Two sister engineering firms, one on each side of the US-Canada border, and the quiet IT work that kept them secure through customer security reviews and into an acquisition.
The short version:
- Client: Two sister engineering firms, one in the US and one in Canada (anonymized), serving industrial clients
- Engagement: Seven years and counting of outsourced IT support and security
- Scope: Email security, cloud storage, remote and in-person helpdesk, phone systems, hardware
- Status: Both firms are now being acquired, primarily for their engineering talent. I still run their security today.
Two firms, one border between them
These two companies came to me about seven years ago. Sister firms, shared ownership, one operating in the US and one in Canada, both doing engineering work for industrial clients. Neither one had internal IT, and neither one needed a big MSP contract with a 40-page SLA. They needed someone who picked up the phone.
That’s been the shape of the whole relationship. I handle their email security, their cloud storage, and their day-to-day support, remote when that works and in person when it doesn’t. Over the years the scope grew the way it does with small firms: I’ve run their phone system migrations, built their workstations by hand when off-the-shelf machines didn’t fit the budget, and made a hundred small calls about where to spend money and where to hold off. IT support for small business lives in those decisions. The stack matters less than the judgment behind it.
The customer security test
A few years in, one of their major industrial customers raised the stakes. Before awarding project work, the customer required compliance with its corporate IT security policy and information security program. Buried in the requirements was a hard one: all project data had to stay in Canada.
That’s a data residency requirement, and it’s the kind of thing that quietly kills deals for small vendors. The engineering team just wanted to work. The customer wanted proof their data wouldn’t drift onto US servers. My job was to close that gap without blowing up the budget or the workflow.
I laid out three options with real time and cost estimates: client-side encryption with Canadian-held keys on their existing cloud storage, a locally encrypted vault, or a move to a Canadian-hosted cloud platform. They picked the Canadian platform. I ran the migration, kept the working copies flowing for the engineer who needed them daily, and mapped the setup against the customer’s security policy documents so the answers were ready before anyone asked.
Small firms lose big customers over vendor security assessments they can’t answer. This one kept theirs.
Then the acquisition came
Both firms are now being acquired by a larger company, and the deal is mostly about people. The acquirer wants the engineers. That’s the whole thesis.
Talent deals move slowly, and this one has. Which makes the IT story simple to state and hard to fake: through the entire drawn-out process, the engineers have kept working, the systems have stayed up, and the security stack has kept running. Seven years in, the incident count is still zero. Nobody on the buyer’s side has had to ask why the target’s email got breached or where the customer data lives, because those answers were settled years ago.
I’m not running this deal, and this case study isn’t about deal work. It’s about the thing that makes deal work easy: an acquirer doing diligence on these firms finds documented systems, a customer-vetted security posture, and a support relationship that didn’t wobble when ownership went into limbo.
What seven years buys
Here’s the honest math on long-term outsourced IT support. Any provider can look good for six months. The value shows up in year three when a customer’s security team comes knocking, and in year seven when a buyer does, and both times the answers are already written down.
These two firms got acquired for their talent. The reason talent was the only thing under negotiation, rather than talent minus a pile of IT risk, is seven years of unglamorous maintenance: patched systems, secured email, data where the contracts say it should be.
If your customers are bigger than you
Industrial customers push their security requirements downstream, and acquirers read your environment like a balance sheet. Both happen on their schedule, not yours. The firms that come through clean are the ones that treated security as routine long before anyone was checking.
If you’re staring down a customer’s vendor security assessment, a data residency requirement, or a sale where your IT needs to hold up to inspection, that’s the work I do.
Facing a security review you’re not sure you’d pass? Get in touch.

