CARMhaus Consulting
Home
Services
  • Security Architecture
  • Readiness Assessment
  • Security Leadership
  • Third-Party Risk
Industries
  • Defense and Aerospace
  • Manufacturing and OT
  • Healthcare
  • Financial Services
Frameworks
  • CMMC Level 2
  • NIST SP 800-171
  • SOC 2
  • ISO 27001
  • HIPAA
  • SOX ITGC
Approach
About
Contact
CARMhaus Consulting
Home
Services
  • Security Architecture
  • Readiness Assessment
  • Security Leadership
  • Third-Party Risk
Industries
  • Defense and Aerospace
  • Manufacturing and OT
  • Healthcare
  • Financial Services
Frameworks
  • CMMC Level 2
  • NIST SP 800-171
  • SOC 2
  • ISO 27001
  • HIPAA
  • SOX ITGC
Approach
About
Contact
More
  • Home
  • Services
    • Security Architecture
    • Readiness Assessment
    • Security Leadership
    • Third-Party Risk
  • Industries
    • Defense and Aerospace
    • Manufacturing and OT
    • Healthcare
    • Financial Services
  • Frameworks
    • CMMC Level 2
    • NIST SP 800-171
    • SOC 2
    • ISO 27001
    • HIPAA
    • SOX ITGC
  • Approach
  • About
  • Contact
  • Home
  • Services
    • Security Architecture
    • Readiness Assessment
    • Security Leadership
    • Third-Party Risk
  • Industries
    • Defense and Aerospace
    • Manufacturing and OT
    • Healthcare
    • Financial Services
  • Frameworks
    • CMMC Level 2
    • NIST SP 800-171
    • SOC 2
    • ISO 27001
    • HIPAA
    • SOX ITGC
  • Approach
  • About
  • Contact

Myka Hauser, CISSP

Twelve years across IT, GRC and regulated manufacturing, most of it spent as the person accountable for the control environment rather than the person advising on it.

The short version

The path

The through line

The through line

Twelve years in IT, security engineering and GRC, almost all of it inside regulated environments. Field IT and industrial systems first, then risk assessment and internal audit, then security and compliance leadership at a cleared defense manufacturer.

The through line

The through line

The through line

Being accountable for the control environment rather than advising on it. Writing the policy and building the configuration underneath it, running incident response, automating access, and working across enterprise, plant and OT networks.

The firm

The through line

The firm

CARMhaus has run since 2023, serving mid-market SaaS, healthcare, financial services and manufacturing clients. We are currently taking on new engagements.

Selected results

CMMC Level 2

Data protection

NIST SP 800-53

Certified with zero PoA&Ms. Led the program end to end at a $60M DoD-revenue site, with all 110 NIST SP 800-171 controls met at assessment.

NIST SP 800-53

Data protection

NIST SP 800-53

Baselines cross-mapped for DoD-adjacent clients. Low and moderate baselines mapped to NIST 800-171 and CMMC equivalents, so one control set answered to three frameworks.

Data protection

Data protection

Data protection

DLP architecture designed across multiple tenants, covering several regulatory regimes at once.

SOX ITGC

Questionnaires and vendor risk

Data protection

Access review cycle time cut 25%. Access review workflows automated against SOX controls, with the evidence collection standardized behind them.

Questionnaires and vendor risk

Questionnaires and vendor risk

Questionnaires and vendor risk

200 or more completed. Enterprise questionnaires and third-party risk assessments, with a reusable answer library built as a byproduct.

ISO 27001

Questionnaires and vendor risk

Questionnaires and vendor risk

Nonconformities cut by 60%. Corrective action plans and control improvements across a multi-year internal assessment program.

Happy to be the second opinion

CARM is what the work is: cybersecurity, assurance, risk management. Haus is how it is put together, designed once so it holds up without us standing next to it.

If you already have a plan and want someone to break it before an assessor does, that is a good use of a call. References available under NDA.

Book a scoping call

© 2026 CARMhaus Consulting LLC. All rights reserved. Cybersecurity · Assurance · Risk Management

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept