A security firm in one room in Columbus, since 2014.
Thornbury started with four analysts and one rule: the people who watch your network at night are the people who answer your call in the morning. Twelve years later there are twenty eight of us, still in one room.

Our building in Franklinton, a converted warehouse two blocks from the Scioto. The operations room is on the second floor.
Why one room.
Tom Brennan spent twelve years answering breach calls for insurers’ response panels. Most of the companies he met had bought good tools and signed a monitoring contract. The alert had fired at 2 am. Nobody read it until Monday.
Thornbury began in 2014 with four analysts on a converted warehouse floor in Franklinton, watching nine companies. The rule was simple: whoever watches your network at 3 am sits in the same room as the person who answers your call at 9.
Today we watch 64 companies of 200 to 2,000 people across Ohio, Indiana, Kentucky and Michigan, from the same building. We are privately owned, have never taken outside investment, and publish our prices.
Five things we will not change.
The people who lead the watches.
Six leads and twenty two analysts, all in Columbus. Every analyst holds at least one GIAC certification and passes a background check before their first watch.
Tom Brennan
Founder and incident response lead
Response
GCFA, CISSP
19 years
Spent twelve years answering breach calls for insurers’ response panels, then started Thornbury in 2014 so mid-size companies could have the same people on their side before the call.
Keisha Morrow
Head of client security
Accounts
CISM, CISSP
14 years
Runs the account leads. Every client has one named person who writes the monthly report and answers the phone.
Dana Okafor
Day watch lead
07:00 to 15:00
GCIH
11 years
Came from a regional bank’s security team. Leads seven analysts and the handover briefings at 07:00 and 15:00.
Luis Ferreira
Evening watch lead
15:00 to 23:00
GCFA
9 years
Former Army cyber operations. Covers the hours when most phishing lands and most IT teams have gone home.
Priya Raman
Night watch lead
23:00 to 07:00
GCIA
8 years
Has led the night watch since 2021 and wrote most of our Microsoft 365 detections after a year of 3 am inbox rules.
Sam Whitaker
Detection engineering lead
Engineering
GCDA
7 years
Tunes the rules so the watch sees fewer and better alerts, and owns the noise number in every monthly report.

Audited, certified and insured.
CREST accredited security operations centre, assessed in 2025
SOC 2 Type II, audited every year, report shared under NDA
ISO/IEC 27001:2022 certified security management
$5 million in cyber and professional liability cover
Every analyst background checked and GIAC certified
Thirty minutes to find out who is watching your network tonight.
Bring your last insurance questionnaire or audit finding. We tell you in plain words where you are exposed after hours and what closing it would cost, then send a written quote within two business days.