Case study · Manufacturing
The price was higher than they expected. They signed for five years anyway.
This is the most useful story we have, partly because the beginning did not go smoothly. Details are anonymized. Every number is real.
- Security failures found
- 93
- Computers across 3 buildings
- 40
- Agreement signed
- 5 yr
- To rebuild their critical app
- ~6 wk
How they found us
Through a conversation that went nowhere. Someone had been talking to us about a job opening; we both concluded it was not the right role, and the conversation ended pleasantly. They mentioned a company they knew that needed a new IT person.
That company had internal IT staff who were causing problems the leadership could not evaluate. They needed it solved and did not know how to judge whether it was being solved.
The awkward start
The first meeting with their chief operating officer did not go especially well. There was, we will admit plainly, a misunderstanding about our pricing early on. What kept the conversation alive was not our sales process. It was that the COO liked how we talked about their business rather than about technology.
They bought the assessment.
What we found
Forty computers. Four physical servers plus several virtual machines. Three buildings and a set of remote users. Twenty-four days of technical scanning, plus interviews with leadership and staff.
We documented 93 security failures.
They clustered into five themes:
- Identity and access controls were fundamentally weak
- Email and Microsoft 365 were high-risk single points of failure
- Operations would stop completely during a cyber or IT incident
- Security policies and incident response were largely informal
- Critical systems depended on ageing, unsupported, or custom technology
Specifics included storage volumes with no encryption, Microsoft 365 backed up to a local device with no testing procedure, backups requiring someone to manually rotate an external hard drive, an incident response plan that existed but only at a high level, and minimal configuration control across the estate.
That last theme, critical systems depending on ageing custom technology, turned out to matter more than anyone realised at the time.
The briefing
We presented to the COO, the CEO, and the CFO. About an hour, walking through what we found, what it would cost them if exploited, and what we would do in the first 30, 90, and 180 days.
Then the price: $10,734 per month on a 36-month agreement, plus $9,800 one-time onboarding, which included two replacement computers.
It was higher than they expected. That was our fault as much as theirs. We had not set expectations well enough early on, and the one-time onboarding figure in particular is the kind of number that lands badly when it appears at the end rather than the beginning.
They signed anyway, and not for three years. They signed for five.
This deal is the reason our pricing page publishes real numbers, including the onboarding fee. Nobody should meet that figure for the first time in a presentation.
Then the part nobody planned
Once we were managing their systems, we understood the business properly, including the tool that quietly ran their production floor.
They personalise products with laser engraving. A small application took a spreadsheet of customer names, applied each to the correct design template, and passed the result to the engraver. It saved an enormous amount of manual work.
It ran on exactly one computer. New products and templates could not be added. The employee who wrote it had left years earlier.
They had already tried to fix this. A traditional development firm had taken the project on, and after tens of thousands of dollars and several years, they had nothing they could use.
We rewrote it. Improved it. Made it run on any modern system, and made new templates something their own team could add. Working software in about six weeks.
The reason it went quickly is not that we are better developers than the firm that failed. It is that we already knew the business. We knew the workflow, the file formats, the machines, and who to ask when a question came up. A development firm starting cold spends its first months learning what we already knew, and that is where those budgets go.
Where it stands
Six months into a five-year agreement, and they are happy. What began as a slightly awkward sales conversation became managed security across three buildings and a rebuild of the software their production depends on.
What we would do differently
Set the pricing expectation in the first conversation rather than the fourth. The assessment findings justified the number, but a buyer should arrive at the briefing already knowing the range, the presentation should be about risk, not about recovering from surprise.
That single lesson is why our pricing page exists in the form it does.
The next step
Their assessment found 93 things. What would yours find?
Start with the free version, nine areas, three minutes, no email address. Or book fifteen minutes and we will tell you honestly whether a full assessment is worth it for a business your size.
No pitch on the first call. If we are not a fit, we will say so and point you somewhere better.