About Nova Luna
Endeavor to be better.
Compliance | Information Security | Risk Management
Like most great things, Nova Luna Consulting began as a series of simple, powerful ideas: compliance doesn’t have to be complicated, information security isn’t just about buying the latest tech, and risk management should always be holistic.
While our bread and butter is NERC CIP, our years in the field have taught us a vital lesson: information security frameworks are largely built on the same foundational pillars. Whether your organization operates in the world of NERC CIP, NIST SP 800-171, NIST SP 800-53, or ISO 27001, the core principles are identical. That is why we apply a unified, holistic approach to any program we touch.
The Nova Luna Vision
We aim to transform regulatory requirements from a burden to a strategic advantage, fostering a culture of security that transcends mere compliance
The Nova Luna Mission
We inspire our clients to build world-class security cultures by delivering holistic approaches to security obstacles and fortifying existing programs. Our mission is to de-mystify complex requirements through expert guidance and streamlined processes, providing organizations with the tools to achieve sustainable compliance without sacrificing operational agility.
Our Core Values
Our values reinforce our fundamental principle: simplifying the complex and bringing absolute clarity to regulatory ambiguity.
Radical Clarity: In an industry governed by dense regulatory standards and technical jargon, we choose to be understood. We translate complex requirements into plain language and actionable steps so that every stakeholder understands their role in security.
Operational Integration: Compliance should support your mission, not hinder it. We design security controls that fit naturally into your existing operational workflows, ensuring that “being compliant” and “doing the work” become one and the same.
Purpose-Driven Compliance: We look far beyond the checkbox. Our focus is always on the underlying security intent of each standard and requirement, helping our clients build meaningful defenses that actually protect their environment rather than just satisfying an auditor.
Scalable Simplicity: Whether we are helping a small co-op or a large investor-owned utility (IOU), we provide right-sized solutions. We firmly reject “complexity for complexity’s sake,” opting instead for elegant, scalable solutions that grow alongside your needs.
What Makes Us Qualified?
We’ve Been in Your Shoes
We have been there before—on both sides of the table. Our team is comprised of real-world practitioners, analysts, and auditors. We have sat in your seat during grueling audits, and we have been the ones conducting them.
Proven Track Record: We have built entire security programs from scratch, transitioned legacy compliance programs to fit modern standards, and actively helped shape the industry into what it is today.
Deep Credentials: We don’t just rely on hands-on experience; our team holds advanced degrees, industry-standard certifications, and years of verifiable, real-life experience within the sector.
"We don't just consult on standards—we help you build a culture that outlasts the audit."
