MEET THE TEAM / CMMC-RP / DFE LICENSED / RALEIGH NC SINCE 2002

The Petronella Team Real Credentials. Real Engineers. Built for Compliance.

Petronella Technology Group, Inc. is a Raleigh, North Carolina cybersecurity, compliance, and managed IT firm founded in 2002. Every engineer is CMMC Registered Practitioner certified. Founder Craig Petronella is a Licensed Digital Forensic Examiner (#604180), MIT-Certified in AI and Blockchain, and the #1 Amazon best-selling author of 14+ cybersecurity books. Twenty-four years on the same street. BBB A+ since 2003. No offshore triage, no nameless ticket queues, no vendor commissions hiding in the bill.

Team online . NC HQ . CMMC-RP across every engineer
#1449CMMC-AB RPO
#604180DFE Licensed
2002Founded Raleigh NC
A+BBB Since 2003

Why the Team Behind the Logo Matters

Compliance Is a People Problem Before It Is a Technology Problem

Most cybersecurity buying mistakes start the same way. A vendor sends a slide deck full of acronyms, the buyer agrees to a number that sounds reasonable, and a few months later an incident, an audit, or a contract renewal reveals that the people on the other end of the contract did not actually have the credentials, the chain-of-custody experience, or the accountability footprint to do the work. The technology never changed. The team did. That is why this page leads with names, licenses, and a continuous twenty-four-year presence at the same Raleigh address rather than another acronym list.

Petronella Technology Group, Inc. has been operating since 2002. The firm holds Registered Provider Organization status number 1449 with the Cyber-AB (formerly CMMC-AB), and every full-time engineer is a CMMC Registered Practitioner. The founder is the only person in the State of North Carolina you will encounter on most regulated engagements who simultaneously holds an active Digital Forensic Examiner license (number 604180), a published CMMC-RP credential, a Certified Wireless Network Expert designation, a Cisco CCNA certification, an MIT-Certified AI and Blockchain credential, and a 14-book authorship record on Amazon. None of those credentials operate a SOC by themselves. Together, they describe a team that produces evidence which holds up in front of a CMMC C3PAO, a HIPAA OCR investigator, a cyber insurance carrier, an attorney conducting a 30(b)(6) deposition, or a federal contracting officer who needs to know whether the subcontractor was operating in a documented compliance posture before the breach window opened.

This page introduces the people who actually do the work, the credentials they hold, the methodology they follow, the industries they have built repeatable plays for, and the press and recognition that backs the public story. The first hire we ever make and the last one we ever lose has to pass the same single test: would you be comfortable putting this person in the room with a federal auditor, a court reporter, a CFO, and a board, all on the same day, all asking different questions, and have them speak credibly. If the answer is anything other than yes, the seat stays open.


Founder

Craig Petronella - Founder, CEO, and AI Architect

Twenty-plus years of professional cybersecurity work. A 14-book authorship record. A live NC Digital Forensic Examiner license. The full credential roster - real, current, verifiable.

Craig Petronella

Founder . CEO . AI Architect . DFE #604180

Craig Petronella founded Petronella Technology Group, Inc. in 2002 with a single working idea - that a small or mid-sized business that handles defense, healthcare, legal, or financial data deserves the same caliber of cybersecurity operation as a Fortune 500 contractor, scaled to fit. What began as a one-person IT consultancy in Raleigh has grown into a full-service AI, cybersecurity, compliance, managed IT, and digital forensics firm serving regulated SMBs across North Carolina and nationally. The firm has held a Better Business Bureau A+ rating continuously since 2003, a 23-year record without a single rating reduction.

Craig brings 30+ years of professional IT experience and 20+ years of focused cybersecurity work. He is an NC Licensed Digital Forensic Examiner (license #604180), a CMMC Registered Practitioner, a Cisco Certified Network Associate (CCNA, CSCO13961360), a Certified Wireless Network Expert (CWNE), MIT-Certified in AI and Blockchain, a graduate of MIT Sloan Executive Education in Cybersecurity for Managers, and a Hyperledger Certified blockchain practitioner. He is a court-recognized cybersecurity expert witness who has supported attorneys, insurance carriers, and law enforcement on cryptocurrency fraud, SIM swap, ransomware, business email compromise, and cybercrime matters where chain-of-custody, evidence preservation, and qualified testimony decide the outcome.

