Security & Risk Assessment Remediation
How Olmec Strengthened a NJ Manufacturer's Cybersecurity DefenseA New Jersey ready-mix concrete manufacturer knew where its security gaps were. Olmec was brought in to actually close them, without ever slowing down a single truck.
- Industry
- Concrete Manufacturing & Building Materials
- Location
- New Jersey (6 sites)
- The Problem
- Critical & high-risk gaps flagged in an outside security audit
- The Result
- Every plant hardened: identity, patching & infrastructure
Key Outcome Every Critical and High-risk finding closed & six plants hardened with zero unplanned downtime
Chapter 01 · The Situation
A good audit is only step one
This client runs several concrete plants across New Jersey, batching orders, dispatching trucks, and moving valuable customer and credit data every single day. That makes them exactly the kind of target insurers, lenders, and big customers now expect to see proof of security from.
So they did the right thing first: they paid for an independent Security & Risk Assessment (SRA) of their network, logins, servers, and cloud setup. The audit came back with a long list of Critical, High, and Moderate findings.
That's where most companies stop. A report gets filed away, nothing gets fixed, and the business is no safer than before it spent the money. Olmec's job was to make sure that didn't happen here.
An assessment tells you where the gaps are. It doesn't close them. That only happens when someone actually does the work.
Chapter 02 · What the Assessment Uncovered
Five gaps, one shared blind spot
None of these findings were exotic. They were the kind of thing that quietly builds up in any growing, multi-site operation, until they line up into a real path for an attacker.
-
Critical
Unprotected admin accounts
IT administrator logins weren't locked down against common credential-theft tricks, and employees could let outside apps connect to company data with no one in IT approving it first.
-
High
Multi-factor authentication gaps
MFA was turned on, but it wasn't configured consistently, leaving room for it to be bypassed on some accounts.
-
Moderate
Inconsistent device hardening
Workstations and servers didn't follow a consistent security baseline, and a well-known Windows print service was left exposed to a common attack technique.
-
Critical
Missing patches, unsupported software
Several systems were running outdated operating systems or third-party software with known, exploitable holes, including some with remote code execution risk.
-
Critical
Outdated virtualization software
The VMware servers running every plant's shared infrastructure had known vulnerabilities, the exact kind that's been used to launch real ransomware attacks on manufacturers.
Alone, each finding looks routine. Together, they described one path: from a single compromised laptop at any plant, straight into the shared servers running the whole company.
Chapter 03 · Turning Findings Into Action
Every finding got an owner and a fix
Olmec treated the audit report like a project plan, not paperwork. Every Critical, High, and Moderate item was assigned to someone, and anything marked "already fixed" was independently re-checked rather than taken on faith.
- Locked down admin accounts and tightened who can grant outside apps access to company data
- Applied a consistent security baseline across every workstation and server
- Fixed the exposed print service and confirmed known Windows security holes were patched
- Reviewed and corrected multi-factor authentication settings company-wide
- Identified every outdated system and coordinated patching across the entire software stack
- Updated the virtualization software running the shared server environment
Chapter 04 · How the Work Got Done
Fixed without slowing down the plants
Concrete doesn't wait. Every step of the remediation was planned so trucks kept rolling and orders kept batching.
-
Nearly everything happened remotely
Most fixes were completed during normal business hours, Monday through Friday, with no disruption to daily operations.
-
One planned exception
Updating the server virtualization software meant taking systems offline briefly. That single outage window was scheduled with the client well in advance, never a surprise.
-
No surprise costs
Anything found outside the original scope was flagged and quoted separately, so the budget and timeline stayed predictable from start to finish.
Chapter 05 · The Outcome
The same list of risks, now closed
Every item that went into the assessment as a risk came out the other side either fixed, re-verified, or formally accepted by the people running the business.
-
Resolved
Admin accounts protected
Privileged logins are now shielded against common credential-theft techniques.
-
Resolved
App access under control
IT now has visibility and approval over any outside app connecting to company data.
-
Resolved
MFA verified and corrected
Multi-factor authentication is now configured consistently across accounts.
-
Resolved
Devices hardened company-wide
A consistent security baseline is now applied across every workstation and server.
-
Resolved
Systems patched and current
Outdated software was identified and brought up to date across the environment.
-
Resolved
Virtualization risk closed
The server infrastructure supporting every plant is patched against known vulnerabilities.
Bottom Line
A security baseline that's not just stronger on paper. It's verifiably closed against the risks this client's own audit found.
6 / 6
Plants hardened
0
Unplanned outages
100%
Findings fixed or formally accepted
1
Scheduled maintenance window
Industry Context
Why this matters for manufacturers
Manufacturers and building materials suppliers are under more pressure than ever to prove they're secure. Cyber insurers price your policy on it. General contractors ask for proof before they'll sign a contract. Lenders factor it into loan decisions. A missing or outdated security assessment is a red flag on its own.
The stakes are real, not theoretical. Ready-mix production runs on a clock. Batching, order entry, and dispatch all depend on the same network staying up, every plant, every day. The exact weaknesses found here are among the most common ways ransomware gets into manufacturers nationwide.
-
01
A defensible answer, ready anytime
A current, documented security picture you can hand to an insurer, auditor, or customer on demand, with no scrambling.
-
02
Problems caught before they cost you
New vulnerabilities and unsupported systems get flagged early, before they become the entry point for an incident.
-
03
A paper trail that protects you
A clear record of what was fixed, what was re-checked, and what risk leadership knowingly accepted, so there's no "we didn't know" after the fact.
Chapter 06 · The Habit
Make it a yearly habit, not a one-time project
Security doesn't stay fixed. New vulnerabilities get disclosed, software falls out of support, staff change, and configurations quietly drift. A one-time assessment captures a single moment, and it's already out of date a year later.
This client's biggest win wasn't any one fix. It was building a repeatable process they can run again next year, with Olmec, to keep their defenses current.
Every business we support gets a dedicated point of contact, defined response times, and a team that treats your uptime like our own.

