Background // Credentials // Track Record
Most small-business security consultants have one dimension. Sparrowhawk brings enterprise depth, military discipline, and real-incident experience to every engagement — because all three matter when something goes wrong.
Who You're Working With
Sparrowhawk Technology is led by Matthew Jones, Founder and Principal Security Consultant — a 20-year U.S. Army combat veteran with more than 30 years of hands-on IT experience across military, manufacturing, and enterprise environments.
When you engage Sparrowhawk, you work directly with the person who assesses your environment. There is no sales engineer who disappears after the kickoff call, no junior analyst running a scanner and forwarding the output, and no offshore report-writing team. The person who finds the problem is the person who explains it to you and the person who verifies it was fixed.
That structure is deliberate. Security findings lose meaning in translation. The value is not the scan — scanners are cheap and anyone can run one. The value is the judgment about which of the four hundred findings actually matter for your environment, your obligations, and your tolerance for downtime.
Checklist security produces compliant organizations that still get breached. A framework tells you to enforce MFA; it does not tell you that your VPN appliance still accepts legacy authentication, that three service accounts are exempt, or that your break-glass account has a password that hasn't rotated since 2019.
Finding that gap requires someone who has administered the systems, not just audited them. Thirty years of building and running infrastructure is what makes the difference between a report that lists controls and a report that tells you where you are actually exposed.
Why Sparrowhawk
These aren't credentials on a wall. Each one changes how an assessment gets done and what it's worth to you.
Operational discipline, chain-of-custody documentation, and security-first thinking aren't concepts from a textbook — they're habits built over two decades in uniform. That rigor carries into every assessment we deliver, from how evidence is handled to how findings are escalated.
Most security consultants have never set foot on a production floor. We've spent nearly a decade securing operational technology in food manufacturing — understanding what cannot go offline, what a line stoppage actually costs, and how to build security around that reality rather than pretending it doesn't exist.
We have been on the inside of a live ransomware incident — not as a bystander or a post-mortem consultant, but as the operator managing response while it was happening. That experience shapes how we assess risk, harden environments, and prepare organizations for the worst case before it arrives.
CISSP, CompTIA Security+ CE, CrowdStrike Falcon, Rapid7 InsightIDR and InsightVM. Not wallpaper — active, tested, and maintained because the threat landscape demands it, and paired with the operational history to apply them.
Past Performance
Eliminated $1M+ in annual MSP dependency at a multi-site manufacturing operation through architecture — not vendor lock-in. Managed active ransomware incident response from the inside. Led a zero-downtime enterprise infrastructure migration across multiple production sites.
Certifications & Federal Registration
Sparrowhawk Technology is an SBA-certified Service-Disabled Veteran-Owned Small Business with active SAM.gov registration for all federal award types.


Get Started
We provide technical security briefings for business owners, operations leaders, and IT teams who want a straight answer about where they stand. No sales pitch.
Request a Security Briefinginfo@sparrowhawktech.com · sparrowhawktech.com