Randy Steinle’s company started with a carrot, matured under a stick, and found its purpose in a badly served middle. In 2012, Steinle and his longtime business partner Chris Canada joined the Texas Organization of Rural and Community Hospitals on a federal “Meaningful Use” program. Hospitals needed annual security risk assessments to qualify for incentive payments. The work was technical, repetitive, and consequential. It was also an unusually good perch from which to watch a market fail in real time.

Steinle’s team helped more than 50 hospitals through the process. When the incentive money began to run out, the compliance obligation did not. The carrot of payment was giving way to the stick of penalties, as he later put it. Smaller organizations still had to understand their exposure, update policies, train staff, and demonstrate that the work had happened. Their choices were awkward: a do-it-yourself product that left them alone with the problem, or a consulting engagement priced for a much larger institution.

The gap was not a lack of checklists. It was a lack of company. Busy teams needed judgment, explanation, and somebody to keep the project moving. They also needed the economics and consistency of software. Cyber Trust Alliance grew from that observation.

50+Hospitals assisted in the early TORCH program
2012The rural-hospital work that exposed the gap
2024CorePLUS acquired Cyber Trust Alliance
The long apprenticeship

First, learn how partners work

Steinle did not arrive at software through a sudden affection for dashboards. His apprenticeship was in the practical machinery of technology services: sales, operations, client work, and alliances. Public biographies describe more than two decades managing service providers. At Onsupport, an Austin managed-services and cloud firm, he led business development and built partnerships. In a 2014 discussion about a Dell cloud platform, he praised the ability to customize services without buying and maintaining all the infrastructure underneath. The principle would return later: borrow scale where it helps, preserve the part the customer values.

He also spent years in the International Association of Microsoft Channel Partners. With local peers, he helped form the Austin chapter. He went on to serve in roles across the US board, including president and past president, and later chaired a committee designed to connect Microsoft and its partner community. The titles can sound ceremonial until you notice the pattern. Steinle kept choosing jobs that required independent organizations to coordinate without pretending they had become one organization.

That instinct shaped Cyber Trust Alliance. The company assembled a national partner network instead of attempting to own every customer relationship or specialty. Steinle’s public advice to small businesses is equally direct: find people you trust, clarify who owns what, and document the work. Partnership, in his telling, lets specialists remain specialists. A clinical team should not have to become a security consultancy after lunch.

Getting caught doing the right things.Randy Steinle on why documentation matters

It is a pleasingly mischievous phrase for a dull necessity. Documentation is usually presented as the bureaucratic tax at the end of useful work. Steinle flips it into evidence. Training completed, patches applied, risks reviewed, policies approved: good intentions become defensible only when another person can see what happened.

The product

Keep the humans, remove the repetition

Cyber Trust Alliance built its model around that evidence. Human assessors would evaluate risk. Virtual “Telassessment” delivery would lower the travel and interruption costs. Compliance coaches would meet with clients and keep the work from dying in a forgotten folder. The CEBA software would hold training, policy templates, findings, remediation plans, and a dashboard of progress.

The arrangement is less romantic than replacing every consultant with a robot, and considerably more considerate. It recognizes that software is good at memory, standardization, reminders, and display. People remain useful for interpretation, persuasion, and the uncomfortable moment when a red finding needs an owner.

Steinle was equally deliberate about packaging. Required parts of the work belonged in the subscription, he argued, rather than arriving later as unpleasant additions to the invoice. A dashboard gave a busy administrator the view at a glance. Templates removed the tyranny of the blank page. Regular coaching created a rhythm. The product’s real feature was not any single module. It was continuity.

Randy Steinle standing at the CorePLUS Technologies booth during the TORCH Spring Conference
Booth duty, but make it useful: Steinle with HEALTHSecure+ at the TORCH Spring Conference in Arlington, Texas, in April 2025.
The risk

Every secured network still has people in it

Steinle’s public cybersecurity guidance is suspicious of solving security through spending alone. Organizations can invest heavily in network controls and still leave the ordinary person at a laptop unprepared for a convincing message. His warning is compact: “Humans are still our number one threat.” It is not contempt for users. It is an argument for training them.

