Associated KonsultantsCybersecurity & Risk Consulting Better Business Bureau Accredited Business (opens in a new tab)

Case study · February 2025 · Tucson, Arizona

Green Valley Cooling & Heating — and the provider who did the work

A full Security, Risk & Business Needs Assessment. Their own IT provider then carried out every short-term recommendation, and Associated Konsultants was paid for the assessment and nothing else.

What they asked for

Green Valley wanted an objective, outside read on their whole operation — not just the network. Their words: “an objective, third-party assessment of our organization to identify potential vulnerabilities and opportunities for improvement across our operations, IT infrastructure, security protocols and company policies.”

They already had an IT provider. They weren’t looking to replace anyone. They wanted to know where they actually stood, from someone with no stake in the answer.

What we examined

Two halves, over six to eight hours on site.

The cyber half was scored against the 18 CIS Critical Security Controls — the framework most regulators and cyber-insurers treat as the baseline for due diligence. Each control was rated on a six-point maturity scale and mapped against the standard’s three implementation groups, so the result is a measurement anyone can check rather than an opinion.

The corporate half covered the ground a network scan never reaches: hiring and termination practice, whether training is tracked and evidenced, separation of duties on payments, visitor handling and contractor identification, emergency and incident procedures, and the building itself — entrances, cameras, access control, lighting, barriers.

The physical security portion was led by a specialist working alongside us: Matt Tank, a retired FBI agent with more than twenty years in the field.

What they received

A Security Baseline Report with the evidence behind every finding, and an executive out-brief they could take to a decision-making conversation — scorecards for both halves, and every recommendation sorted into short, mid and long term, with the ones driven by regulation flagged as such.

Then a meeting to walk through all of it and answer questions until there weren’t any. Roughly two weeks from signature.

What we found

Better than expected, which is worth saying because it isn’t the usual sales story.

Green Valley scored above most organizations of its size and sector, with a company culture that showed up directly in the security posture — candid staff, a management team that knew its own operation in detail, and evidence of decisions having been made deliberately rather than by default.

There were specific gaps, in five control areas, with a clear order to address them. Those findings stay between us and the client.

What happened next — and this is the part that matters

We did not do the implementation work.

Green Valley had an IT provider they were happy with, and that provider carried out the recommendations. We were paid for the assessment and for nothing else.

That was the arrangement from the beginning. The out-brief belongs to the client. They can hire Associated Konsultants to act on it, hand it to the provider they already have, or do it in-house — and the advice reads the same either way, because it was never written to lead anywhere in particular.

An assessment produced by a firm that also wants the remediation contract is a document with an interest in what it finds. This one didn’t have one.

“He didn’t simply identify concerns. He took the time to provide realistic strategies we could put into action — thorough, but practical and easy to understand.”

Joanna BuglewiczOwner, Green Valley Cooling & Heating

Since then

Every short-term recommendation in the out-brief has been completed.

The work was done by Green Valley’s own IT provider. We weren’t involved in any of it, and we weren’t paid for any of it.

That is the arrangement doing exactly what it is supposed to do. An independent assessment, a document the client owns, and a provider they already trusted carrying out the work. We were paid once, for the assessment.

We speak with Green Valley about twice a year — a genuine check-in, not a sales call. We told them at the out-brief that we would re-assess whenever they wanted it, and we have not talked to them about it since.

Acting on the rest is a business decision only they can make. The exception is anything driven by regulation, which we raise on those calls, because that isn’t a preference.

No specific findings are named here. The out-brief is marked non-publicly releasable, and naming which control areas scored low would tell a reader exactly where a named local business is weak. The scope is described in full; the findings only in aggregate. That is the same protection your report would get.

← All client results

Twenty minutes.

No cost, no presentation. We work out whether there’s a fit — and if there isn’t, I’ll say so.

Book a 20-minute call

(520) 585-4746 · ClientServices@akonsultants.com · Tucson-based — clients nationwide