Independent cybersecurity and governance advisory for healthcare practices and mission-driven organizations.

No IT services to sell. No referral fees. No vendor partnerships shaping the answer.

FOUNDER INTRODUCTION

Hi. Tom Polk here. I spent 30+ years in IT. I ran an IT company from 1992 to 2016, then served as CIO and Chief Security Officer at a multi-state eyecare group. I founded Northline Advisors to do something I couldn’t do from inside an executive seat: tell small organizations exactly what I see, without worrying about whose budget it comes out of.

I built Northline on a simple idea: the organizations people count on deserve someone in their corner who isn’t selling them anything. That started with the healthcare practices near me in Indiana. It’s the same standard I bring to nonprofits and practices anywhere, delivered remotely, wherever you are.

Your policies and evidence come to you as documents you own, in a folder you control. Nothing expires and there is no subscription to keep paying. If you want the work tracked in a platform month to month, that comes with the retainer.

What I don’t sell: security products, IT services, insurance or anything I’d earn a referral fee on.

WHAT I HEAR FROM OWNERS AND DIRECTORS

“If we get breached, my name is on the door. I don’t know what ‘good enough’ even looks like.”

“A funder asked how we protect donor data. I didn't have an answer."

“We’ve grown. Our security hasn’t kept up.”

“I trust our IT company, but I have no idea if we’re actually compliant.”

Here’s the problem: most IT providers aren’t lying to you. I ran one for 24 years, so I know how it happens. They genuinely believe what they’re telling you. But a lot of what passes for “security” in a small company is the IT equivalent of shooting the side of a barn, drawing a circle around the hole, and calling it a bullseye. They do what they do, slap a label on it, and call it good. Nobody’s checked whether any of it lines up with what is actually needed, or what a real attacker would actually try.

“That’s not security. That’s just a good-looking hole in the barn.”

HOW I WORK WITH CLIENTS

Most engagements start with a low-cost entry point. A Security Snapshot, an IT Provider Review, or a Cyber Insurance Application Review. You get an honest picture of where things stand, and we go from there at whatever pace makes sense for you.

For organizations ready to go deeper, I offer a Defensible Risk Assessment, Governance Implementation Sprint, and ongoing security leadership (vCISO) retainer. Every deliverable is plain-language and built to actually be used. Ranked priorities, clear ownership, and a roadmap your team can execute without a PhD in cybersecurity.

WHO NORTHLINE IS A FIT FOR

Northline is built for a specific kind of client. If the description below sounds like you, we should talk. If it doesn’t, I’ll happily point you toward someone better suited.

  • Independent or small-group healthcare practices, including medical, dental, optometric, behavioral, and specialty

  • Nonprofits and mission-driven organizations, including foundations, free clinics, community-serving and faith-based groups handling donor, client, or patient data

  • Owners, executive directors, and boards asking real questions about breach exposure, cyber insurance, grant and funder security requirements, or HIPAA, not just chasing a checkbox

  • Organizations that want someone checking the security who has no stake in what it costs to fix

  • Delivered remotely nationwide; on-site available regionally

CREDENTIALS

CISSP

Certified Information Systems Security Professional. The main general security certification.

CCSP

Certified Cloud Security Professional. Cloud architecture, governance, and risk.

CGRC

Certified in Governance, Risk and Compliance. Authorization frameworks, risk management, continuous monitoring.

ProSci Change Practitioner

Structured change management for security and governance rollouts that actually stick.

BEYOND CONSULTING

My work outside Northline shapes how I work inside it.

I don’t just advise mission-driven organizations. I’ve sat on their boards and run their committees. As Past District Governor of Lions Clubs International District 25-G, and through board and committee service with 85 Hope Free Medical Clinic and VisionFirst (the Indiana Lions Eye Bank), I’ve lived what nonprofits deal with: lean budgets, volunteer turnover, donor trust, and no room for a breach. The same principle runs through all of it. Do the work, document it honestly, and leave things better than you found them.

My wife Kim and I live in the LaFontaine area of Indiana. The roots matter: they’re where I learned that the organizations people count on rarely have someone independent looking out for them. That’s the job, wherever the client happens to be.

An outside look at your security. Because you can't afford to guess.

READY FOR A STRAIGHT ANSWER?

If you’re a practice owner or a nonprofit leader asking “Are we actually protected?” Let’s talk. Thirty minutes, no pitch, no pressure. We’ll walk through what you’re actually worried about and whether Northline is the right fit. If we’re not, I’ll point you toward who is.

© 2026 NORTHLINE ADVISORS, LLC