Request Assessment
Methodical Security Inspection

Find the gaps before the attackers do.

Methodical, assessor-grade penetration testing and vulnerability assessments. We combine a hacker's perspective with an assessor's rigor to secure your perimeter and protect critical assets.

Ethical
Pen Testing
DoD
Vetted Assessor
Gap
Vulnerability Scan
Scope
Boundary Audits
Ethical Hacker
Penetration Tester
Security Auditor
Assessor Vetted
DIB Partner
Vetted Assessment Suitability
๐Ÿ” U.S. Government Vetted
๐Ÿ“‹ DIBCAC Assessment Experience
โš“ U.S. Navy Submariner Veteran
๐Ÿ’ป Assessor-Minded Reporting
Who I Am

The path from 600 feet under the ocean to your perimeter.

I started my career in the weapons department of U.S. Navy Trident submarines. Serving on the Lafayette-class USS Casimir Pulaski (SSBN 633) and the USS Ohio (SSBN 726), I helped maintain Trident C-4 tactical missiles and strategic weapons systems. I was responsible for systems where a single failure didn't generate a ticket โ€” it put 130 lives at risk. From treadmills to nuclear weapons and everything in between, that's where I learned what security actually means. Not as a compliance checkbox, but as an operational discipline that keeps people safe.

U.S. Navy Enlisted Submarine Warfare Insignia (Silver Dolphins)
Submarine Warfare Qualified: Attained through systems walkthroughs and board review

For the next two decades, I took that discipline into enterprise technology across the Seattle area โ€” building, securing, and transforming infrastructure across industries. Then in 2022, I went to the other side of the table.

As a cybersecurity assessor with DCMA/DIBCAC, I've participated in 80+ formal assessments of Defense Industrial Base contractors against NIST SP 800-171A, 800-172, and CMMC. I know the difference between what looks compliant on paper and what survives a formal review.

"PwnInspect is built to think like an attacker and report like an assessor. We inspect your boundaries and identify vulnerabilities before they can be exploited."
What We Offer

Methodical vulnerability inspections.

We simulate real-world attacks to identify security weaknesses in network, application, and cloud boundaries.

Perimeter
External Penetration Testing

Identify vulnerabilities in your external-facing systems, firewalls, and APIs. We test if attackers can breach your initial defenses.

Containment
Internal Vulnerability Audits

Simulate a breached perimeter or rogue insider to evaluate lateral movement potential, access control effectiveness, and domain security.

Execution
Red Team Simulations

Multi-layered simulation attacks designed to evaluate your security operations, detection capability, and incident response under pressure.

Trust
Boundary Verification

Ensure your operational security boundaries and CUI flow systems conform to CMMC and NIST 800-171 scope requirements.

Our Method

The Assessor-Minded audit approach.

We don't just hand you automated scanner logs. We run targeted manual tests and document findings in a format that directly maps to regulatory control objectives.

01
Boundary Mapping & Recon
Determine target scope & inventory

Establish the exact target boundaries. We gather OSINT, map system entry points, and catalog all active hosts and network pathways.

Scope Mapping Reconnaissance System Boundary
02
Vulnerability Analysis
Scan, analyze, and verify findings

Use automated scanners and manual verification tools to locate configuration flaws, weak passwords, and unpatched software across your infrastructure.

Vulnerability Scan Manual Verification Flaw Discovery
03
Exploitation & Pivot
Simulate real attacker operations

Attempt to gain access to systems using identified vulnerabilities. We safely test credential strength, lateral movement, and verify how far an attacker could penetrate.

04
Assessor-Grade Reporting
Practical remediation steps

Deliver a detailed report outlining the path of compromise, business risk level, and specific remediation steps mapped directly to CMMC/NIST control requirements.

The Proof

Vetted credentials and real experience.

PwnInspect maps exploit details to compliance realities. We don't just break in; we tell you exactly what CMMC controls were compromised, helping your team fix them efficiently.

With 20+ years of infrastructure systems experience and active federal assessor vetting, Barry Morgan bridges the gap between offensive testing and compliance auditing. Paper certifications have no bearing on operational quality; true qualification is earned through hands-on practice. We test for real security, not paper checkmarks.

๐Ÿ”
U.S. Government Vetted
Active federal background investigation & suitability
Silver Dolphins Insignia
Submarine Warfare Qualified (SS)
Attained through cross-functional systems walkthroughs and a rigorous evaluation board
FTB MT
U.S. Navy Submariner | Weapons Department
USS Casimir Pulaski (SSBN 633) & USS Ohio (SSBN 726) ยท Trident C-4 systems

Core Competencies

Offensive security
Penetration testing Vulnerability scanning Active exploit verification Red teaming
Verification & Auditing
DIBCAC framework NIST SP 800-172 Scope audit GPO configuration review Remediation roadmaps
Technical Proof
Credential auditing MFA verification Lateral movement checks
The Invitation

Request a Vulnerability Inspection

Let's evaluate your perimeter, test your system boundaries, and identify security weaknesses. Get a professional, assessor-grade report.

Select all areas where you need assessment or auditing support: