About us

We defend by thinking
like the adversary.

Cyber Tower Labs was founded on a simple belief: you can't defend what you've never tried to break.

Our story

Built by operators, for defenders.

We started Cyber Tower Labs after years on both sides of the fight — breaking into the world's most sensitive networks by day, and rebuilding their defenses by night. We kept seeing the same gap: security tools everywhere, but few teams who could think like the people actually trying to get in.

Today we do four things exceptionally well. We run application and network penetration testing that mirrors a real adversary. We operate a 24/7 SOC with managed detection and incident response. We deliver compliance-as-code against ISO 27001, NIST 800-53, and SOC 2. And we build cybersecurity products — our flagship, NOMARCH, automates Windows compliance for entire fleets.

No dashboards for the sake of dashboards. Just measurable, provable resilience against the threats that actually target you — delivered by the same people who build the tooling behind it.

Years defending
Engagements shipped
Monitoring uptime
Avg. response
What we stand for

Principles we don't compromise

Adversarial by default

We assume breach and think like the attacker, because the only assessment that matters is the one that mirrors the real threat.

Radical clarity

No fear-mongering, no jargon walls. Every finding comes with impact, likelihood, and a concrete path to fix it.

Partners, not vendors

We embed with your team, share our playbooks, and measure success by your resilience — not our billable hours.

Provable security

Controls you can test, evidence you can show an auditor, and outcomes you can put in front of a board.

The people

Leadership

AS

Ava Sinclair

Founder & CEO

MR

Marcus Rhee

Head of Offensive Security

PN

Priya Nadar

Director, SOC & Detection

DF

Diego Fuentes

Lead Incident Responder

Our flagship product

NOMARCH Windows compliance that guards — and heals — itself.

NOMARCH is our autonomous Windows compliance platform. A guardrailed AI generates hardened PowerShell checks, verifies every line through a static safety gate, and auto-heals configuration drift across your entire fleet — turning audit prep into a continuous, provable, hands-off process.

Guardrailed AI generation
Hardened checks are written by an LLM behind a four-layer static safety gate — nothing unsafe ever reaches a host.
Self-healing baselines
When a control drifts or a script breaks, NOMARCH repairs it, re-verifies, version-bumps, and the agent re-runs — autonomously.
Ten frameworks, out of the box
NIST 800-53 and nine ISO standards ship ready to deploy — or author your own custom baseline, control by control.
True multi-tenant
Cryptographically isolated organizations on one deployment — every org sees only its own fleet, findings, and keys.
nomarch · fleet scan
compliant
  • nist_firewall_enabledPASS
  • nist_defender_antivirusPASS
  • iso27001_password_policyDRIFT → HEAL
  • iso27001_password_policyPASS
Covers:ISO 27001ISO 27002ISO 27017ISO 27018ISO 27701ISO 22301
Ready when they are

Find your weak points before attackers do.

Book a scoping call and get a threat-model of your environment within 48 hours — no obligation, no jargon.