Craig is an Amazon #1 best-selling author of 14+ cybersecurity books covering ransomware, HIPAA, AI security, blockchain, social engineering, and crypto fraud. He hosts the Encrypted Ambition podcast with more than 95 episodes published. He serves as Contributing Editor for Cybersecurity at the NC Triangle Attorney at Law Magazine and is a regular guest lecturer at the NCCU School of Law. He has been featured as a cybersecurity expert on NBC, ABC, CBS, FOX, WRAL, and Time Warner Cable News, and has delivered 200+ keynote engagements to professional audiences ranging from bar association chapters to defense contractor consortia to medical practice management groups.

Under Craig's leadership, Petronella Technology Group operates an enterprise private AI cluster sourced through the NVIDIA Elite Partner Channel, enabling CMMC-aligned and HIPAA-aligned AI workloads for clients with data sovereignty and regulatory constraints. The firm has built a vertical specialization across defense contracting, healthcare, legal practice, financial services, manufacturing, engineering firms, and real estate brokerages - in each case translating the buyer's compliance framework, threat model, and operational reality into a documented program that holds up to audit.

  • CMMC-RP
  • CCNA #CSCO13961360
  • CWNE
  • NC DFE #604180
  • MIT-Certified AI & Blockchain
  • MIT Sloan Cyber for Managers
  • Hyperledger Certified
  • CompTIA Security+
  • Cybersecurity Expert Witness
  • Amazon #1 Best-Selling Author x 14
  • 200+ Keynote Speaker

Selected Books by Craig Petronella

  • How Hackers Can Crush Your Business - foundational SMB cybersecurity playbook, repeat Amazon #1.
  • Cybersecurity for Beginners - executive primer for non-technical decision-makers and board members.
  • Ransomware - prevention, response, ransom-negotiation, recovery sequence and tabletop scripts.
  • Peace of Mind Computing - HIPAA, compliance, and small-practice managed-IT operational guide.

Media, Speaking, and Recognition

  • National TV - cybersecurity expert commentary on NBC, ABC, CBS, FOX, WRAL, Time Warner Cable News.
  • Print and Online - Contributing Editor for Cybersecurity, NC Triangle Attorney at Law Magazine.
  • Academia - regular guest lecturer at NCCU School of Law on cybercrime and digital evidence.
  • Podcast Host - Encrypted Ambition (95+ episodes) interviewing CISOs, founders, regulators.
  • Keynote Speaker - 200+ engagements for bar associations, defense consortia, medical groups.

Senior Team

The Engineers and Security Practitioners Behind Every Engagement

Every full-time engineer at Petronella Technology Group is a CMMC Registered Practitioner. Several hold additional credentials in security, infrastructure, virtualization, and compliance. Below are the senior team members named on most engagements.

Blake Rea, Senior Security and Infrastructure Engineer at Petronella Technology Group

Blake Rea

CMMC-RP . Sr. Security & Infra Engineer

Blake leads cybersecurity engineering and DevOps work across client environments. He owns endpoint security baselining, vulnerability management cycles, and the infrastructure-as-code patterns the firm uses to deliver consistent, audit-friendly deployments. A CMMC Registered Practitioner, Blake brings specialized experience aligning cybersecurity and DevOps workflows to NIST 800-171 and CMMC Level 2 evidence requirements.

CMMC-RP . DevOps . Endpoint Security . Vuln Management
Justin Summers, Technical Support Manager at Petronella Technology Group

Justin Summers

CMMC-RP . Technical Support Manager

Justin runs client support and user success. Every Petronella ticket route - email, phone, portal - ultimately funnels through a documented escalation tier that Justin owns. He coordinates with the engineering bench for complex incidents, maintains service-level commitments, and is the named point of contact for most active managed-IT clients across the Raleigh metro. CMMC-RP credentialed.

