<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber-Security &#8211; TristanPoulsen.com</title>
	<atom:link href="https://tristanpoulsen.com/category/cyber-security/feed/" rel="self" type="application/rss+xml" />
	<link>https://tristanpoulsen.com</link>
	<description>Welcome to TristanPoulsen.com</description>
	<lastBuildDate>Tue, 11 Aug 2026 16:07:22 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://tristanpoulsen.com/wp-content/uploads/2024/07/cropped-Tristan-Forryst-Poulsen-initials-logo-32x32.png</url>
	<title>Cyber-Security &#8211; TristanPoulsen.com</title>
	<link>https://tristanpoulsen.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Seven Years, Zero Incidents: The Outsourced IT Support Behind an Acqui-Hire</title>
		<link>https://tristanpoulsen.com/outsourced-it-support-acquisition-case-study/</link>
					<comments>https://tristanpoulsen.com/outsourced-it-support-acquisition-case-study/#respond</comments>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Wed, 19 Aug 2026 15:46:19 +0000</pubDate>
				<category><![CDATA[Cyber-Security]]></category>
		<category><![CDATA[Private Equity]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=919</guid>

					<description><![CDATA[Two sister engineering firms, one on each side of the US-Canada border, and the quiet IT work that kept them secure through customer security reviews and into an acquisition. The short version: Two firms, one border between them These two companies came to me about seven years ago. Sister firms, shared ownership, one operating in ... <a title="Seven Years, Zero Incidents: The Outsourced IT Support Behind an Acqui-Hire" class="read-more" href="https://tristanpoulsen.com/outsourced-it-support-acquisition-case-study/" aria-label="Read more about Seven Years, Zero Incidents: The Outsourced IT Support Behind an Acqui-Hire">Read more</a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>Two sister engineering firms, one on each side of the US-Canada border, and the quiet IT work that kept them secure through customer security reviews and into an acquisition.</em></p>



<p class="wp-block-paragraph"><strong>The short version:</strong></p>



<ul class="wp-block-list">
<li><strong>Client:</strong> Two sister engineering firms, one in the US and one in Canada (anonymized), serving industrial clients</li>



<li><strong>Engagement:</strong> Seven years and counting of outsourced IT support and security</li>



<li><strong>Scope:</strong> Email security, cloud storage, remote and in-person helpdesk, phone systems, hardware</li>



<li><strong>Status:</strong> Both firms are now being acquired, primarily for their engineering talent. I still run their security today.</li>
</ul>



<h2 class="wp-block-heading">Two firms, one border between them</h2>



<p class="wp-block-paragraph">These two companies came to me about seven years ago. Sister firms, shared ownership, one operating in the US and one in Canada, both doing engineering work for industrial clients. Neither one had internal IT, and neither one needed a big MSP contract with a 40-page SLA. They needed someone who picked up the phone.</p>



<p class="wp-block-paragraph">That&#8217;s been the shape of the whole relationship. I handle their email security, their cloud storage, and their day-to-day support, remote when that works and in person when it doesn&#8217;t. Over the years the scope grew the way it does with small firms: I&#8217;ve run their phone system migrations, built their workstations by hand when off-the-shelf machines didn&#8217;t fit the budget, and made a hundred small calls about where to spend money and where to hold off. IT support for small business lives in those decisions. The stack matters less than the judgment behind it.</p>



<h2 class="wp-block-heading">The customer security test</h2>



<p class="wp-block-paragraph">A few years in, one of their major industrial customers raised the stakes. Before awarding project work, the customer required compliance with its corporate IT security policy and information security program. Buried in the requirements was a hard one: all project data had to stay in Canada.</p>



<p class="wp-block-paragraph">That&#8217;s a data residency requirement, and it&#8217;s the kind of thing that quietly kills deals for small vendors. The engineering team just wanted to work. The customer wanted proof their data wouldn&#8217;t drift onto US servers. My job was to close that gap without blowing up the budget or the workflow.</p>



<p class="wp-block-paragraph">I laid out three options with real time and cost estimates: client-side encryption with Canadian-held keys on their existing cloud storage, a locally encrypted vault, or a move to a Canadian-hosted cloud platform. They picked the Canadian platform. I ran the migration, kept the working copies flowing for the engineer who needed them daily, and mapped the setup against the customer&#8217;s security policy documents so the answers were ready before anyone asked.</p>



<p class="wp-block-paragraph">Small firms lose big customers over vendor security assessments they can&#8217;t answer. This one kept theirs.</p>



