Technology strategy and procurement support for state and local government.

Public agencies are asked to modernize aging systems, meet security requirements, and follow procurement rules, usually at the same time and on a fixed budget. The hard part is rarely finding a solution. It is deciding well inside those constraints.

A gavel and a laptop with a security shield, with a state capitol dome behind

The pressure, in three numbers.

From the latest national survey of state chief information security officers.

22%of state security chiefs say their staff have the skills the job now requiresNASCIO and Deloitte, 2026 Cybersecurity Study
63%are not confident in the cybersecurity of the local governments around themNASCIO and Deloitte, 2026 Cybersecurity Study
16%reported cuts to their security budgets this yearNASCIO and Deloitte, 2026 Cybersecurity Study

What we usually walk into.

Rarely one problem. Usually four, arriving together.

Procurement rulesRFPs, cooperative contracts, and a process the decision has to survive.
Legacy systemsInfrastructure older than the staff who maintain it.
Security mandatesFrameworks such as NIST shaping what any provider must show.
Stretched teamsNobody owns the evaluation full time.
A leadership team in discussion around a boardroom table

A decision you can defend in public.

Agency decisions are read later by people who were not in the room.

A council, an auditor, or a reporter may ask why this provider, at this price, under this contract. The answer has to exist in writing before the award, not be reconstructed after it.

We write the requirement before any provider is shortlisted, score every option on the same sheet, and document the reasons. When the right answer is to renegotiate with the incumbent or wait for the next cycle, that is the recommendation.

  • Requirements written before the shortlist
  • Every option on one scoring sheet
  • A documented rationale for the file
  • How we are paid, disclosed in writing

How an engagement runs.

The same order in every industry. What changes is the rulebook the decision has to satisfy.

How an engagement runs 1. Diagnose: What you run, what it costs, what is at risk 2. Write the requirement: Including the rules the purchase has to satisfy 3. Compare: Every option on one sheet, the incumbent and doing nothing included 4. Decide and document: A rationale that survives an auditor, an insurer, or a board 5. Stay engaged: Through implementation, and the review six months in 1 Diagnose What you run, what itcosts, what is at risk 2 Write therequirement Including the rulesthe purchase has tosatisfy 3 Compare Every option on onesheet, the incumbentand doing nothingincluded 4 Decide and document A rationale thatsurvives an auditor,an insurer, or a board 5 Stay engaged Throughimplementation, andthe review six monthsin
  1. DiagnoseWhat you run, what it costs, what is at risk
  2. Write the requirementIncluding the rules the purchase has to satisfy
  3. CompareEvery option on one sheet, the incumbent and doing nothing included
  4. Decide and documentA rationale that survives an auditor, an insurer, or a board
  5. Stay engagedThrough implementation, and the review six months in

Questions we hear from public agencies.

The ones we hear most, with straight answers.

All questions

Can you work inside our procurement process?

Yes. We work to your rules rather than around them: requirements, scoring criteria, and documentation built to fit the process you are required to follow. We do not bid on the work we help you evaluate.

Do you replace our IT staff or our current provider?

No. We sit at the strategy layer. Day-to-day operations stay with your team or the provider already running them, and often the finding is that they can close the gap.

How are you paid on public sector work?

It depends on the engagement and it is disclosed in writing before we start. When a provider would compensate us, you are told which one and how before you decide. See How We're Paid.

Three ways to start.

Pick the one that matches where you are. None of them costs anything.

Get the Review

The same diagnostic we run for paying clients, at no charge. Findings in three business days.

Request the Full Review

Check cyber readiness

Score yourself against the controls insurers and auditors ask about.

Take the Assessment

Score your options

The vendor evaluation template, built for a decision that has to be defended.

Get the Template