Helping You Forge Automated
Cybersecurity Capabilities
TRUSTED I EXPERIENCED I RESULTS-DRIVEN
Our Services
Proposal Support
Does your must-win proposal have an cybersecurity automation requirement? Would that be a discriminator?
We have excellent win-rate architecting cybersecurity responses.

OSCAL Enablement
Trying to incorporate OSCAL into your cybersecurity strategy?
Let the co-author of the OSCAL specification help you determine the best starting point and approach for your organization.
OSCAL Education and Training
Standard and custom cybersecurity and OSCAL training available for your sales, proposal and technical teams.
OSCAL Content Creation
Share 100% Compliant, industry-aligned OSCAL content with your stakeholders.

FISMA/FedRAMP/CMMC Alignment
Unlock a massive market by embracing Federal cybersecurity requirements or improve your existing capabilities to achieve better margins and expand your customer base. We can help you reach these goals faster and more efficiently.

Solution Architecture
From enterprise harmonization to point-solutions, we help you understand options, design solutions, and ensure implementation efforts remain on target.
Our product agnostic approach ensures we work in your best interest.
Our Clients
Strategic Design
Sensible Implementation
Our solutions start out aspirational and are aligned to the realities of your scope and resources. Our unique mix of experience with enterprise IT and cyber operations, regulatory compliance, standards alignment, process improvement, and system development methodologies ensure you experience benefits as soon as possible and to the greatest degree practical.
Ready for the next steps?
Contact us for a free consultation.
Let's discuss your goals and determine how we can best help you!
Meet Brian
Brian is the architect and co-creator of the Open Security Controls Assessment Language (OSCAL) and inaugural chair of the OSCAL Foundation. His achievements are built on 35 years of experience with information technology (IT), quality management, business process re-engineering (BPR), and cyber solution architecture. In 2024 Brian started Ruf Risk to focus on his passion for serving organizations as they seek to enhance their cybersecurity practices.
News and Updates
Published! Multi-Cloud Architecture Challenges
August 25, 2026 We are excited to announce the DRAFT publication of NIST IR 8613, Multi-Cloud Architecture Challenges, which is out for public review and comment! Brian Ruf serves as a co-chair for the Multi-Cloud Security Public Working Group (MCSPWG), where he...
The Python OSCAL Library
August 15, 2026 Ruf Risk is excited to announce Version 3.1.0 of the Python OSCAL Library! Now with advanced import handling and profile processing!Brian first conceived of this library in 2020, and has been actively developing it over the past few years. Earlier...
First OSCAL-Based PCI Report
January 13, 2026 It was an honor to provide OSCAL advising and implementation support for AWS as they became the first organization to publish a compliance report in OSCAL format. The AWS Fall Payment Card Industry (PCI) Data Security Standard (DSS) Attestation of...





