Principal Team


  • Jonathan Ham
  • Sherri Davidoff
  • Eric Fulton

Jonathan Ham

Certified SANS Instructor, CISSP, GCIA, GCIH

Jonathan Ham is an independent consultant who specializes in large-scale enterprise security issues, from policy and procedure, through staffing and training, to scalable prevention, detection, and response technology and techniques. With a keen understanding of ROI and TCO, he has helped his clients achieve greater success for over 12 years, advising in both the public and private sectors, from small startups to the Fortune 500. He's been commissioned to teach NCIS investigators how to use Snort, performed packet analysis from a facility more than 2000 feet underground, and chartered and trained the CIRT for one of the largest U.S. civilian Federal agencies. He currently holds the CISSP, GCIA, and GCIH certifications, and is a Certified Instructor with the SANS Institute.


Sherri E. Davidoff

MIT 2003, GCFA and GPEN-certified

Sherri Davidoff is an independent information security consultant specializing in forensics, penetration testing and incident response. She began her security career as a member of MIT's network security team, where she managed incidents and designed a network flow analysis tool. Subsequently, she founded the incident response team and managed UNIX/Linux security for the Boston Children's Hospital. She has consulted for a wide variety of industries, including financial, health care, manufacturing, academic, and government institutions. Ms. Davidoff holds her GCFA forensic certification and her GPEN penetration testing certification. She has an S.B. in Computer Science and Electric Engineering from MIT.

Eric Fulton

Certified Web Application Penetration Tester (GWAP)

Eric Fulton is a specialist in network penetration testing and web application assessments. His clients have included Fortune 500 companies, international financial institutions, global insurance firms, government entities, telecommunications companies, as well as world-renowned academic and cultural institutions. In his spare time, Eric works with local students to provide hands-on security training, and conducts independent security research on magnetic access cards and RFID technology. He publishes network forensics contests on ForensicsContest.com.