// MD

Cybersecurity services in Baltimore.

Secuur provides security testing to Baltimore, Maryland organisations across defense and government contracting, healthcare and health systems, biotech and life sciences. Maryland requires breach notification no later than 45 days, and MODPA is in force. Every engagement includes an A–F post-quantum readiness grade.

The Baltimore risk profile

Baltimore is a federal cybersecurity and intelligence corridor adjacent to major academic medical and research institutions. Security work here is shaped by that mix more than by anything generic about company size or headcount.

Defense and government contracting

Contractors and subcontractors are attacked as the soft route to information the prime is defending properly. Controlled Unclassified Information sitting in an engineering share, a supplier portal or an email archive is the objective, and the adversary is patient, well-resourced and specifically interested in persistence rather than immediate extraction.

Healthcare and health systems

Healthcare is the sector where a security failure becomes a clinical failure. Ransomware against a hospital does not merely encrypt files; it diverts ambulances and delays procedures. The pressure to restore service fast is precisely what makes healthcare a profitable target, and the sprawl of clinical devices, imaging systems and third-party portals gives an attacker unusually many ways in.

Biotech and life sciences

The asset is intellectual property with a decade-long development cycle: assay data, trial results, manufacturing process detail. The adversary is frequently seeking a research advantage rather than a payday, which changes the profile — the goal is quiet persistence and exfiltration, not disruption you would notice.

What Maryland law expects of you

Security testing is not a compliance exercise, but in Maryland the legal clock is what turns an unnoticed weakness into a reportable event with a deadline attached. Knowing the timeline in advance is what lets you decide how fast findings need to be remediated.

ObligationRequirement in Maryland
Consumer notification deadlineno later than 45 days
Regulator notificationAG must be notified before consumers are.
Comprehensive privacy statuteMaryland Online Data Privacy Act (MODPA) — in effect

MODPA imposes strict data-minimisation duties that go beyond the Virginia template most states copied.

The practical consequence for Baltimore businesses is straightforward: a breach you discover on a Friday starts a clock that runs in calendar days, not business days. Testing exists to find the exposure before that clock ever starts — and to give you documented evidence of diligence if it does.

This is general information, not legal advice. Statutory requirements change and their application depends on your specific facts. Confirm current obligations with Maryland counsel before relying on any timeline here.

Services available in Baltimore