CMMC-RP . Client Success . SLA Ownership . Escalation
Jonathan Wood, Infrastructure and Systems Engineer at Petronella Technology Group

Jonathan Wood

CMMC-RP . Infra & Systems Engineer

Jonathan designs and runs the backend systems that support high-performance AI workloads and managed IT environments. His focus is operational reliability under load - server architecture, container orchestration, security hardening, hybrid cloud and on-premises topology, and the documented runbooks that turn 02:00 incidents into 30-minute outcomes. CMMC-RP credentialed.

CMMC-RP . Server Arch . Containers . Hardening . Reliability
Scott Hendrix, Senior AI Engineer at Petronella Technology Group

Scott Hendrix

Sr. AI Engineer . Integration Lead

Scott designs and ships the enterprise AI systems that unify client data, workflows, and customer-experience surfaces. He leads agent logic, API design, data orchestration, and the integration patterns that connect AI workloads to CRM systems, legacy applications, telephony, and marketing automation - all of it produced inside the documented security envelope a regulated client requires.

AI Engineering . Agents . APIs . Data Orchestration
James Grice, Senior Infrastructure Engineer at Petronella Technology Group

James Grice

Sr. Infrastructure Engineer

James brings 20+ years of hands-on experience with servers, storage, workstations, virtualization, and networking. He holds CJIS, VMware, Microsoft, and Arcserve certifications, which together cover most of the on-premises and hybrid environments Petronella clients run. James is the engineer most often named on data-migration, virtualization, and disaster-recovery work.

CJIS . VMware . Microsoft . Arcserve . 20+ Years

Petronella SOC Bench

CMMC-RP . 24/7 Detection & Response

Behind the named engineers, the Petronella SOC bench runs the 24/7 detection-and-response work backing the Managed XDR and incident response services. Every analyst on the bench is CMMC-RP credentialed, NC based, and operates under documented chain-of-custody when an engagement crosses into digital forensics territory. No offshore triage farm.

CMMC-RP . MTTR < 15 min . Chain-of-Custody

Why Hire Petronella

Petronella vs Generic MSP vs DIY Internal Build

Three different buying patterns, three different audit outcomes, three different bills. The decision is rarely about a feature list. It is about which team produces evidence that holds up when the contract, the regulator, or the cyber insurance carrier comes asking.

Dimension
Generic MSP
DIY Internal Build
Petronella
Credentialing depth
Marketing lists vendor logos. Few or no audited individual credentials behind them.
Depends on whoever the internal IT manager happened to hire. Often non-portable.
Every engineer CMMC-RP. CCNA / CWNE / DFE / MIT-Certified on the founder.
CMMC-AB RPO status
Rarely. "We help with CMMC" without the RPO listing on the Cyber-AB marketplace.
N/A. Internal teams cannot register as an RPO for their own work.
Yes. Cyber-AB RPO #1449. Verifiable on the public marketplace.
Named DFE license
No. Forensics gets subcontracted to a third party with separate engagement letter.
No. Forensics work cannot be self-performed when chain-of-custody matters.
Yes. NC DFE license #604180 on the founder. Court-recognized expert witness.
Twenty-four-year track record
Median MSP age in the market is under 10 years. Many under 5.
N/A. Hiring cycle dominates institutional knowledge.
2002 founding. BBB A+ continuously since 2003. Same Raleigh address.
NC-based, onsite within driving distance
Often. Some are pure-remote nationals with no local presence.
Yes, but limited to internal HQ footprint.
Yes. Raleigh HQ. Onsite to Durham, Cary, Apex, Wake Forest, Burlington, Wilmington, Charlotte.
Vertical specialization
"Industry agnostic." Buyer translates compliance to the MSP, not the other way around.
Strong inside one vertical. Brittle outside it.
Defense, healthcare, legal, finance, manufacturing, engineering, real estate - documented per-vertical plays.
Authored cybersecurity books and public thought leadership
Blog content. Rarely peer-published, rarely on national TV.
N/A. Internal teams are not in the public record.
14+ Amazon #1 best-sellers. NBC / ABC / CBS / FOX / WRAL. 200+ keynotes.
Private AI cluster, 24/7 SOC, court-admissible forensics under one firm
Usually three vendors. Three contracts. Three places the ball can drop.
Almost never economical to build all three internally below $50M revenue.
All three under one firm, one phone number, one accountable named partner.

