Home / About

Background  //  Credentials  //  Track Record

The background that changes the conversation.

Most small-business security consultants have one dimension. Sparrowhawk brings enterprise depth, military discipline, and real-incident experience to every engagement — because all three matter when something goes wrong.

One operator. Accountable end to end.

Matthew Jones, Founder and Principal Security Consultant, Sparrowhawk Technology
Matthew Jones Founder & Principal
Security Consultant
CISSP
CompTIA Security+ CE
CrowdStrike Falcon
Rapid7 InsightIDR / InsightVM Prior: CEH (EC-Council), CCNA (Cisco)

Sparrowhawk Technology is led by Matthew Jones, Founder and Principal Security Consultant — a 20-year U.S. Army combat veteran with more than 30 years of hands-on IT experience across military, manufacturing, and enterprise environments.

When you engage Sparrowhawk, you work directly with the person who assesses your environment. There is no sales engineer who disappears after the kickoff call, no junior analyst running a scanner and forwarding the output, and no offshore report-writing team. The person who finds the problem is the person who explains it to you and the person who verifies it was fixed.

That structure is deliberate. Security findings lose meaning in translation. The value is not the scan — scanners are cheap and anyone can run one. The value is the judgment about which of the four hundred findings actually matter for your environment, your obligations, and your tolerance for downtime.

Why "no checklists" is more than a slogan

Checklist security produces compliant organizations that still get breached. A framework tells you to enforce MFA; it does not tell you that your VPN appliance still accepts legacy authentication, that three service accounts are exempt, or that your break-glass account has a password that hasn't rotated since 2019.

Finding that gap requires someone who has administered the systems, not just audited them. Thirty years of building and running infrastructure is what makes the difference between a report that lists controls and a report that tells you where you are actually exposed.

Four things most consultants can't claim.

These aren't credentials on a wall. Each one changes how an assessment gets done and what it's worth to you.

// 20 Years Active Duty

U.S. Army Combat Veteran

Operational discipline, chain-of-custody documentation, and security-first thinking aren't concepts from a textbook — they're habits built over two decades in uniform. That rigor carries into every assessment we deliver, from how evidence is handled to how findings are escalated.

// Rare Background

9 Years in Manufacturing OT/IT

Most security consultants have never set foot on a production floor. We've spent nearly a decade securing operational technology in food manufacturing — understanding what cannot go offline, what a line stoppage actually costs, and how to build security around that reality rather than pretending it doesn't exist.

// Real Incidents

Active Ransomware Response

We have been on the inside of a live ransomware incident — not as a bystander or a post-mortem consultant, but as the operator managing response while it was happening. That experience shapes how we assess risk, harden environments, and prepare organizations for the worst case before it arrives.

// Verified & Current

Credentials Backed by Experience

CISSP, CompTIA Security+ CE, CrowdStrike Falcon, Rapid7 InsightIDR and InsightVM. Not wallpaper — active, tested, and maintained because the threat landscape demands it, and paired with the operational history to apply them.

Results delivered.
Operator-led.

$1M+ Annual MSP Spend Eliminated Multi-site manufacturing operation
0 Downtime on Migration Full enterprise, multiple production sites
Industry Certified CISSP · Security+ & more
Eliminated $1M+ in annual MSP dependency at a multi-site manufacturing operation through architecture — not vendor lock-in. Managed active ransomware incident response from the inside. Led a zero-downtime enterprise infrastructure migration across multiple production sites.

Built on real expertise.
Verified by the industry.

Sparrowhawk Technology is an SBA-certified Service-Disabled Veteran-Owned Small Business with active SAM.gov registration for all federal award types.

CISSP Certified Information Systems
Security Professional · ISC²
Security+ CompTIA Security+ CE
Continuing Education
CrowdStrike Falcon Platform
Certified
Rapid7 InsightIDR & InsightVM
Certified
SAM.gov Active Federal Registration  ·  Veteran-Owned  ·  All Awards UEI: NG57HR5JFF83  ·  CAGE: 98N91  ·  SDVOSB Certified
// Verified Credentials
CISSP - Certified Information Systems Security Professional, ISC2
CompTIA Security+ CE Certified
Prior Certifications CEH · Certified Ethical Hacker · EC-Council CCNA · Cisco Certified Network Associate

If your network is worth protecting,
it's worth an honest assessment.

We provide technical security briefings for business owners, operations leaders, and IT teams who want a straight answer about where they stand. No sales pitch.

Request a Security Briefing

info@sparrowhawktech.com  ·  sparrowhawktech.com