View Ridge Security

About View Ridge Security

Built by a practitioner who has spent decades securing applications and cloud infrastructure.

View Ridge Security is built by Brett Bentley, CISSP/CISA, who has spent 20+ years securing SaaS infrastructure and building the systems and data pipelines that run inside them. That background shapes every engagement: practical remediation, evidence-ready outputs, and controls your team can maintain.

About the founder

Headshot of Brett Bentley, founder of View Ridge Security

Brett Bentley

Brett Bentley founded View Ridge Security after 20+ years building and securing applications, IT infrastructure, and data pipelines that organizations depend on. That dual background shapes how we work: most security advice gets written by people who have never had to maintain the thing they are recommending. We have. Our engagements deliver practical remediation, evidence-ready outputs, and controls your team can maintain.

CISSP · CISA · 20+ yrs in cybersecurity engineering and advisory

Connect on LinkedIn

View full work history on LinkedIn.

Why View Ridge

How we work

We start every engagement by understanding your actual SaaS footprint — not a questionnaire, not a maturity model, but the real accounts, apps, and access patterns running across your tenant. From there we build a roadmap that your engineering team can execute and your auditor can verify. No abstract frameworks. No prescriptive checklists that do not map to your stack. Just the controls that matter, in the order that makes sense for your risk profile.

Our commitment

We recommend and implement the controls your environment requires. Our recommendations are based on your risk profile and existing technology stack — not vendor relationships or referral incentives.

What we believe

Security should be engineered, not audited into existence. The best control is the one your team does not notice because it is built into how they already work. Practitioners — people who have configured the tenant, written the policy, investigated the incident — make better advisors than career auditors. We hire and operate accordingly.

We recommend and implement the controls your environment requires. Our recommendations are based on your risk profile and existing technology stack — not vendor relationships or referral incentives.

— View Ridge Security, zero conflicts of interest policy

Frameworks we work in

We deliver against the standards that your customers, auditors, and carriers ask about.

NIST CSF 2.0, 800-37, 800-53NIST 800-37 & 800-53CIS ControlsSOC 2 (Type 1 & Type 2)ISO 27001PCI DSSHIPAACMMC & NIST 800-171FTC Safeguards Rule

Discuss your security posture.

Schedule a 30-minute consultation. No pitch deck. We will review your current setup and provide an honest assessment.

Book a call