing Editor for Cybersecurity at the NC Triangle Attorney at Law Magazine and is a regular guest lecturer at the NCCU School of Law. He has been featured as a cybersecurity expert on NBC, ABC, CBS, FOX, WRAL, and Time Warner Cable News, and has delivered 200+ keynote engagements to professional audiences ranging from bar association chapters to defense contractor consortia to medical practice management groups.
Under Craig's leadership, Petronella Technology Group operates an enterprise private AI cluster sourced through the NVIDIA Elite Partner Channel, enabling CMMC-aligned and HIPAA-aligned AI workloads for clients with data sovereignty and regulatory constraints. The firm has built a vertical specialization across defense contracting, healthcare, legal practice, financial services, manufacturing, engineering firms, and real estate brokerages - in each case translating the buyer's compliance framework, threat model, and operational reality into a documented program that holds up to audit.
- CMMC-RP
- CCNA #CSCO13961360
- CWNE
- NC DFE #604180
- MIT-Certified AI & Blockchain
- MIT Sloan Cyber for Managers
- Hyperledger Certified
- CompTIA Security+
- Cybersecurity Expert Witness
- Amazon #1 Best-Selling Author x 14
- 200+ Keynote Speaker
The Engineers and Security Practitioners Behind Every Engagement
Every full-time engineer at Petronella Technology Group is a CMMC Registered Practitioner. Several hold additional credentials in security, infrastructure, virtualization, and compliance. Below are the senior team members named on most engagements.
Blake Rea
CMMC-RP . Sr. Security & Infra EngineerBlake leads cybersecurity engineering and DevOps work across client environments. He owns endpoint security baselining, vulnerability management cycles, and the infrastructure-as-code patterns the firm uses to deliver consistent, audit-friendly deployments. A CMMC Registered Practitioner, Blake brings specialized experience aligning cybersecurity and DevOps workflows to NIST 800-171 and CMMC Level 2 evidence requirements.
Justin Summers
CMMC-RP . Technical Support ManagerJustin runs client support and user success. Every Petronella ticket route - email, phone, portal - ultimately funnels through a documented escalation tier that Justin owns. He coordinates with the engineering bench for complex incidents, maintains service-level commitments, and is the named point of contact for most active managed-IT clients across the Raleigh metro. CMMC-RP credentialed.
Jonathan Wood
CMMC-RP . Infra & Systems EngineerJonathan designs and runs the backend systems that support high-performance AI workloads and managed IT environments. His focus is operational reliability under load - server architecture, container orchestration, security hardening, hybrid cloud and on-premises topology, and the documented runbooks that turn 02:00 incidents into 30-minute outcomes. CMMC-RP credentialed.
Scott Hendrix
Sr. AI Engineer . Integration LeadScott designs and ships the enterprise AI systems that unify client data, workflows, and customer-experience surfaces. He leads agent logic, API design, data orchestration, and the integration patterns that connect AI workloads to CRM systems, legacy applications, telephony, and marketing automation - all of it produced inside the documented security envelope a regulated client requires.
James Grice
Sr. Infrastructure EngineerJames brings 20+ years of hands-on experience with servers, storage, workstations, virtualization, and networking. He holds CJIS, VMware, Microsoft, and Arcserve certifications, which together cover most of the on-premises and hybrid environments Petronella clients run. James is the engineer most often named on data-migration, virtualization, and disaster-recovery work.
Petronella SOC Bench
CMMC-RP . 24/7 Detection & ResponseBehind the named engineers, the Petronella SOC bench runs the 24/7 detection-and-response work backing the Managed XDR and incident response services. Every analyst on the bench is CMMC-RP credentialed, NC based, and operates under documented chain-of-custody when an engagement crosses into digital forensics territory. No offshore triage farm.
Petronella vs Generic MSP vs DIY Internal Build
Three different buying patterns, three different audit outcomes, three different bills. The decision is rarely about a feature list. It is about which team produces evidence that holds up when the contract, the regulator, or the cyber insurance carrier comes asking.
Discovery, Roadmap, Operate
Every Petronella engagement collapses to three operational stages. The deliverables, the named owner, and the success criteria are defined before any invoice is sent. No open-ended hours, no scope creep masquerading as urgency, no surprises on the second invoice.
