Skip to main content

How Olmec Strengthened a NJ Manufacturer’s Cybersecurity Defense

By August 13, 2026September 1st, 2026Case Study

Security & Risk Assessment Remediation

How Olmec Strengthened a NJ Manufacturer's Cybersecurity Defense

A New Jersey ready-mix concrete manufacturer knew where its security gaps were. Olmec was brought in to actually close them, without ever slowing down a single truck.

See the Results Talk to Olmec

Engagement Snapshot
Industry
Concrete Manufacturing & Building Materials
Location
New Jersey (6 sites)
The Problem
Critical & high-risk gaps flagged in an outside security audit
The Result
Every plant hardened: identity, patching & infrastructure

Key Outcome Every Critical and High-risk finding closed & six plants hardened with zero unplanned downtime

Chapter 01 · The Situation

A good audit is only step one

This client runs several concrete plants across New Jersey, batching orders, dispatching trucks, and moving valuable customer and credit data every single day. That makes them exactly the kind of target insurers, lenders, and big customers now expect to see proof of security from.

So they did the right thing first: they paid for an independent Security & Risk Assessment (SRA) of their network, logins, servers, and cloud setup. The audit came back with a long list of Critical, High, and Moderate findings.

That's where most companies stop. A report gets filed away, nothing gets fixed, and the business is no safer than before it spent the money. Olmec's job was to make sure that didn't happen here.

An assessment tells you where the gaps are. It doesn't close them. That only happens when someone actually does the work.


Chapter 02 · What the Assessment Uncovered

Five gaps, one shared blind spot

None of these findings were exotic. They were the kind of thing that quietly builds up in any growing, multi-site operation, until they line up into a real path for an attacker.

  • Critical

    Unprotected admin accounts

    IT administrator logins weren't locked down against common credential-theft tricks, and employees could let outside apps connect to company data with no one in IT approving it first.

  • High

    Multi-factor authentication gaps

    MFA was turned on, but it wasn't configured consistently, leaving room for it to be bypassed on some accounts.

  • Moderate

    Inconsistent device hardening

    Workstations and servers didn't follow a consistent security baseline, and a well-known Windows print service was left exposed to a common attack technique.

  • Critical

    Missing patches, unsupported software

    Several systems were running outdated operating systems or third-party software with known, exploitable holes, including some with remote code execution risk.

  • Critical

    Outdated virtualization software

    The VMware servers running every plant's shared infrastructure had known vulnerabilities, the exact kind that's been used to launch real ransomware attacks on manufacturers.

Alone, each finding looks routine. Together, they described one path: from a single compromised laptop at any plant, straight into the shared servers running the whole company.


Chapter 03 · Turning Findings Into Action

Every finding got an owner and a fix

Olmec treated the audit report like a project plan, not paperwork. Every Critical, High, and Moderate item was assigned to someone, and anything marked "already fixed" was independently re-checked rather than taken on faith.

  • Locked down admin accounts and tightened who can grant outside apps access to company data
  • Applied a consistent security baseline across every workstation and server
  • Fixed the exposed print service and confirmed known Windows security holes were patched
  • Reviewed and corrected multi-factor authentication settings company-wide
  • Identified every outdated system and coordinated patching across the entire software stack
  • Updated the virtualization software running the shared server environment

Chapter 04 · How the Work Got Done

Fixed without slowing down the plants

Concrete doesn't wait. Every step of the remediation was planned so trucks kept rolling and orders kept batching.

  1. Nearly everything happened remotely

    Most fixes were completed during normal business hours, Monday through Friday, with no disruption to daily operations.

  2. One planned exception

    Updating the server virtualization software meant taking systems offline briefly. That single outage window was scheduled with the client well in advance, never a surprise.

  3. No surprise costs

    Anything found outside the original scope was flagged and quoted separately, so the budget and timeline stayed predictable from start to finish.


Chapter 05 · The Outcome

The same list of risks, now closed

Every item that went into the assessment as a risk came out the other side either fixed, re-verified, or formally accepted by the people running the business.

  • Resolved

    Admin accounts protected

    Privileged logins are now shielded against common credential-theft techniques.

  • Resolved

    App access under control

    IT now has visibility and approval over any outside app connecting to company data.

  • Resolved

    MFA verified and corrected

    Multi-factor authentication is now configured consistently across accounts.

  • Resolved

    Devices hardened company-wide

    A consistent security baseline is now applied across every workstation and server.

  • Resolved

    Systems patched and current

    Outdated software was identified and brought up to date across the environment.

  • Resolved

    Virtualization risk closed

    The server infrastructure supporting every plant is patched against known vulnerabilities.

Bottom Line

A security baseline that's not just stronger on paper. It's verifiably closed against the risks this client's own audit found.

  • 6 / 6

    Plants hardened

  • 0

    Unplanned outages

  • 100%

    Findings fixed or formally accepted

  • 1

    Scheduled maintenance window


Industry Context

Why this matters for manufacturers

Manufacturers and building materials suppliers are under more pressure than ever to prove they're secure. Cyber insurers price your policy on it. General contractors ask for proof before they'll sign a contract. Lenders factor it into loan decisions. A missing or outdated security assessment is a red flag on its own.

The stakes are real, not theoretical. Ready-mix production runs on a clock. Batching, order entry, and dispatch all depend on the same network staying up, every plant, every day. The exact weaknesses found here are among the most common ways ransomware gets into manufacturers nationwide.

  • 01

    A defensible answer, ready anytime

    A current, documented security picture you can hand to an insurer, auditor, or customer on demand, with no scrambling.

  • 02

    Problems caught before they cost you

    New vulnerabilities and unsupported systems get flagged early, before they become the entry point for an incident.

  • 03

    A paper trail that protects you

    A clear record of what was fixed, what was re-checked, and what risk leadership knowingly accepted, so there's no "we didn't know" after the fact.


Chapter 06 · The Habit

Make it a yearly habit, not a one-time project

Security doesn't stay fixed. New vulnerabilities get disclosed, software falls out of support, staff change, and configurations quietly drift. A one-time assessment captures a single moment, and it's already out of date a year later.

This client's biggest win wasn't any one fix. It was building a repeatable process they can run again next year, with Olmec, to keep their defenses current.

Every business we support gets a dedicated point of contact, defined response times, and a team that treats your uptime like our own.

Chapter 07 · Your Turn

Sitting on a security report nobody's acted on yet?

Olmec's SRA Review & Remediation service turns your assessment into a prioritized, executed plan, with clear documentation for every finding fixed, re-confirmed, or knowingly accepted.

Book a Free Security Assessment Call (973) 586-6590

No obligation  ·  No spam  ·  Just honest advice

Jason Manteiga

Jason J. Manteiga serves as Vice President at Olmec Systems, leveraging more than two decades of experience in IT services, infrastructure management, and MSP delivery. Since 1999, he’s played a key role in guiding Olmec’s technical strategy and service operations. Jason earned his bachelor’s degree in Information Systems from NJIT, and he is certified in Microsoft MCSE, VMware VCP, and Cisco CCNA. His hands-on background and leadership ensure Olmec delivers secure, reliable, and scalable IT solutions for clients.