<h2 class="wp-block-heading">Then the acquisition came</h2>



<p class="wp-block-paragraph">Both firms are now being acquired by a larger company, and the deal is mostly about people. The acquirer wants the engineers. That&#8217;s the whole thesis.</p>



<p class="wp-block-paragraph">Talent deals move slowly, and this one has. Which makes the IT story simple to state and hard to fake: through the entire drawn-out process, the engineers have kept working, the systems have stayed up, and the security stack has kept running. Seven years in, the incident count is still zero. Nobody on the buyer&#8217;s side has had to ask why the target&#8217;s email got breached or where the customer data lives, because those answers were settled years ago.</p>



<p class="wp-block-paragraph">I&#8217;m not running this deal, and this case study isn&#8217;t about deal work. It&#8217;s about the thing that makes deal work easy: an acquirer doing diligence on these firms finds documented systems, a customer-vetted security posture, and a support relationship that didn&#8217;t wobble when ownership went into limbo.</p>



<h2 class="wp-block-heading">What seven years buys</h2>



<p class="wp-block-paragraph">Here&#8217;s the honest math on long-term outsourced IT support. Any provider can look good for six months. The value shows up in year three when a customer&#8217;s security team comes knocking, and in year seven when a buyer does, and both times the answers are already written down.</p>



<p class="wp-block-paragraph">These two firms got acquired for their talent. The reason talent was the <em>only</em> thing under negotiation, rather than talent minus a pile of IT risk, is seven years of unglamorous maintenance: patched systems, secured email, data where the contracts say it should be.</p>



<h2 class="wp-block-heading">If your customers are bigger than you</h2>



<p class="wp-block-paragraph">Industrial customers push their security requirements downstream, and acquirers read your environment like a balance sheet. Both happen on their schedule, not yours. The firms that come through clean are the ones that treated security as routine long before anyone was checking.</p>



<p class="wp-block-paragraph">If you&#8217;re staring down a customer&#8217;s vendor security assessment, a data residency requirement, or a sale where your IT needs to hold up to inspection, that&#8217;s the work I do.</p>



<p class="wp-block-paragraph"><em>Facing a security review you&#8217;re not sure you&#8217;d pass? <a href="https://tristanpoulsen.com/contact/">Get in touch.</a></em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://tristanpoulsen.com/outsourced-it-support-acquisition-case-study/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cybersecurity Due Diligence Case Study: A Real PE Acquisition</title>
		<link>https://tristanpoulsen.com/case-studies-cybersecurity-due-diligence-acquisition/</link>
					<comments>https://tristanpoulsen.com/case-studies-cybersecurity-due-diligence-acquisition/#respond</comments>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 15:00:28 +0000</pubDate>
				<category><![CDATA[Cyber-Security]]></category>
		<category><![CDATA[Private Equity]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=912</guid>

					<description><![CDATA[From Breach Cleanup to Buyout: Cybersecurity Due Diligence in a Real Acquisition How 4.5 years of security work turned a single-location self-storage company into a clean acquisition target, and what a three-week technology handoff looks like when the buyer runs 50+ facilities. The short version: It started with a breach They found me the way ... <a title="Cybersecurity Due Diligence Case Study: A Real PE Acquisition" class="read-more" href="https://tristanpoulsen.com/case-studies-cybersecurity-due-diligence-acquisition/" aria-label="Read more about Cybersecurity Due Diligence Case Study: A Real PE Acquisition">Read more</a>]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">From Breach Cleanup to Buyout: Cybersecurity Due Diligence in a Real Acquisition</h2>



<p class="wp-block-paragraph"><em>How 4.5 years of security work turned a single-location self-storage company into a clean acquisition target, and what a three-week technology handoff looks like when the buyer runs 50+ facilities.</em></p>



<p class="wp-block-paragraph"><strong>The short version:</strong></p>



<ul class="wp-block-list">
<li><strong>Client:</strong> Single-location self-storage operator in Colorado (anonymized)</li>



<li><strong>Buyer:</strong> Private equity-backed storage operator with 50+ facilities</li>



<li><strong>My role:</strong> IT and security provider for 4.5 years, then transition lead on the seller side</li>



<li><strong>Handoff:</strong> Three weeks, kickoff to done</li>
</ul>



<h2 class="wp-block-heading">It started with a breach</h2>



<p class="wp-block-paragraph">They found me the way a lot of my clients do: mid-incident. Their previous IT provider had gone defunct, and the provider&#8217;s abandoned website was serving malware. Someone at the storage company opened that site looking for support and infected their machine instead.</p>



