OTS Helps Specialty Contractor Go from Red to Green and Land a $3MM Utility Contract

Intro
A specialty contractor was chasing work with a major utility. Then the utility’s cybersecurity review came back Red.
Red meant critical findings were open, and a $3 million contract wasn’t going anywhere until they were closed. About two months and just under $20,000 later, the same reviewer confirmed Green, and the contract was theirs.
Client Background
The company is a mid-sized specialty contractor. Like a lot of growing contractors, its technology grew alongside the business rather than by design. Some security controls were in place. Others lived in people’s heads. Very little of it was written down in a way an outside reviewer could check.
That works fine until a large customer sends a security assessment and wants proof.
Problems Experienced
The utility sorts its vendors into three buckets:
- Red: critical findings open
- Yellow: some medium or high findings remain
- Green: required findings resolved and accepted
Several critical findings put the company squarely in Red, and that status was holding it up in the procurement process.
When we looked closer, the picture was more mixed than the score suggested. There were real technical gaps: stale privileged accounts, MFA that wasn’t consistently enforced, guest access that needed review, and legacy systems adding risk. But a big share of the problem was that controls already in place weren’t documented, security policies were incomplete or informal, and the evidence an assessor needs to see was scattered or missing.
Solutions Implemented
We didn’t treat this as a questionnaire to fill out. It was assessment, evidence, and remediation, run together.
Discovery. We reviewed the original findings and the company’s earlier responses, then worked through the infrastructure, the Microsoft 365 environment, existing policies, and day-to-day practices. We interviewed key people to learn how the business actually ran, which wasn’t always what the paperwork said.
Evidence. Plenty of controls were already doing their job. We mapped every requirement to proof, including system configurations, security reports, monitoring output, and administrative controls, so existing investments got credit instead of being scored as missing.
Remediation. We built a roadmap that went after the findings most likely to move the status first. That included:
- a full policy framework covering information security, risk management, incident response, business continuity, governance, and data protection
- a formal security awareness and phishing training program
- administrative account review, MFA validation, and a documented access inventory, including third-party access
- network segmentation recommendations and isolation of legacy systems
- logging, monitoring, DNS, and email security improvements
Everything was packaged into response matrices, policy documents, screenshots, and remediation schedules the utility could evaluate directly.
Results
On the final review, the assessor confirmed every required action item was satisfied and no further submissions were needed. The company moved from Red to Green for the project, and its next review was pushed out to a future assessment cycle.
The math is simple. The company spent just under $20,000 on reassessment and remediation and landed a $3 million contract. That’s roughly a 150-to-1 return, before counting the next opportunity that asks for the same proof.
It also came out with things it didn’t have before: a documented security program, clear ownership of security responsibilities, a risk register, formal incident response and governance processes, and a roadmap for what comes next. The next assessment, from this utility or anyone else, starts from a much stronger position.
Most companies that get a bad score on a vendor security review don’t have a security crisis. They have documentation gaps, evidence gaps, and a handful of real technical issues. All of that is fixable.
If a customer’s security review is standing between you and a contract, talk to us. You can also read more about our managed cybersecurity services.