Enterprise-informed security without enterprise complexity.
Calderstone Security Group helps smaller organizations understand cybersecurity risk, strengthen controls and make realistic improvements.
Why Calderstone
Effective cybersecurity should make a business stronger—not bury it in unnecessary tools, jargon or paperwork. Calderstone combines cybersecurity risk management, identity and access management, cloud security, Microsoft 365 security and compliance practices to identify what matters most and turn findings into practical action.
Practical Focus
Actionable recommendations you can actually implement.
Right-Sized Solutions
Security that fits your organization, not a one-size-fits-all approach.
Microsoft 365 Expertise
Strengthen identity, access, sharing and core Microsoft 365 security settings.
Risk & Compliance
Prepare for security requirements with a clear, prioritized roadmap.

Conrad Fongoh
Calderstone Security Group was founded by Conrad Fongoh, a cybersecurity and IT professional with more than a decade of experience across information technology, cybersecurity risk, compliance, identity and access management, and cloud environments.
His professional experience includes supporting cybersecurity and compliance initiatives involving NIST SP 800-53, FedRAMP, FISMA, ISO 27001, SOC, PCI and HIPAA-related security requirements. His background includes risk assessments, security policy development, vendor risk, vulnerability management, cloud security, IAM/ICAM and security-focused infrastructure deployments.
His technical experience spans environments and tools including AWS, Microsoft Azure, Microsoft 365, ServiceNow, Splunk, Tenable/Qualys/Nessus, Terraform and Ansible, along with identity and credentialing deployments supporting federal environments.
Conrad holds a Master of Science in Cybersecurity Management & Policy from the University of Maryland Global Campus (UMGC). His broader academic background includes management and business communications as well as electrical engineering coursework.
Through Calderstone, he brings that experience to organizations that need practical security leadership and stronger controls without building a full internal cybersecurity department.
IT Experience
Cybersecurity Management & Policy
Risk and compliance
Security experience