OTS Helps Specialty Contractor Go from Red to Green and Land a $3MM Utility Contract

Open Tier Systems case study graphic for a specialty contractor

Intro

A specialty contractor was chasing work with a major utility. Then the utility’s cybersecurity review came back Red.

Red meant critical findings were open, and a $3 million contract wasn’t going anywhere until they were closed. About two months and just under $20,000 later, the same reviewer confirmed Green, and the contract was theirs.

Client Background

The company is a mid-sized specialty contractor. Like a lot of growing contractors, its technology grew alongside the business rather than by design. Some security controls were in place. Others lived in people’s heads. Very little of it was written down in a way an outside reviewer could check.

That works fine until a large customer sends a security assessment and wants proof.

Problems Experienced

The utility sorts its vendors into three buckets:

  • Red: critical findings open
  • Yellow: some medium or high findings remain
  • Green: required findings resolved and accepted

Several critical findings put the company squarely in Red, and that status was holding it up in the procurement process.

When we looked closer, the picture was more mixed than the score suggested. There were real technical gaps: stale privileged accounts, MFA that wasn’t consistently enforced, guest access that needed review, and legacy systems adding risk. But a big share of the problem was that controls already in place weren’t documented, security policies were incomplete or informal, and the evidence an assessor needs to see was scattered or missing.

Solutions Implemented

We didn’t treat this as a questionnaire to fill out. It was assessment, evidence, and remediation, run together.

Discovery. We reviewed the original findings and the company’s earlier responses, then worked through the infrastructure, the Microsoft 365 environment, existing policies, and day-to-day practices. We interviewed key people to learn how the business actually ran, which wasn’t always what the paperwork said.

Evidence. Plenty of controls were already doing their job. We mapped every requirement to proof, including system configurations, security reports, monitoring output, and administrative controls, so existing investments got credit instead of being scored as missing.

Remediation. We built a roadmap that went after the findings most likely to move the status first. That included:

  • a full policy framework covering information security, risk management, incident response, business continuity, governance, and data protection
  • a formal security awareness and phishing training program
  • administrative account review, MFA validation, and a documented access inventory, including third-party access
  • network segmentation recommendations and isolation of legacy systems
  • logging, monitoring, DNS, and email security improvements

Everything was packaged into response matrices, policy documents, screenshots, and remediation schedules the utility could evaluate directly.

Results

On the final review, the assessor confirmed every required action item was satisfied and no further submissions were needed. The company moved from Red to Green for the project, and its next review was pushed out to a future assessment cycle.

The math is simple. The company spent just under $20,000 on reassessment and remediation and landed a $3 million contract. That’s roughly a 150-to-1 return, before counting the next opportunity that asks for the same proof.

It also came out with things it didn’t have before: a documented security program, clear ownership of security responsibilities, a risk register, formal incident response and governance processes, and a roadmap for what comes next. The next assessment, from this utility or anyone else, starts from a much stronger position.

Most companies that get a bad score on a vendor security review don’t have a security crisis. They have documentation gaps, evidence gaps, and a handful of real technical issues. All of that is fixable.

If a customer’s security review is standing between you and a contract, talk to us. You can also read more about our managed cybersecurity services.

About The Author

Brian McCarthy

Share This Post

Post Meta

Table Of Contents

Recent Posts

Featured Review

testimonial

Tortoise and Hare has been a key partner in our MSP's growth. Over the year's we've worked together they've helped our MSP dramatically increase our website traffic, and build a steady stream of leads sourced from our website and advertising efforts. Over that time, we've been able to raise our base customer size, build economies of scale to more efficiently service customers, and expand into new markets.

R.D.
President Regional MSP

Open Tier Systems

We Get IT Done
IT For Eastern Pennsylvania Businesses
Home » Blog » OTS Helps Specialty Contractor Go from Red to Green and Land a $3MM Utility Contract

Visit Us On Social Media

More About Our Open Tier Systems

Managed IT, Voice, AI and Compliance

Locations We Serve

Policies and Terms

Proudly Serving The State Of Pennsylvania

© 2018-2026 Open Tier Systems. All Rights Reserved.
This site content may not be copied, reproduced, or redistributed without the prior written permission of Open Tier Systems or its affiliates.