The Phishing Checklist You Learned Is Already Obsolete
What a recent unsolicited "executive search" email taught me about where company security awareness training breaks down.
Read Article →Cybersecurity Consulting
RedZoan stress-tests organizations against real-world risk and converts what we find into clear, quantifiable choices for executives. Built on 17 years inside the USAF, NSA, DISA, Mandiant, and Google.
Proven at
Engagements span the agencies that regulate America's financial system (FDIC, OCC, SEC, CFPB, Treasury), federal law enforcement (DOJ, FBI, USMS), energy (INL), public health (NIH), legislative oversight (GAO, House of Representatives), international defense (NATO), major US cities, and research institutions, all with the same depth of expertise now applied to organizations of every size.
Services
RedZoan is launching with one focused service: tabletop exercise design, facilitation, and executive reporting. More are coming. If you have a specific need outside this scope, get in touch. There's a good chance we can help, or point you to someone who can.
Tabletop Exercise (TTX) Engagements
A tabletop exercise translates abstract risk into observable behavior. We walk your team through a realistic scenario, document where decisions stall and information breaks down, and hand leadership a clear picture of what to fix and in what order. The cost of failure becomes a lesson, not a breach.
We've run this work for Google's most critical systems, federal cabinet agencies, research universities, and municipalities across the country. Same rigor. Right-sized for the organizations that need it most.Schedule a Consultation
Additional services coming soon. Have a specific need? Get in touch.
Our Approach
Every RedZoan tabletop exercise is delivered in three phases: Design, Execute, and Report. Each phase contains structured workshops, scoped to your engagement and the people who need to be in each one. Targeted delivery and completion time is 5 weeks, start to finish after the Statement of Work has been fully executed.
Build the right exercise for the right organization.
Design scope flexes with how tailored you want the exercise to be. At one end, a generic exercise built around common industry scenarios (fewer workshops, faster to stand up). At the other, a fully tailored exercise built around your specific environment, threat landscape, and operational context (deeper Design work, sharper scenario authenticity). We'll establish where on that spectrum your engagement sits during kick-off.
Workshops in this phase
Run the scenario. Observe the response.
Depending on the scope of your engagement, the Execute phase involves one or both of the following sessions. Each is facilitated live, with structured decision-point injects and scoring against a five-level maturity model.
Workshops in this phase
Hand leadership a clear picture of what to fix and in what order.
The Report phase converts what happened in the room into a presentation-ready package leadership can act on. Same content in both Word and PowerPoint, formatted for the audience.
Workshop in this phase
What's in the report
Sized to the engagement, not to a template.
About
James Inhof is a cybersecurity practitioner with over 17 years of experience across the USAF, NSA, DISA, Mandiant, and Google. His work has centered on translating complex security risk into strategic decisions leadership can act on: architecting Google's enterprise Stress Testing & Resilience program as its solo architect, advising CISOs and executive teams at organizations of every size, and translating active incident response into executive decisions when the boardroom conversation moved to crisis. A career built on building programs where none existed, fixing the unfixable, and solving the problems others couldn't.
James founded RedZoan Consulting on a simple premise: the combination of experience he brings (defensive cyber operations inside the intelligence community, translating major incident response for cabinet-level agencies, and enterprise Stress Testing & Resilience program design inside Google) is not a thing most organizations can assemble through a traditional hire or a typical vendor. RedZoan exists to make it directly available.
James is a United States Air Force veteran. He began his career with the 33rd Combat Communications Squadron (part of the "3rd Herd"), whose mission was to deploy anywhere in the world and stand up full command-and-control communications from scratch within 72 hours.
Anytime. Anywhere.
Improvise. Adapt. Overcome.
Every piece of the mission packed onto pallets and flown out the back of a plane. If it wasn't on the pallet, it didn't exist. Things got forgotten. Things broke. Failure wasn't an option. James was responsible for server, workstation, and cryptographic readiness on paper, but a 72-hour clock forced him to understand the whole picture and cross-train across the rest.
That habit (following the bouncing ball, finding the critical path, seeing how every piece fits) is what lets him lead complex engagements today without getting lost in the weeds. Most of the time.
Insights
Occasional field notes on risk, decision-making, and where the old playbook stops working.
What a recent unsolicited "executive search" email taught me about where company security awareness training breaks down.
Read Article →Engage
If you're responsible for your organization's security posture (whether you own the decision, run the program, or you're the one bringing the case to leadership), reach out. No jargon. No sales pitch. Just a straight answer about where you stand and what it would take to get to where you need to be.
RedZoan works with a limited number of clients at any given time. The person who scopes your engagement is the person who runs it — no account managers, no junior staff, no hand-offs.