Engagement Methodology

Discovery, Roadmap, Operate

Every Petronella engagement collapses to three operational stages. The deliverables, the named owner, and the success criteria are defined before any invoice is sent. No open-ended hours, no scope creep masquerading as urgency, no surprises on the second invoice.

Stage One . Free

Discovery

A 15-minute discovery call, free of charge, with a credentialed engineer rather than a sales rep. We map the buyer's regulatory framework (CMMC level, HIPAA covered-entity status, PCI level, SOC 2 scope), the headcount, the endpoint and identity footprint, and the immediate event driving the conversation - upcoming audit, lost contract, breach, insurance renewal, growth event. The output is a written discovery summary and a fixed-fee scoping letter inside three business days.

Stage Two . Fixed Fee

Roadmap and SOW

A written roadmap that names the controls, the deliverables, the milestones, and the named Petronella engineer accountable for each. The scope of work prices the engagement under a fixed-fee milestone model, with 100% upfront at contract execution. No splits, no hourly-bleed traps, no net-30 ambiguity. The roadmap doubles as the audit-evidence artifact when the time comes.

Stage Three . Retainer

Operate

Ongoing operate work runs under a retainer model with monthly executive summaries, quarterly tabletop exercises where applicable, and continuous control evidence captured into the audit binder. Optional add-ons include the Managed XDR service for 24/7 detection-and-response, the incident response retainer for pre-paid forensics hours, and the vCISO engagement for executive-level security governance. Boards and audit committees usually start the conversation with our NIST CSF 2.0 Board Roadmap in hand - it is the practical translation from the six CSF functions to the questions directors actually have to sign off on.


What Drives the Team

Five Operating Principles

Technology changes fast. Our operating principles do not. These have guided every hire, every engagement, and every renewal since 2002.

Principle 01

Real Credentials, No Fabrication

Every credential on this page is verifiable. CMMC-AB RPO #1449 is on the Cyber-AB public marketplace. DFE #604180 is on the NC Private Protective Services Board roster. CCNA #CSCO13961360 is on the Cisco credential verification portal. We do not publish fake client counts, fake satisfaction percentages, fake testimonials, or fake industry awards. Real wins or no win.

Principle 02

Independent of Vendor Commissions

The firm does not run a referral or rebate program with the EDR vendors, the cloud providers, or the hardware OEMs that would distort recommendations. Vendor-agnostic across CrowdStrike, SentinelOne, Microsoft Defender, Sophos, Palo Alto, Fortinet, and others. Recommendations are documented in the engagement letter with the reasoning, not buried in a kickback schedule.

Principle 03

NC Based, Onsite Drive Radius

Headquartered at 5540 Centerview Drive, Suite 200, Raleigh, NC 27606. We perform onsite engagements within driving distance of the Research Triangle and along I-85, I-95, and I-40. That includes Durham, Cary, Apex, Holly Springs, Wake Forest, Burlington, Greensboro, Winston-Salem, Wilmington, Fayetteville, and Charlotte. National engagements run hybrid with documented chain-of-custody.

Principle 04

Twenty-Four-Year Track Record

Founded 2002. Continuously operating from the same Raleigh footprint. BBB A+ continuously since 2003. The firm has worked through the 2008 financial crisis, the COVID disruption, the ransomware era, the cyber insurance hardening, the CMMC framework rollout, and the AI inflection - all without a single change in ownership or a single rating reduction. Continuity is itself a control.

