// CASE STUDY · DEFENCE AND AEROSPACE MANUFACTURING
Small-business IT to CMMC and NIST SP 800-171 readiness, as fractional CTO and CISO
- vCTO / vCISO engagement
- CMMC + NIST SP 800-171
- Defence supply chain
The problem
A manufacturer supplying wiring harnesses into armoured vehicle and military aircraft programs had standard small-business IT and no information security function. The defence supply chain requirements they were being held to were a long way from where they were.
What I did
- Took a combined fractional CTO and CISO role, covering both the technology direction and the security function.
- Re-architected the infrastructure so it could support controlled unclassified information handling rather than being retrofitted around it.
- Built the policy set and put the controls in place against CMMC and NIST SP 800-171.
- Moved the organization from typical small-business practice to a defensible, documented control set with the evidence behind it.
Where it landed
A defence supplier that went from no information security programme to CMMC and NIST SP 800-171 ready, with the architecture, policies, and controls to support the contracts it was pursuing.
Something similar coming up?
Engagements like this start with a call about what you are actually dealing with. No hardware, no software, and no installation is sold here, which is the independence policy in one line.