Stellaria Labs
Currently booked · scoping ahead

Security programs that scale

Risk-based governance, compliance, and roadmapping for organizations building a security function that can prove it works.

Program readinessPCI-DSS v4.0
Scope & data flow92%
Access control74%
Logging & monitoring48%
Vendor management31%
Sample dashboard from a live engagement. Every client gets this view from week two, tailored to what matters most.
Engagements

Selected recent and current work

A sample of recent engagements, not a full client list. Names withheld — happy to talk through any of these in detail on a call.

Delivered
Nonprofit

PCI-DSS compliance program for a regional nonprofit — cardholder data scope narrowed to keep the burden off their technology and business teams, with compliance achieved against the acquirer's requirements

Delivered
Healthcare

FAIR-based security risk management program and roadmap for a large regional healthcare organization, integrated with their existing asset inventory and incident response systems

Active
Financial services

vCISO for a mid-sized investment firm — building the governance framework and lifecycle, driving third-party risk management, and maturing the program toward RIA compliance

Active
Defense industrial base

CMMC program advisory for a defense industry startup — ensuring the compliance investment produces durable security value rather than an audit artifact

Active
Nonprofit

Strategic planning lifecycle for a regional nonprofit's technology organization — aligning quarterly prioritization, resource capacity, and measurable outcomes that surface in monthly business reviews

Services

Three ways engagements start

Most clients begin with an assessment and continue into program work. Scope is set in the first call.

01 / Build

Security Program Development

Program designResourcingvCISO

Build your security roadmap from the ground up, using risk-based approaches to resource allocation. Together, we'll define the right scope and structure for your security function, ensuring decisions are grounded in business reality rather than checkbox compliance.

02 / Govern

Governance & Frameworks

PCI-DSSSOC 2NIST · ISO · CIS

Navigate PCI-DSS compliance and other regulatory requirements with frameworks that guide rather than constrain. Implement NIST, ISO, and CIS standards, and create governance structures that let your team make smart, consistent security decisions.

03 / Measure

Program Assessment & Roadmap

Maturity baselineRoadmapBoard reporting

Evaluate your current security maturity and develop practical improvement plans. Understand where you are, define where you need to be, and build sustainable programs that grow with you.

About

An independent security practice, built on Fortune 500 experience

Stellaria Labs is an independent security consultancy working with executives and security leaders on governance, risk, and compliance. Engagements are hands-on: scoping, framework implementation, roadmap design, and the ongoing decisions in between.

The GRC discipline transfers beyond security. Risk-based prioritization, resource capacity, and measurable outcomes are the same machinery whether the subject is a controls program or a technology portfolio — which is why some engagements reach into strategic planning for technology organizations.

Remote-first, on-site for key meetings and strategic sessions. Based in West Lafayette, Indiana, working with clients across the United States.

Frameworks
PCI-DSS v4.0 NIST CSF NIST 800-53 NIST SP800-37 FAIR ISO 27001 CIS Controls SOC 2 Sarbanes-Oxley
A selection — ask about anything not listed here.
Sectors worked
NonprofitHealthcareFinancial servicesTechnology / SoftwareDefense industrial baseRetail
Elliot Harbin Founder · fifteen years in Fortune 500 security leadership

I spent fifteen years building security programs inside Fortune 500 companies before starting Stellaria Labs. Most recently I served as Interim CISO at Nordstrom, leading a 100-plus person security organization and reporting to the Board of Directors on posture, maturity and strategic investment. Before that I built the company's GRC function from scratch — a thirty-person organization running PCI, SOX, SOC 2 and HIPAA certification on a single common control framework, alongside the enterprise risk methodology and third-party assurance programs. Earlier, at Microsoft, I owned security policy and risk management for the cloud infrastructure behind Microsoft's online services.

I started Stellaria Labs in 2026 to bring that experience to organizations building a security program for the first time — designing and standing up a program mature enough that their own team can run it once I step back.

Contact

Let's talk about your program

A scoping call runs about thirty minutes: where you are, what's driving the timeline, and whether this is a fit.

I'm currently booked, with capacity opening in roughly two to four months. Scoping conversations typically happen well ahead of a start date, so if you're planning a program for later this year it's worth talking now.

Location West Lafayette, IN · remote-first, on-site for key sessions
Get in touch

Send a note with your timeline and current state, and I'll reply within one business day.

Email stellaria@stellaria.io
What's driving this
Opens your mail app with this filled in — nothing is sent from the page.