Principle 05

Public Thought Leadership and Authorship

The founder has published 14+ Amazon #1 best-selling cybersecurity books, delivered 200+ keynote engagements, and provided expert commentary on NBC, ABC, CBS, FOX, WRAL, and Time Warner Cable News. Contributing Editor for Cybersecurity at NC Triangle Attorney at Law Magazine. Regular guest lecturer at NCCU School of Law. Public record, public accountability, public results.



Hiring and Culture

How We Hire, How We Train, What We Refuse to Compromise

The first thing every Petronella engineer encounters at hire is a credentialing roadmap. Within 90 days of start, every full-time engineer is expected to obtain or already hold a current CMMC Registered Practitioner credential. Within the first year, the engineer is expected to layer on at least one of CompTIA Security+, Network+, A+, AWS Solutions Architect Associate, Microsoft Azure Administrator, VMware Certified Professional, or Cisco CCNA. Continuing education time, lab time, and vendor-neutral threat research is a budgeted line item, not a personal-time burden. Stagnation is the failure mode this firm spends the most energy preventing. The same internal curriculum that brings new engineers to CMMC-RP standing within 90 days is also packaged as CMMC training for your team - useful for defense contractors who need their own staff up to speed on NIST 800-171 control families ahead of a C3PAO visit.

Background checks are mandatory before the first client touchpoint. Onsite engagements involving classified or controlled environments require additional documentation that is reviewed before access is granted. Every full-time engineer signs an NDA. Every named engineer on a client engagement is documented in the SOW, and substitutions require written client acknowledgement. There is no rotating cast of pseudonymous Tier-1 voices on the phone.

The firm refuses to do certain things that are common in the broader market. We do not subcontract triage to overseas providers. We do not run vendor referral or rebate programs that distort hardware or software recommendations. We do not produce fabricated case studies, fabricated testimonials, fabricated satisfaction percentages, or fabricated industry-award badges to fill out the website. We do not publish AggregateRating schema unless real, verifiable reviews exist for the exact entity being described. We do not claim to be an NVIDIA-authorized reseller - hardware is sourced through the NVIDIA Elite Partner Channel, which is the accurate language. We do not stretch the digital forensics practice into mobile-device extraction (Cellebrite, GrayKey), private-investigator work, or jailbreak workflows. The forensics scope is explicitly bounded to BYOD and corporate-mobile breach response, computer and server imaging, network traffic capture, and cloud-tenant evidence preservation.

This is the discipline that has held an A+ BBB rating continuously since 2003 and the Cyber-AB RPO listing since the CMMC framework launched. It is not glamour. It is consistency.


Press and Recognition

Public Record, Verifiable Sources

Cybersecurity expert commentary, peer-recognized credentialing, and continuous BBB accreditation. Real, verifiable, public.

NBC ABC CBS FOX WRAL Time Warner Cable News NC Triangle Attorney at Law Magazine NCCU School of Law Guest Lecturer BBB A+ Since 2003 Cyber-AB RPO #1449 Amazon #1 Best-Selling Author x 14 Encrypted Ambition Podcast (95+ Eps)

FAQ

Questions Decision-Makers Ask About the Team

Selected from scoping calls with CFOs, general counsel, IT directors, compliance officers, and contracting officers across North Carolina and nationally.

