// CASE STUDY · DEFENCE AND AEROSPACE MANUFACTURING

Small-business IT to CMMC and NIST SP 800-171 readiness, as fractional CTO and CISO

  • vCTO / vCISO engagement
  • CMMC + NIST SP 800-171
  • Defence supply chain

The problem

A manufacturer supplying wiring harnesses into armoured vehicle and military aircraft programs had standard small-business IT and no information security function. The defence supply chain requirements they were being held to were a long way from where they were.

What I did

  • Took a combined fractional CTO and CISO role, covering both the technology direction and the security function.
  • Re-architected the infrastructure so it could support controlled unclassified information handling rather than being retrofitted around it.
  • Built the policy set and put the controls in place against CMMC and NIST SP 800-171.
  • Moved the organization from typical small-business practice to a defensible, documented control set with the evidence behind it.

Where it landed

A defence supplier that went from no information security programme to CMMC and NIST SP 800-171 ready, with the architecture, policies, and controls to support the contracts it was pursuing.

Something similar coming up?

Engagements like this start with a call about what you are actually dealing with. No hardware, no software, and no installation is sold here, which is the independence policy in one line.