Bienvenidos, San Antonio · 25% off all cybersecurity services, now through December 31, 2026. See what qualifies →

Military-spouse-owned · San Antonio, TX

From scanner noise to verified risk reduction.

Vulnerability management, SOC 2 readiness, AI security, and fractional security leadership for small and mid-sized teams. A practitioner runs your engagement.

Credentials and standing

  • ISC2 CSSLP
  • ISC2 SSCP
  • CompTIA Security+
  • CyberAB Registered Practitioner
  • Verify credential
  • MS Cybersecurity

Author of VM3, a published vulnerability-management maturity model (CC BY 4.0). Credentials listed are held by Emmanuel Aguero, founder, and are independently verifiable — the CyberAB Registered Practitioner credential can be checked at badges.parchment.com. Invictus is pursuing CyberAB Registered Provider Organization status.

The problem

Most teams drown in findings and can’t prove risk went down.

Verified reduction

We measure what actually got fixed and re-test it — not how many findings your scanner printed.

Continuous, not one-and-done

A program that runs on a cadence and holds, instead of a PDF that ages out the week you receive it.

Executive-ready reporting

Your board and your insurer see risk in plain language. Your engineers get a queue they can work.

Our framework

VM3 — our published maturity model.

VM3 is a practitioner-derived maturity model for vulnerability management: five maturity levels across five operational dimensions, with a scoring rubric and mappings to NIST 800-171, SOC 2, and PCI DSS. We wrote it, we publish it openly under CC BY 4.0, and we run our engagements on it.

Get the report and see where your program sits today.

Read about VM3

Get the VM3 report

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

The report and occasional field notes. Nothing else, and no reselling your details.

How it works

Every engagement runs the pre-flight checklist.

  1. 01

    Pre-check

    We scope against what you actually run — users, systems, cloud, and the compliance driver behind the work.

  2. 02

    Map

    Findings become a ranked picture of risk, mapped to your framework and your business, not a raw export.

  3. 03

    Remediate

    Your team gets a queue they can work, with fixes sequenced by risk and effort. We work it with you.

  4. 04

    Validate

    We re-test and prove the risk actually went down. That evidence is what your auditor and your board want.

Why Invictus

A practitioner, not a reseller.

Invictus Cybersecurity is a military-spouse-owned security consultancy based in San Antonio, Texas. We are product-agnostic: we don’t resell tooling, and we don’t take vendor commissions. We run programs on the tools you already own.

The person who scopes your engagement is the person who delivers it. Engagements are available in English or Spanish.

More about us

BasedSan Antonio, TX

OwnershipMilitary-spouse-owned

DeliveryRemote & on-site, SA metro

LanguagesEnglish · Español

InsuredE&O, professional & liability

FrameworkVM3 — CC BY 4.0

Talk to a real engineer, not a sales rep.

Tell us what’s driving the work — an auditor, an insurer, a customer questionnaire, or a feeling that something’s been missed. We’ll tell you honestly whether we’re the right fit.