Who is Craig Petronella?
Craig Petronella is the founder and CEO of Petronella Technology Group, Inc., which he started in Raleigh, North Carolina in 2002. He has 30+ years of professional IT experience and 20+ years of focused cybersecurity work. Credentials include CMMC Registered Practitioner (CMMC-RP), Cisco CCNA (CSCO13961360), Certified Wireless Network Expert (CWNE), NC Licensed Digital Forensic Examiner (DFE #604180), MIT-Certified in AI and Blockchain, MIT Sloan Cybersecurity for Managers (Executive Education), and Hyperledger Certified. He is the #1 Amazon best-selling author of 14+ cybersecurity books, a court-recognized cybersecurity expert witness, and a regular media commentator on NBC, ABC, CBS, FOX, and WRAL. See the full founder bio for the unabridged credential roster.
What credentials does the Petronella team hold?
Every full-time engineer is a CMMC Registered Practitioner (CMMC-RP). The firm itself holds Registered Provider Organization (RPO) status #1449 with the Cyber-AB, which is publicly verifiable on the Cyber-AB marketplace. Senior staff Blake Rea, Justin Summers, and Jonathan Wood are each CMMC-RP credentialed. Additional credentials across the team include CompTIA Security+, Network+, A+, VMware (VCP), Microsoft Azure Administrator, Microsoft 365 Administrator, Arcserve, CJIS, and AWS Solutions Architect Associate. The firm partners with CMMC Certified Assessors (CCAs) and C3PAOs through the Cyber-AB marketplace for formal CMMC Level 2 and Level 3 assessments.
How long has Petronella Technology Group been in business?
Petronella Technology Group, Inc. was founded in 2002 in Raleigh, North Carolina. As of 2026 the firm has 24 years of continuous operation. It has held an A+ rating with the Better Business Bureau continuously since 2003, a 23-year unbroken record. The firm has worked through the 2008 financial crisis, the COVID disruption, the ransomware-as-a-service era, the cyber insurance market hardening, the CMMC framework rollout, and the AI inflection - all without a change in ownership.
What industries does the team specialize in?
The team specializes in regulated industries where the cost of a breach is measured in regulatory fines, lost government contracts, and litigation - not just downtime. Primary verticals are defense contracting (CMMC, NIST 800-171, DFARS), healthcare (HIPAA Security Rule, OCR audit-readiness, EHR security), legal practice (attorney-client privilege protection, e-discovery, digital forensics, ethical walls), financial services (SOC 2, PCI DSS, SEC cybersecurity rules), manufacturing (OT/IT convergence, ICS monitoring, CMMC for subcontractors), engineering firms (CMMC posture, CAD environment protection, AI assistant security), and real estate (wire fraud prevention, transaction security).
Where is the Petronella team based?
Petronella Technology Group is headquartered at 5540 Centerview Drive, Suite 200, Raleigh, NC 27606. The team is North Carolina based. Onsite engagement is offered within driving distance of the Research Triangle and along the I-85, I-95, and I-40 corridors, including Durham, Cary, Apex, Holly Springs, Wake Forest, Burlington, Greensboro, Winston-Salem, Wilmington, Fayetteville, and Charlotte. Hybrid and remote engagements are delivered nationally with documented chain-of-custody where regulated data is in scope.
Do you offer expert witness and digital forensics services?
Yes. Founder Craig Petronella is a North Carolina Licensed Digital Forensic Examiner (license #604180) and a court-recognized cybersecurity expert witness. The firm supports attorneys, insurance carriers, and law enforcement on cryptocurrency fraud, SIM swap, ransomware, business email compromise, and cybercrime matters where chain-of-custody, evidence preservation, and qualified testimony decide the outcome. See the digital forensics page for the full scope, including the explicit "What We Do Not Do" exclusions (no Cellebrite or GrayKey mobile extraction, no jailbreak workflows, no PI work).

Office and Coverage

Visit, Call, or Schedule

Petronella Technology Group, Inc.

Petronella Technology Group, Inc.
5540 Centerview Drive, Suite 200
Raleigh, NC 27606
United States

Phone: (919) 348-4912
Email: info@petronellatech.com

Coverage

Onsite within driving distance of the Research Triangle (Raleigh, Durham, Cary, Apex, Holly Springs, Wake Forest, Chapel Hill, Hillsborough) and along the I-85, I-95, and I-40 corridors (Burlington, Greensboro, Winston-Salem, Wilmington, Fayetteville, Charlotte). Hybrid and remote engagements delivered nationally. CMMC-AB Registered Provider Organization #1449.


Where the Team Plugs In

Petronella Pillars and Programs

The same credentialed team named above runs each of the pillar programs below. Click through to see scope, methodology, and credentialing per program.


Put a Credentialed Team on Your Compliance Problem

Free 15-minute discovery call with a Petronella engineer. We map the regulatory framework, the headcount, the immediate event driving the conversation, and produce a fixed-fee scoping letter inside three business days.