Index / Work / 01

Case 01 — Founder & Chief Executive

Cobrix Solutions

A remote California MSP and MSSP built for businesses where an IT failure is also a regulatory event. I founded it, built the delivery model, and still run it.

Role
Founder & Chief Executive
Period
2024 — Present
Status
Operating · cobrixsolutions.net ↗
Verticals
Healthcare · Legal · Accounting · Real estate · Construction

The problem I started from

Small businesses in regulated industries get the worst version of IT support available. A twelve-person medical practice carries the same HIPAA obligations as a hospital system and gets a break-fix technician with a phone number and no written incident response plan. A three-partner law firm handles wire instructions on a mailbox with no phishing-resistant authentication in front of it.

The gap is not technical capability — the tooling is commoditized and affordable. The gap is program discipline: documented procedures, tested restores, defined response times, and someone accountable when the calendar says an annual review is due. That is a project management problem wearing a cybersecurity costume, which is precisely why I thought I could build it.

Every engagement is designed so the next 2:00 a.m. page never lands.

What I actually built

1. A deliberately narrow stack

The obvious move for a new MSP is to bolt together a separate RMM, PSA, EDR, and backup vendor and pass the license cost through. I did the opposite. Cobrix standardizes on Microsoft 365 Business Premium and runs endpoint management through Intune, threat detection through Defender, identity through Entra, and multi-tenant oversight through Lighthouse.

One vendor, one identity plane, one audit trail. Fewer integration seams means fewer places for a client's security posture to quietly drift out of compliance between reviews — and a materially lower cost basis I can pass through as flat-rate pricing instead of a per-tool markup.

2. Three commitments, written into every engagement

  • A signed Business Associate Agreement wherever HIPAA applies — before any access is provisioned, not after an auditor asks.
  • SLA-backed response times measured in minutes rather than business days.
  • Flat-rate monthly pricing with no long-term lock-in, so the relationship survives on performance rather than on a termination clause.

3. A preventive service catalog

Managed IT, managed cybersecurity, cloud strategy and migration, AI automation for regulated workflows, and vCIO advisory — each mapped to the specific regulation the buyer is actually exposed to. Healthcare gets HIPAA. Accounting gets the FTC Safeguards Rule. Real estate gets wire fraud and business email compromise defense. Legal gets confidentiality obligations under the ABA Model Rules.

The management thesis

Running this taught me something I could not have learned managing projects inside someone else's operation: every decision has a cost I have to personally absorb. Choosing a second security vendor is not a slide in a deck, it is margin. Writing an aggressive SLA is not a positioning statement, it is a promise I have to staff.

That changes how I run a project. I now instinctively ask what a control costs to operate for three years, not what it costs to implement once — which is the question most implementation plans forget to answer.

1
Company founded, licensed, and delivering service
5
Regulated verticals served with framework-specific programs
0
Long-term contracts required to hold a client

What I would tell a hiring manager

Cobrix is not a side project I mention for color. It is the proof that I can be handed an undefined problem, define the scope myself, choose the stack, price the work, absorb the risk, and still be operating two years later. Most project managers have never had to own the P&L of the thing they are managing. I do, weekly.