About Nova Luna

Endeavor to be better.

Compliance | Information Security | Risk Management

Like most great things, Nova Luna Consulting began as a series of simple, powerful ideas: compliance doesn’t have to be complicated, information security isn’t just about buying the latest tech, and risk management should always be holistic.

While our bread and butter is NERC CIP, our years in the field have taught us a vital lesson: information security frameworks are largely built on the same foundational pillars. Whether your organization operates in the world of NERC CIP, NIST SP 800-171, NIST SP 800-53, or ISO 27001, the core principles are identical. That is why we apply a unified, holistic approach to any program we touch.

The Nova Luna Vision

We aim to transform regulatory requirements from a burden to a strategic advantage, fostering a culture of security that transcends mere compliance

The Nova Luna Mission

We inspire our clients to build world-class security cultures by delivering holistic approaches to security obstacles and fortifying existing programs. Our mission is to de-mystify complex requirements through expert guidance and streamlined processes, providing organizations with the tools to achieve sustainable compliance without sacrificing operational agility.

A foggy mountain landscape with tall evergreen trees and a dense forest on a misty day.

Our Core Values

Our values reinforce our fundamental principle: simplifying the complex and bringing absolute clarity to regulatory ambiguity.

Radical Clarity: In an industry governed by dense regulatory standards and technical jargon, we choose to be understood. We translate complex requirements into plain language and actionable steps so that every stakeholder understands their role in security.

Operational Integration: Compliance should support your mission, not hinder it. We design security controls that fit naturally into your existing operational workflows, ensuring that “being compliant” and “doing the work” become one and the same.

Purpose-Driven Compliance: We look far beyond the checkbox. Our focus is always on the underlying security intent of each standard and requirement, helping our clients build meaningful defenses that actually protect their environment rather than just satisfying an auditor.

Scalable Simplicity: Whether we are helping a small co-op or a large investor-owned utility (IOU), we provide right-sized solutions. We firmly reject “complexity for complexity’s sake,” opting instead for elegant, scalable solutions that grow alongside your needs.

A paved road running through a dense forest of evergreen trees, with mist visible in the distance and a cloudy sky overhead.

What Makes Us Qualified?

We’ve Been in Your Shoes

We have been there before—on both sides of the table. Our team is comprised of real-world practitioners, analysts, and auditors. We have sat in your seat during grueling audits, and we have been the ones conducting them.

Proven Track Record: We have built entire security programs from scratch, transitioned legacy compliance programs to fit modern standards, and actively helped shape the industry into what it is today.

Deep Credentials: We don’t just rely on hands-on experience; our team holds advanced degrees, industry-standard certifications, and years of verifiable, real-life experience within the sector.

"We don't just consult on standards—we help you build a culture that outlasts the audit."