Catch Advisors
Technology

Houston Tech Company Achieves SOC 2 Compliance After Full Cybersecurity Overhaul

Achieved in 6 Months
SOC 2 Compliance
Fully Remediated
Security Gaps
Replaced
MSP
Services: CybersecurityManaged ITVendor Selection

The Challenge

A Houston-based technology company came to us knowing they needed SOC 2 compliance but unsure how far they were from achieving it. What we found during our initial cyber defense matrix engagement was worse than expected.

Their existing managed service provider had passwords stored on sticky notes. When the client began exploring a transition away from them, the MSP attempted to lock the company out of their own Fortinet firewalls. The relationship had become adversarial, and the client was left with an IT environment they did not fully control, undocumented security practices, and no clear path to the compliance posture their clients and prospects were demanding.

Beyond the MSP situation, the company had persistent WiFi issues throughout their office that were disrupting day-to-day operations. Their endpoint protection was inadequate, email security was basic, and password management across the organization was essentially nonexistent. There were no documented security frameworks, no formalized policies, and no evidence trail that would satisfy a SOC 2 auditor.

Key challenges included:

  • Negligent MSP storing passwords on sticky notes and attempting to lock the client out of their own firewall infrastructure during the transition
  • No SOC 2 compliance despite growing client demand for it as a requirement to do business
  • No documented security frameworks or formalized IT policies of any kind
  • Inadequate endpoint protection and email security leaving the company exposed to modern threats
  • No centralized password management, creating credential sprawl and security risk across the organization
  • Persistent WiFi issues impacting employee productivity throughout the office
  • No visibility into their own security posture — they did not know what they did not know

Our Approach

We started with our cyber defense matrix engagement to establish a clear picture of where the client stood and what it would take to get them to SOC 2 compliance.

Phase 1: Cyber Defense Matrix Assessment (Weeks 1-3)

We conducted a comprehensive assessment of the client’s security environment, mapping every gap against SOC 2 requirements. The cyber defense matrix gave the client and our team a visual, prioritized view of where they were exposed and what needed to be addressed first. This was not a generic checklist — it was a structured analysis of their specific environment, workflows, and risk profile.

The assessment confirmed what we suspected: the existing MSP had left the client in a precarious position. Firewall configurations were undocumented, endpoint protection was minimal, there was no email threat protection beyond basic spam filtering, credentials were unmanaged, and there was zero documentation that would support a compliance audit.

We presented the findings to the client’s leadership with a clear remediation roadmap and timeline to SOC 2 readiness.

Phase 2: MSP Replacement and Vendor Selection (Weeks 3-6)

The first priority was removing the existing MSP and regaining full control of the client’s infrastructure. We managed the transition carefully, ensuring continuity while extracting the company from a provider who was actively working against their interests.

We then evaluated and selected a new technology stack purpose-built for a company pursuing SOC 2:

  • Atera for remote monitoring and management — giving the client and their new MSP full visibility into every endpoint with documented audit trails
  • Coro for endpoint detection and response plus email security — a single platform covering two critical SOC 2 control areas with centralized management and reporting
  • Keeper for enterprise password management — eliminating credential sprawl and providing the access controls and audit logs SOC 2 requires
  • Splice for network connectivity — resolving the persistent WiFi issues and ensuring reliable, secure connectivity throughout the office

Each vendor was selected not just for capability but for how their platform mapped to specific SOC 2 trust service criteria, ensuring every tool deployed was pulling double duty as both an operational improvement and a compliance control.

Phase 3: Implementation and Framework Documentation (Weeks 6-14)

We managed the deployment of the entire stack, coordinating across four vendors to ensure everything was configured correctly and integrated properly. Coro was deployed across all endpoints for EDR and connected to email for inbound threat protection. Keeper was rolled out organization-wide with enforced policies. Atera was configured for monitoring, patching, and alerting. Splice resolved the WiFi infrastructure issues.

Critically, we worked with the client to document everything. Every security policy, every configuration decision, every access control — all formalized into frameworks that mapped directly to SOC 2 trust service criteria. This documentation was not an afterthought; it was built alongside the implementation so that by the time the stack was fully deployed, the client had the evidence and paper trail a SOC 2 auditor would need.

Results

The client went from a company with passwords on sticky notes and a hostile MSP to achieving SOC 2 compliance in six months:

  • SOC 2 compliance achieved within six months of engagement, opening doors to enterprise clients who require it
  • Negligent MSP fully replaced with a modern, documented, and accountable IT management approach powered by Atera
  • Endpoint and email security deployed via Coro, providing EDR and email threat protection from a single platform with compliance-ready reporting
  • Enterprise password management implemented with Keeper, eliminating credential sprawl and providing auditable access controls
  • WiFi and connectivity issues resolved with Splice, removing a daily productivity drain
  • Full compliance documentation created including security policies, frameworks, and evidence packages mapped to SOC 2 trust service criteria
  • Complete infrastructure control restored — the client owns and controls every piece of their technology environment

Client Feedback

“We knew we needed SOC 2 but had no idea how far behind we were until Catch Advisors walked us through the cyber defense matrix. Our old MSP had us in a terrible position — passwords on sticky notes, trying to lock us out of our own firewalls. Kyle’s team replaced them, built us a real security stack, and documented everything. Six months later we had SOC 2. That compliance certification has already helped us close deals we would have lost.”

— Client Leadership

Solutions Deployed

Platforms Deployed