<p class="wp-block-paragraph">I took the call, cleaned the infection, recovered their systems, and combed through everything for leftover malicious code. Then I rebuilt their stack so it wouldn&#8217;t happen twice: antivirus, EDR through Huntress, cloud backup, and same-day helpdesk, remote and onsite. All of it sized and priced for a single-location business.</p>



<h2 class="wp-block-heading">Four and a half years of quiet</h2>



<p class="wp-block-paragraph">For the next 4.5 years I ran their IT and security. Webroot and Huntress covered the endpoints. Backups ran to the cloud and got checked. When something broke, I fixed it the same day. No repeat incidents, no drama.</p>



<p class="wp-block-paragraph">That stretch of quiet matters more than it sounds. When a buyer showed up years later, the company had a documented, monitored environment with a real security history behind it. Most small businesses walk into a sale with none of that.</p>



<h2 class="wp-block-heading">Then a buyer showed up</h2>



<p class="wp-block-paragraph">A private equity-backed storage operator with 50+ facilities acquired the company. Deals like this live or die in diligence, and the buyer&#8217;s team had two questions about IT: is this environment secure, and is it cost-effective?</p>



<p class="wp-block-paragraph">That&#8217;s technology due diligence in one sentence. Buyers want proof, and on small acquisitions they rarely get it, because the seller&#8217;s IT knowledge lives in one person&#8217;s head or a defunct vendor&#8217;s filing cabinet. Here, I had run the environment for years and could answer with documentation instead of guesses. That alone shortened the timeline.</p>



<h2 class="wp-block-heading">The three-week handoff</h2>



<p class="wp-block-paragraph">Post merger IT integration for this deal came down to four workstreams.</p>



<p class="wp-block-paragraph"><strong>RMM migration.</strong> The buyer standardized every acquisition onto their own remote management platform. Instead of touching each machine by hand, I wrote a script that deployed their agent and removed mine (ConnectWise Automate, at the time) across all systems in one pass.</p>



<p class="wp-block-paragraph"><strong>Backup migration.</strong> I moved their cloud backups off my platform and onto the buyer&#8217;s, and verified restore points on both ends before cutting over. A migration without verified restores is a gamble, and nobody gambles during a closing.</p>



<p class="wp-block-paragraph"><strong>Access control.</strong> The buyer&#8217;s team ran the access control migration themselves. I supported from the client side, kept credentials flowing, and made sure nothing on our end held them up.</p>



<p class="wp-block-paragraph"><strong>Data cleanup and destruction.</strong> The buyer&#8217;s compliance requirements meant old data had to go, and go for real. I purged stale records the business no longer needed, then dealt with the retired hard drives that held customer data: a seven-pass wipe on each drive, and then I opened them up and pulled the platters out. Nobody is recovering that data. The platters make decent coasters, if you&#8217;re wondering.</p>



<p class="wp-block-paragraph">Secure data destruction is the step small-business acquisitions skip most, and it&#8217;s the one that turns into a lawsuit years later when a drive full of customer records surfaces at a pawn shop.</p>



<p class="wp-block-paragraph">Total time, including the buyer&#8217;s inspection and the back-and-forth between their team and my client: three weeks.</p>



<h2 class="wp-block-heading">The result</h2>



<p class="wp-block-paragraph">The buyer got what diligence teams almost never get from a small acquisition: a documented environment, a working security stack, verified backups, and proof that legacy customer data was destroyed instead of forgotten in a closet. My client walked into closing without IT sitting on the deal as an open issue.</p>



<p class="wp-block-paragraph">And the whole thing traced back to a malware infection five years earlier. The same work that saved them from a breach made them a cleaner company to buy.</p>



<h2 class="wp-block-heading">Why this matters if you&#8217;re buying or selling</h2>



<p class="wp-block-paragraph">Most small businesses run on undocumented IT held together by whoever set it up. In an acquisition, undocumented becomes risk, and risk becomes a price reduction or a delayed close. Buyers now run cybersecurity due diligence on deals of every size, and sellers who can&#8217;t answer basic questions about their environment pay for it at the negotiating table.</p>



<p class="wp-block-paragraph">If you&#8217;re a buyer, a searcher, or an owner planning an exit, the cheapest time to fix your technology story is before diligence starts. That&#8217;s the work I do: assess the stack, close the gaps, and run the handoff so the deal keeps moving.</p>



