United States

Summon Cybersecurity Solutions

Independent cybersecurity consulting focused on penetration testing and incident response for US organizations.

Matthew Bourn

I am an independent cybersecurity consultant operating as Summon Cybersecurity Solutions LLC. With over ten years of hands-on experience in offensive security and post-breach work, I help organizations find real risk and recover cleanly when something breaks.

The LLC exists to make contracting straightforward: a single counterparty, clear statements of work, and senior work delivered directly without layers of account management or a rotating bench.

I take a limited number of engagements at a time so every assessment and every incident gets the attention it deserves. Findings are written for people who have to act on them: technical enough for engineers, clear enough for leadership.

What I Deliver

Penetration Testing

Hands-on assessments that map real attack paths and business risk not checkbox scans. Deliverables prioritize exploitable issues with practical remediation.

  • External & internal network testing
  • Web & API application assessments
  • Cloud environment reviews
  • Adversary simulation / red team operations

Incident Response

Structured response when minutes matter: contain the threat, preserve evidence, and give leadership a clear picture of impact and next steps.

  • Incident investigation & forensics
  • Compromise assessment
  • Incident response retainers
  • Post-incident review & hardening

Approach

Whether the goal is proactive testing or reactive response, the shape of the work is the same: agree the rules, do the work carefully, report what matters, and leave you better positioned than before.

  1. 01

    Discovery & scope

    Goals, constraints, rules of engagement, and success criteria. Contracts and RoE written so both sides know the boundaries.

  2. 02

    Execution

    Testing or investigation with continuous communication. No surprises on production systems; evidence handled with care.

  3. 03

    Reporting

    Findings ranked by business risk, with reproduction detail and remediation that security and engineering teams can use.

  4. 04

    Closeout

    Readout, questions answered, optional retest or hardening follow-up. Retainers available for teams that want a known responder on call.

Experience & Credentials

Professional focus

Over a decade of work across offensive security and incident response has shaped how I test and how I investigate. Attackers reuse patterns; defenders need evidence and priorities, not noise.

I specialize in helping organizations see their true posture through hands-on testing and in supporting them through the hardest days after a breach. That dual view keeps assessments realistic and response advice practical.

Certifications

Current

A+

Expired

Sec+
MCP
MCDBA
CCNA

In progress

CPTS
CDSA
GCIH

Let’s Work Together

I work with a limited number of clients at any given time so every engagement receives senior, uninterrupted attention. If you need a pen test, a compromise assessment, or a responder you can put on retainer, start with an email.

Based in the United States · Available for engagements nationwide

Summon Cybersecurity Solutions LLC - a single-member practice built for clear contracts and direct work.