Discovery
A 15-minute discovery call, free of charge, with a credentialed engineer rather than a sales rep. We map the buyer's regulatory framework (CMMC level, HIPAA covered-entity status, PCI level, SOC 2 scope), the headcount, the endpoint and identity footprint, and the immediate event driving the conversation - upcoming audit, lost contract, breach, insurance renewal, growth event. The output is a written discovery summary and a fixed-fee scoping letter inside three business days.
Roadmap and SOW
A written roadmap that names the controls, the deliverables, the milestones, and the named Petronella engineer accountable for each. The scope of work prices the engagement under a fixed-fee milestone model, with 100% upfront at contract execution. No splits, no hourly-bleed traps, no net-30 ambiguity. The roadmap doubles as the audit-evidence artifact when the time comes.
Operate
Ongoing operate work runs under a retainer model with monthly executive summaries, quarterly tabletop exercises where applicable, and continuous control evidence captured into the audit binder. Optional add-ons include the Managed XDR service for 24/7 detection-and-response, the incident response retainer for pre-paid forensics hours, and the vCISO engagement for executive-level security governance. Boards and audit committees usually start the conversation with our NIST CSF 2.0 Board Roadmap in hand - it is the practical translation from the six CSF functions to the questions directors actually have to sign off on.
Five Operating Principles
Technology changes fast. Our operating principles do not. These have guided every hire, every engagement, and every renewal since 2002.
Real Credentials, No Fabrication
Every credential on this page is verifiable. CMMC-AB RPO #1449 is on the Cyber-AB public marketplace. DFE #604180 is on the NC Private Protective Services Board roster. CCNA #CSCO13961360 is on the Cisco credential verification portal. We do not publish fake client counts, fake satisfaction percentages, fake testimonials, or fake industry awards. Real wins or no win.
Independent of Vendor Commissions
The firm does not run a referral or rebate program with the EDR vendors, the cloud providers, or the hardware OEMs that would distort recommendations. Vendor-agnostic across CrowdStrike, SentinelOne, Microsoft Defender, Sophos, Palo Alto, Fortinet, and others. Recommendations are documented in the engagement letter with the reasoning, not buried in a kickback schedule.
NC Based, Onsite Drive Radius
Headquartered at 5540 Centerview Drive, Suite 200, Raleigh, NC 27606. We perform onsite engagements within driving distance of the Research Triangle and along I-85, I-95, and I-40. That includes Durham, Cary, Apex, Holly Springs, Wake Forest, Burlington, Greensboro, Winston-Salem, Wilmington, Fayetteville, and Charlotte. National engagements run hybrid with documented chain-of-custody.
Twenty-Four-Year Track Record
Founded 2002. Continuously operating from the same Raleigh footprint. BBB A+ continuously since 2003. The firm has worked through the 2008 financial crisis, the COVID disruption, the ransomware era, the cyber insurance hardening, the CMMC framework rollout, and the AI inflection - all without a single change in ownership or a single rating reduction. Continuity is itself a control.
Public Thought Leadership and Authorship
The founder has published 14+ Amazon #1 best-selling cybersecurity books, delivered 200+ keynote engagements, and provided expert commentary on NBC, ABC, CBS, FOX, WRAL, and Time Warner Cable News. Contributing Editor for Cybersecurity at NC Triangle Attorney at Law Magazine. Regular guest lecturer at NCCU School of Law. Public record, public accountability, public results.
Deep Expertise Across Regulated Sectors
The team has built repeatable engagement playbooks for the verticals where compliance, threat profile, and operational reality look different from a generic SMB. Click a card to see the dedicated industry page.
Healthcare
HIPAA Security Rule, OCR audit-readiness, EHR security, ePHI segmentation, medical device network isolation, BAAs.
Defense Contracting
CMMC Level 1, 2, and 3. NIST SP 800-171, DFARS 252.204-7012, CUI scoping, RPO #1449 with C3PAO partner network.
Legal Practice
Attorney-client privilege protection, e-discovery support, ethical walls, NCCU School of Law guest-lectured frameworks.
Financial Services
SOC 2 readiness, PCI DSS, SEC cybersecurity rules, GLBA, NYDFS, encryption, fraud and wire-transfer controls.
