Security Analysts

How to start a cybersecurity consulting business on the side

Security skills sell well to small businesses, startups and training buyers who cannot hire a full-time analyst. Most people start with one narrow service for one kind of client, then grow from what clients ask for next.

Two rules come first. Only test systems you have written permission to test, and check your employer's outside-work and conflict-of-interest policy before you take a single client. This is general information, not legal or financial advice.

Talk to Carmen

Your AI career coach

Say it the way you’d say it to a friend. Carmen will ask what she needs to know.

Free, no sign-up to start.

$129,180 a year

Median information security analyst pay, May 2025

BLS Occupational Outlook Handbook

6%

Share of information security analyst jobs in management, scientific, and technical consulting services

BLS Occupational Outlook Handbook

Side businesses security analysts start

  • Vulnerability assessments for small businesses

    Reviewing a small company's external exposure, patching, backups, MFA and email security, then handing over a plain-language list of fixes. Suits analysts who explain risk well to people who are not technical.

    What it takes
    A signed scope and written authorization for every engagement. Many consultants also carry professional liability insurance; ask a local advisor what fits.
    First step
    Write a one-page checklist of what you would review for a ten-person office, and offer it to one business you know, with a written authorization form ready.
  • Security awareness training

    Short sessions for staff on phishing, passwords, MFA and reporting. Suits analysts who present well and have real examples from the queue (with anything identifying removed).

    First step
    Build a thirty-minute phishing talk using public examples and offer to run it for a local business group or nonprofit.
  • Compliance readiness help

    Helping a startup or clinic prepare for a framework such as SOC 2 or HIPAA: gap assessments, policies, evidence collection. You help them get ready. You do not certify, attest or issue audit reports, and you should say so in writing.

    What it takes
    Solid framework knowledge. Suits analysts with GRC or audit exposure.
    First step
    Draft a gap-assessment template for one framework you know well and state clearly in it what the engagement does not include.
  • Bug bounties

    Finding and reporting vulnerabilities through programs run on platforms such as HackerOne or Bugcrowd. Income is uneven and competitive. Each program sets its own scope and rules, and anything outside scope is off limits.

    What it takes
    Time and practice. Read each program's policy page in full before testing anything.
    First step
    Pick one public program, read its scope and rules twice, and spend a weekend on recon only, taking notes.
  • Teaching and content

    Tutoring people breaking into security, teaching evening courses, writing guides or making videos. Suits analysts who like explaining the basics and are patient with beginners.

    First step
    Write a guide to one thing you wish you had known as a new L1 and share it where people breaking into security gather.
  • Fractional security for startups

    A few hours a week as a startup's part-time security lead: access reviews, vendor questionnaires, basic policies, incident plans. Suits experienced analysts who can work without a team around them.

    What it takes
    Usually needs several years of broad experience. Watch conflict-of-interest rules closely if the startup overlaps with your employer's market.
    First step
    List the five security questions early startups get from enterprise customers and write how you would answer each for a small team.

Sample conversation

How a conversation with Carmen starts

Carmen asks before she suggests. An illustrative example, not a real person.

I want to do some security consulting on weekends. Small businesses near me have nothing in place.

That is a real gap. Before clients, have you checked your employer's policy on outside work?

Not yet. I figured it was fine if it's not the same industry.

Worth confirming in writing first. Then let's pick one service, like a basic assessment for small offices, and write down exactly what it covers.

Work it out with Carmen, free

30 free minutes with Carmen and the team. No card needed.

Questions & answers

Can I start a cybersecurity consulting business while working full time?
Many people do, but check your employer's outside-work and conflict-of-interest policy first, and keep client work off company time and equipment. This is general information, not legal or financial advice.
Do I need permission to run a vulnerability assessment?
Yes. Only test systems you have written permission to test, from someone with the authority to give it, and keep to the agreed scope. Testing without authorization can be illegal even if you mean well.
Can I certify a company for SOC 2 or HIPAA?
No. SOC 2 reports are issued by independent auditors, and no consultant can certify HIPAA compliance for a client. You can help a company prepare, and you should state that limit clearly in your agreement.
What is the easiest cybersecurity side hustle to start?
Awareness training and teaching need the least setup and carry little testing risk. Assessments and fractional work pay off more of your experience but need written scopes and more care.

More for security analysts

Start or grow a business