Skip to main content

Client Work

A machine shop, brought to compliance grade.

One real engagement, told the way we found it. The client is a small, high-volume precision machine shop in the defense supply chain, kept anonymous here for the obvious reasons. Everything below comes from the engagement record.

Under 20

Endpoints, one site, one Microsoft tenant

About $3k

Per month for fully managed IT and compliance support

~$3,500

Monthly savings against the previous provider, by the owner’s own invoices

110

NIST 800-171 controls, every one assigned a named owner

What We Found

The starting position.

The shop had been paying for managed IT for years. Here’s what the first real look at the environment turned up.

  • No working backup of the only server, despite the compliance record claiming an encrypted backup existed. The previous provider’s backup appliance was still in the rack, still being paid for, protecting nothing, and reachable through undocumented remote access.
  • A single domain admin account with no break-glass alternative, plus leftover admin accounts from the previous provider and the owner’s own daily-driver account.
  • Nothing published in DNS to stop anyone on the internet from forging the company’s email domain, and legacy mail protocols left open.
  • A remediation plan of more than 70 items that was wrong in both directions: items marked closed that were never fixed, and items marked open that already were.
  • No environment documentation at all. Passwords, licenses, and configurations lived in people’s heads.

What Changed

The work, in order.

Documentation before hardening, a working backup before anything risky, and dated evidence behind every change.

  • Documented everything first: full inventory of the environment, network, and compliance scope, then a dated baseline so every later change is provable.
  • Cleaned the admin surface: leftover provider access verified gone, least-privilege admin established, MFA enforced across the tenant.
  • Moved every workstation to modern cloud management with monitoring and patching agents across the fleet.
  • Told the client, in writing, that their compliance record overstated their backup posture, and scoped the real fix with evidence attached.
  • Mapped all 110 NIST 800-171 controls to a named owner, so the path to a CMMC assessment is a checklist with prices, and the remediation roadmap is costed and in motion.

Tested Live

A phishing attempt hit mid-2026.

The MFA rollout held and nothing was lost. Tenant-wide hardening went on the same day, inside the monthly fee.

Told Straight

The record got corrected.

When the compliance paperwork claimed a backup that didn’t exist, the client heard it from us in writing before an assessor could find it.

Where It Stands

On a costed path to CMMC readiness.

Full control ownership mapped, remediation scoped and priced with hard ceilings, and evidence designed for the assessor’s pipeline.

Next Step

Want the same first look at your environment?

Every engagement here starts the same way this one did: with an honest, documented picture of where you actually stand.

Prefer the phone? +1 (402) 819-7177