Rich Bates, CRISC, GSLC, CyberAB RP
Fractional CIO and Cybersecurity Specialist with Expertise in CMMC, NIST 800-171, and IT Governance.
40 yrs experience · <10 hrs/week
About
With over 30 years of experience in Governance, Risk, and Compliance (GRC), I’ve guided organizations through complex cybersecurity frameworks and delivered measurable results, including 99% maturity validation against NIST 800-171 controls and readiness for CMMC Level 2 compliance. As a trusted advisor, I translate technical complexity into clear, executive-aligned strategies. My credentials - CRISC, GSLC, and The Cyber AB Registered Practitioner (CMMC Certified Professional in process) - underscore my commitment to risk management and regulatory excellence. I help build resilience, protect sensitive data, and maintain trust that wins contracts.
Experience
- Proprietor · The Prydwen Advisory2025-08-01 –
Helping Government Contractors Sleep at Night At The Prydwen Advisory, we specialize in turning compliance challenges into competitive advantages. For many contractors, CMMC, NIST SP 800-171, and CUI protection aren’t just regulations - they’re what keeps leadership awake at night. We make those worries disappear by delivering clarity, confidence, and compliance. What We Do: *Compliance Readiness & Strategy - Gap analysis, remediation planning, and audit preparation for CMMC Level 2 and NIST SP 800-171. *Cybersecurity Governance & Risk Management - Tailored GRC solutions that align with federal frameworks and business objectives. *Executive Advisory - Translating technical complexity into actionable decisions for leadership teams. Why Clients Choose Us: *Proven Expertise - Over 30 years in GRC, guiding organizations through high-stakes compliance challenges. *Certified Leadership - Credentials include CRISC, GSLC, and The Cyber AB Registered Practitioner, ensuring trusted, standards-based guidance. *Results That Matter - Achieved 99% maturity validation against NIST 800-171 controls, enabling clients to retain and win critical contracts. Our mission is simple: help contractors feel confident, secure, and ready for what’s next.
- CIO Emeritus, Cybersecurity Program Manager · Zeiders Enterprises2012-11-01 – 2025-09-01
Lead all aspects of the enterprise Cybersecurity Program including CMMC readiness, education and awareness, NIST 800-171 and 800-161 compliance, and policy development. Developed several in-house tools used in a CMMC L2 self-assessment. Key Achievements as CIO: Lead all aspects of enterprise IT strategy, cybersecurity programs, infrastructure modernization, and vendor partnerships for a federal contractor serving military and government communities. Reached 99% audit readiness across 450+ NIST 800-53 controls, transitioned the organization to NIST 800-171 and CMMC Level 2 preparedness Directed the migration to Microsoft 365 GCC and cloud-based SharePoint with zero disruption for 1,000 users Built and scaled virtual call centers supporting up to 35,000 quarterly interactions Delivered consistent cost savings across a $2.1M–$3.5M budget through contract negotiation and vendor management Led remote workforce transformation during the pandemic, earning government recognition for preparedness Turned a contract loss into a (small) profit and kept hundreds of pounds of non-biodegradable waste out of landfills Skills: Cybersecurity Governance • CMMC/NIST Compliance • Cloud Transition (M365 GCC) • Infrastructure Modernization • Vendor Management • Virtual Call Center Setup • Strategic IT Planning • Budget Management • Federal Contracting • Remote Workforce Enablement • Change Management • Leadership Coaching
- Principal · Gilead Consulting2010-06-01 – 2012-11-01
Founded and ran a boutique consulting firm focused on cybersecurity, FedRAMP readiness, and IT transformation for public and private sector clients. Key Achievements: Advised firms like Apptis and Ventraq on achieving compliance with FedRAMP and SOC 2 standards Conducted security assessments and remediation for SSAE-16/SOC 2 alignment Led IT infrastructure modernization and data center strategy for clients managing large-scale systems Skills: FedRAMP Readiness • SOC 2 / SSAE-16 Audits • IT Compliance Strategy • Infrastructure Optimization • Risk Management • Private Cloud Transitions • Data Center Operations • Executive Advisory • Tools Evaluation • Staff Augmentation Strategy
- Sr. Director & VP, Technical Operations · ServerVault/Carpathia Hosting, Inc.2009-09-01 – 2010-04-01
Oversaw operations for a commercial hosting firm supporting government agencies and enterprise clients across the Americas, ensuring full compliance with federal standards. Key Achievements: Managed 1,500+ enterprise assets and 75+ clients across North and South America Directed operations across 20+ vendors, delivering on up to $3M capital budgets Authored business continuity and disaster recovery plans—resulting in certifications with zero audit findings Eliminated recurring SLA penalties by revamping service delivery protocols Skills: Hosting Infrastructure • INFOSEC Operations • Business Continuity Planning • Vendor Oversight • Capital Budgeting • Disaster Recovery • Compliance Certifications (SysTrust, SAS 70 II) • SLA Performance Management • Enterprise IT Delivery • Team Leadership
- Earlier Leadership Roles · Various Companies1983-01-01 – 2009-09-01
Principal, BatWerks Development Senior Associate, AT&T Solutions Senior Program Engineer, SMS Data Products Group Senior Project Manager, Integrated Microcomputer Systems
Education
- The George Washington UniversityMSIS, Information Science
- The George Washington UniversityBBA, Information Sciences
Similar talent on Pangea
Hire Rich through Pangea
Describe your project to the Pangea agent — see if Rich is a fit, with transparent pricing and interviews booked straight onto your calendar. No contact details change hands until you hire.
See if Rich is a fit