His practical list begins where many sensible lists begin: teach people to recognize phishing and ransomware, keep systems patched, use professional email services, and require multi-factor authentication. Then document the work. A penetration test, in his account, should not finish with an impressive pile of possible problems. Findings need to be sorted by likelihood and impact, tested where appropriate, and converted into a remediation roadmap.

That bias toward translation became more visible as Cyber Trust Alliance moved from compliance software toward broader risk assessment. Technical findings had to connect with operational and business consequences. In January 2026, when the company announced a partnership with HANYS Marketplace for hospitals across New York, Steinle focused on visibility. Many organizations, he said, could not see where their greatest exposures were. The promised output was not simply another control inventory. It was an actionable ordering of risk.

His view of artificial intelligence is similarly measured. In a 2024 interview, Steinle called AI and machine learning a double-edged sword. Better tools can strengthen defense; the same capabilities can make attacks more credible and help attackers probe for weakness. He saw potential and urged care. Enthusiasm, in this corner of technology, benefits from a seat belt.

The next chapter

An acquisition, then a wider circle

CorePLUS Technologies acquired Cyber Trust Alliance in August 2024, folding its assessment tools and methods into the HEALTHSecure+ platform. Steinle described the deal as a way to pursue a shared vision for healthcare security. Publicly, he moved into an executive vice president role with CorePLUS while continuing to appear as Cyber Trust Alliance’s CEO and co-founder. At conferences, the two stories now share a booth.

The TORCH engagement reveals the underserved middle in security risk assessments.

IAMCP Women in Technology names Steinle its Man of WIT, recognizing his work as an agent of change.

CorePLUS Technologies acquires Cyber Trust Alliance and integrates its tools into HEALTHSecure+.

A HANYS Marketplace partnership brings the company’s risk-assessment approach to New York hospitals.

The transaction did not end the partnership habit. Steinle joined advisory boards for the Central Texas chapter of HIMSS and Mona Lisa Healthcare in 2024. In 2026, he was listed among advisors supporting rural health transformation work. Cyber Trust Alliance’s collaboration with HANYS Marketplace extended a route first tested in Texas: work through an institution that hospitals already know, then translate specialist knowledge into a manageable program.

There is a personal symmetry here. Steinle studied at Wheaton College from 1985 to 1989, played soccer, and served as a student teacher in business law. Decades later, public recommendations still describe him as teacher-minded. His operating style seems to prefer explanation over mystique. Even the compliance product was built to show people where they stood instead of preserving the consultant’s aura.

His public biography for Voices for Innovation opens somewhere less corporate. Before job titles, it names his wife, Beth, and their four children. That ordering offers a useful glimpse of a person whose résumé otherwise moves through boards, platforms, assessments, and partner programs. The same biography places him in a regional technology firm serving small and midsize clients, not in a distant laboratory of grand theories. His career has been built close to the customer, where a fine strategic sentence eventually meets somebody’s Tuesday afternoon.

Soccer also supplies a modest metaphor, if one is careful with it. The sport rewards the pass that creates the next pass, and much of Steinle’s professional life has involved arranging exactly that sort of movement. A Microsoft partner finds another partner. A hospital association connects its members with a specialist. An assessor identifies a risk, a coach finds an owner, and software keeps the next action from disappearing. No single touch is the whole play. Progress depends on the handoff.

This may be the reusable idea in his career. Partnerships are not merely a distribution channel, software is not merely labor reduction, and documentation is not merely paperwork. Each can turn invisible effort into something another person can understand and continue. The founder’s work was to arrange them in the right order.

Cybersecurity will keep producing new acronyms, new threats, and new reasons for an anxious executive to buy a thick report. Steinle’s answer is quieter: make the risk visible, make the next step clear, keep a knowledgeable person in the loop, and leave evidence behind. A paper chase becomes a working system when somebody can finally see where it goes.