<p class="wp-block-paragraph"><em>Working a deal and want a second set of eyes on the technology? <a href="https://tristanpoulsen.com/contact/">Get in touch.</a></em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://tristanpoulsen.com/case-studies-cybersecurity-due-diligence-acquisition/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Having a Maximum Security Mindset is Important</title>
		<link>https://tristanpoulsen.com/having-a-maximum-security-mindset-is-important/</link>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Fri, 10 Mar 2023 16:53:17 +0000</pubDate>
				<category><![CDATA[Cyber-Security]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=549</guid>

					<description><![CDATA[I’ve always tried to have the most secure mindset when it comes to my passwords. Unfortunately with the news of the recent LastPass hacks, I’ve had to migrate away from it (over a year ago at this point) but now with the more serious breach that occurred, I decided to update ALL of my passwords, ... <a title="Having a Maximum Security Mindset is Important" class="read-more" href="https://tristanpoulsen.com/having-a-maximum-security-mindset-is-important/" aria-label="Read more about Having a Maximum Security Mindset is Important">Read more</a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">I’ve always tried to have the most secure mindset when it comes to my passwords. Unfortunately with the news of the recent LastPass hacks, I’ve had to migrate away from it (over a year ago at this point) but now with the more serious breach that occurred, I decided to update ALL of my passwords, quite literally over 1000 passwords, in order to maintain that maximum personal and business security mentality. I’ve probably spent 8 hours already, just updating passwords, usernames, and 2FA where available.</p>



<h3 class="wp-block-heading"><strong>2FA Availability</strong></h3>



<p class="wp-block-paragraph">That’s the thing that I’m frustrated with at the moment, not all major companies offer Two Factor Authentication via a true 2FA App or even better a YubiKey physical key. Banks are the biggest offender of this. They might offer 2FA via your phone or email verification token, but as we all should know, your phone and your email ARE NOT SECURE EITHER. What do I have to do to get USBank and other major Banks to offer the best of the best in security for access to our digital currency?</p>



<p class="wp-block-paragraph">All it takes is a hacker taking control of an email, or SIM jacking your phone number, and presto – they have access to the remainder of your personal information and money. Quite scary if you ask me.</p>



<p class="wp-block-paragraph">Now that I’m looking into this I’m finding that Bank of America – BOA has the highest online security including support for YubiKey. That might be everyone’s best bet, especially large targets like Whales.</p>



<p class="wp-block-paragraph">[insert picture of a whale]</p>



<p class="wp-block-paragraph">“Whaling is a highly targeted phishing attack &#8211; aimed at senior executives &#8211; masquerading as a legitimate email. Whaling is digitally enabled fraud through social engineering, designed to encourage victims to perform a secondary action, such as initiating a wire transfer of funds.”</p>



<h3 class="wp-block-heading"><strong>SIM Jacking</strong></h3>



<p class="wp-block-paragraph">Okay so I don’t have a solution for this, unfortunately, most carriers allow for a sim lock but that has its flaws, as someone with enough information could bypass that over the phone with a telecom customer service rep.</p>



<p class="wp-block-paragraph">It would be cool if a startup or a current telecom company just made a High-security mode for your account/phone numbers linked to the account, which locks the phone number from being replicated to a different SIM without an In-Person double identity verification process. Possibly with fingerprint verification, again in-person to add a barrier to socially engineered methods like SIM jacking.</p>



<p class="wp-block-paragraph">I think this is essential for everyone as our lives now live on our phones, and realistically I’ve noticed most people are less secure with their mobile devices than they are with their desktop computers. When in the real world your phone/phone number should be more important to protection as it ends up being that 2FA step that malicious entities would have to overcome, and currently it’s doable with the right attack vectors. No seriously how are these multi-millionaires not terrified that with their mindset in cyber-security and when they are targeted, they would be hacked in a matter of hours, not days or weeks? Leaving massive financial risk based on one of 3 attack vectors, compromised email, compromised mobile device, or a socially engineered SIM jacking.</p>



<h4 class="wp-block-heading">Get a Yubico Key for your personal or business cyber-security.</h4>



<script type="text/javascript">
amzn_assoc_tracking_id = "tristanp0c-20";
amzn_assoc_ad_mode = "manual";
amzn_assoc_ad_type = "smart";
amzn_assoc_marketplace = "amazon";
amzn_assoc_region = "US";
amzn_assoc_design = "enhanced_links";
amzn_assoc_asins = "B07HBD71HL";
amzn_assoc_placement = "adunit";
amzn_assoc_linkid = "fbe1ff348681137ee16615f55ceec90a";
</script>
<script src="//z-na.amazon-adsystem.com/widgets/onejs?MarketPlace=US"></script>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
