// About the founder

Hello. I'm Edith Forestal, CISSP.

Founder of Forestal Security — senior-level security, sized for small business.

I've spent over a decade building and running technology companies — and I still build. My AI security tools have run over a thousand analyses for small businesses. My specialty is finding vulnerabilities before attackers do — across AWS, Microsoft 365, and Azure, identity and access systems, and the everyday software your business runs on.

Most security firms are built for enterprises: bloated toolstacks, account managers, jargon-filled reports nobody reads. I built Forestal Security to be the opposite — flat fees, no contracts, and findings explained in language the person who signs the checks can act on. When you work with me, you work with me: I run the assessment, I write the report, I take the findings call.

The same skills protect high-stakes, heavily audited systems every day — hardening identity, enforcing Zero Trust access, and hunting vulnerabilities. Your business gets that level of rigor, sized and priced for a small business.

CISSP CISM CEH v13 CASP+ / SecurityX CySA+ AZ-500 SC-200 SC-300
Edith L. Forestal, CISSP — founder of Forestal Security
Edith Forestal | Founder
CISSP, CISM, and
security consultant
LinkedIn

Education

Western Governors University
M.S. in Cybersecurity & Information Assurance
Defiance College
B.S. in Criminal Justice · Minor in Psychology

Technical specialties

Microsoft 365 & Azure security
Entra ID hardening, Conditional Access, Zero Trust architecture (AZ-500)
Detection engineering & security operations
Microsoft Sentinel & Defender XDR (SC-200)
Identity & access management
IAM architecture and administration (SC-300)

Focus areas

Vulnerability assessment & ethical hacking
Finding and prioritizing weaknesses before attackers do
Cloud & identity security
Microsoft 365, Azure, AWS and access control done right
AI security automation
10+ tools built · 1,000+ analyses delivered

Curious where your business stands?

// Certifications

11 certifications. Every one independently verifiable.

No claims, just proof — every credential below links to the issuing body's own verification page (Credly, Microsoft Learn, or EC-Council). Tap "What is this?" on any row for a plain-English explanation.

Security Leadership & Architecture
CISSP
Certified Information Systems Security Professional
ISC2 · experience-verified
✓ Verify
CISM
Certified Information Security Manager
ISACA · experience-verified
✓ Verify
SecurityX
CompTIA SecurityX (formerly CASP+)
CompTIA · advanced practitioner
✓ Verify
Microsoft Cloud, Identity & 365
MS-102
Microsoft 365 Administrator Expert
Microsoft · expert level
✓ Verify
SC-300
Microsoft Identity & Access Administrator Associate
Microsoft
✓ Verify
AZ-500
Microsoft Azure Security Engineer Associate
Microsoft
✓ Verify
SC-200
Microsoft Security Operations Analyst Associate
Microsoft
✓ Verify
Offensive & Defensive Operations
CEH v13
Certified Ethical Hacker
EC-Council · AI-focused v13
✓ Verify
PenTest+
CompTIA PenTest+
CompTIA
✓ Verify
CySA+
CompTIA CySA+
CompTIA
✓ Verify
Security+
CompTIA Security+
CompTIA
✓ Verify

My Professional Journey

From building businesses to defending them — my career has always been about solving problems others overlook.

// My professional journey

From building businesses to defending them.

My career has always been about solving the problems others overlook.

Hello, I'm Edith Forestal, founder of Forestal Security. I've spent over a decade building and running technology companies — starting with a web development and IT firm serving small businesses, and growing into a full cybersecurity consultancy.

That entrepreneurial background gives me something most security professionals don't have: I understand how businesses actually operate. I've handled payroll, managed clients, and built infrastructure from scratch — and worn every hat in between. So when I assess an organization's security, I'm not checking boxes. I'm thinking about what keeps the business running, and what could shut it down.

Today my work spans the full stack of a modern business environment — cloud platforms, identity, endpoints, and the AI systems increasingly woven into all of it — backed by eleven verified certifications and a master's in cybersecurity.

How I can help

Vulnerability Management
  • Full-environment vulnerability assessments with risk-ranked, plain-English reporting
  • Remediation planning and automated patch management across entire fleets
  • CISA KEV-driven prioritization — fixing what attackers actually exploit first
Cloud Security — Azure, AWS & M365
  • Microsoft 365 tenant hardening: Exchange Online, SharePoint, Teams, OneDrive
  • Azure security engineering (AZ-500) and AWS environment reviews
  • Configuration baselines that close misconfigurations and data-leakage paths
Identity & Access Management
  • Entra ID and Active Directory: provisioning, roles, and access lifecycle
  • Conditional Access and Zero Trust policy design and enforcement
  • Phishing-resistant MFA and authentication hardening
Detection & Response
  • Detection engineering: custom KQL analytics rules, MITRE ATT&CK-mapped
  • Microsoft Sentinel and Defender XDR integration and tuning
  • Threat hunting for indicators of compromise, lateral movement, and persistence
Infrastructure & Endpoint Management
  • VMware vCenter / ESXi administration, hardening, and lifecycle management
  • Endpoint management and configuration at fleet scale
  • Update rings, maintenance windows, and reboot policies that respect the business
AI Security & Automation
  • AI security governance aligned to NIST AI RMF and OWASP LLM Top 10
  • 10+ AI-powered security tools built and deployed — 1,000+ analyses delivered
  • Security workflow automation: from scan data to executive-ready reporting

Security Tools I Use To Monitor User Behavior, Discover Vulnerabilities,
& Detect Network Anomalous Activity:

images

Microsoft Sentinel

Ivanti

elastic-logo

Elastic Security

Screenshot 2026-02-17 234214

Defender For Endpoint

AWS_GuardDuty_logo

AWS GuardDuty

wireshark

Wireshark

PRTG

Trellix

Barracuda

splunk (1)

Splunk

burp suite

Burp Suite

Tenable Nessus

Cybersecurity Awards and Honors

Recognized for excellence in cybersecurity, risk management, and compliance, these awards highlight my expertise in protecting digital assets, mitigating threats, and strengthening security frameworks.

Certified Ethical Hacker (CEH) AI Achievement

Recognized by EC-Council, this certification validates my expertise in penetration testing, ethical hacking, and AI-driven cybersecurity methodologies. This achievement demonstrates my ability to identify vulnerabilities, deploy countermeasures, simulate AI-powered cyberattacks, and actively defend networks against evolving attacks.

Governance, Risk, and Compliance (GRC) Excellence Award

This award from WGU recognizes my exemplary work in Governance, Risk, and Compliance (GRC), showcasing my ability to assess risks, implement security controls, and ensure regulatory compliance. It highlights my expertise in cybersecurity governance, policy enforcement, and risk mitigation strategies, essential for securing digital infrastructures.

My Portfolio Featuring Hands-on Projects

My portfolio features real-world labs, penetration testing exercises, and security implementations, showcasing my ability to detect, analyze, and mitigate threats in complex environments.

Azure + OpenVas for vulnerability scanning and Remediation

Developed a Live SOC W/ Real-time Threat Detection in Azure

Azure + Tenable + PowerShell for vulnerability scanning & Remediation

Proactive Threat Hunting Using MITRE ATT&CK Framework

Still Have Questions?

Thanks for taking the time to read this! If you have any other questions, email me, or find me on Linkedin

Address: 700 E. Firmin St. SUITE 99 Kokomo, Indiana 46901

Receive My CV Securely

Enter your email address to receive my CV securely. This ensures confidentiality, prevents spam, and guarantees my credentials reach the right person. Your email will only be used for this request.