Manufacturing
OT/IT convergence security, ICS monitoring, CMMC for DoD manufacturing subcontractors, supply chain risk management.
Engineering Firms
CMMC posture for engineering subcontractors, CAD-environment protection, AI assistant security, IP exfil prevention.
Real Estate
Wire fraud prevention, transaction security, BEC defense for brokerages, escrow workflow hardening, identity controls.
All Industries
See the full Industries hub for additional verticals - education, nonprofit, professional services, retail, government.
How We Hire, How We Train, What We Refuse to Compromise
The first thing every Petronella engineer encounters at hire is a credentialing roadmap. Within 90 days of start, every full-time engineer is expected to obtain or already hold a current CMMC Registered Practitioner credential. Within the first year, the engineer is expected to layer on at least one of CompTIA Security+, Network+, A+, AWS Solutions Architect Associate, Microsoft Azure Administrator, VMware Certified Professional, or Cisco CCNA. Continuing education time, lab time, and vendor-neutral threat research is a budgeted line item, not a personal-time burden. Stagnation is the failure mode this firm spends the most energy preventing. The same internal curriculum that brings new engineers to CMMC-RP standing within 90 days is also packaged as CMMC training for your team - useful for defense contractors who need their own staff up to speed on NIST 800-171 control families ahead of a C3PAO visit.
Background checks are mandatory before the first client touchpoint. Onsite engagements involving classified or controlled environments require additional documentation that is reviewed before access is granted. Every full-time engineer signs an NDA. Every named engineer on a client engagement is documented in the SOW, and substitutions require written client acknowledgement. There is no rotating cast of pseudonymous Tier-1 voices on the phone.
The firm refuses to do certain things that are common in the broader market. We do not subcontract triage to overseas providers. We do not run vendor referral or rebate programs that distort hardware or software recommendations. We do not produce fabricated case studies, fabricated testimonials, fabricated satisfaction percentages, or fabricated industry-award badges to fill out the website. We do not publish AggregateRating schema unless real, verifiable reviews exist for the exact entity being described. We do not claim to be an NVIDIA-authorized reseller - hardware is sourced through the NVIDIA Elite Partner Channel, which is the accurate language. We do not stretch the digital forensics practice into mobile-device extraction (Cellebrite, GrayKey), private-investigator work, or jailbreak workflows. The forensics scope is explicitly bounded to BYOD and corporate-mobile breach response, computer and server imaging, network traffic capture, and cloud-tenant evidence preservation.
This is the discipline that has held an A+ BBB rating continuously since 2003 and the Cyber-AB RPO listing since the CMMC framework launched. It is not glamour. It is consistency.
Public Record, Verifiable Sources
Cybersecurity expert commentary, peer-recognized credentialing, and continuous BBB accreditation. Real, verifiable, public.
Questions Decision-Makers Ask About the Team
Selected from scoping calls with CFOs, general counsel, IT directors, compliance officers, and contracting officers across North Carolina and nationally.
Who is Craig Petronella?
What credentials does the Petronella team hold?
How long has Petronella Technology Group been in business?
What industries does the team specialize in?
Where is the Petronella team based?
Do you offer expert witness and digital forensics services?
Visit, Call, or Schedule
Petronella Technology Group, Inc.
Petronella Technology Group, Inc.5540 Centerview Drive, Suite 200
Raleigh, NC 27606
United States
Phone: (919) 348-4912
Email: info@petronellatech.com
Coverage
Onsite within driving distance of the Research Triangle (Raleigh, Durham, Cary, Apex, Holly Springs, Wake Forest, Chapel Hill, Hillsborough) and along the I-85, I-95, and I-40 corridors (Burlington, Greensboro, Winston-Salem, Wilmington, Fayetteville, Charlotte). Hybrid and remote engagements delivered nationally. CMMC-AB Registered Provider Organization #1449.
Petronella Pillars and Programs
The same credentialed team named above runs each of the pillar programs below. Click through to see scope, methodology, and credentialing per program.
Put a Credentialed Team on Your Compliance Problem
Free 15-minute discovery call with a Petronella engineer. We map the regulatory framework, the headcount, the immediate event driving the conversation, and produce a fixed-fee scoping letter inside three business days.