Active Program

Security & data protection initiative

Steve's & Sons, Inc. — a 3-phase program to secure company data, identity, and AI usage

Updated — week of August 3, 2026

Program Lifecycle

9%Overall completion
Phase 1
25%
Phase 2
3%
Phase 3
0%
25%
Phase 1 progress

6

Phase 1 workstreams

1

Decision needed

6

Future workstreams

3

Phases to complete

Vendor decision — awaiting executive sign-off

This decision funds and staffs Phase 1. It does not include Phase 2 or Phase 3 — those will be scoped separately once Phase 1 is underway.

Patriot Consulting$25,500
  • Identity security + full Purview build, ~13–17 weeks
  • Lower price, broader Phase 1 scope, includes a Copilot-readiness track
  • Open-ended cancellation / milestone fees
  • Requires naming Patriot partner-of-record for 1+ year
  • No post-project support window
Avertium$44,500
  • Purview only — no identity/Conditional Access work
  • Includes licensing validation step
  • 3 months of post-launch support included
  • Cleaner cost ceiling, no hidden fees found
  • No week-by-week schedule provided yet

Neither proposal includes Phase 2 or Phase 3 work — those will need separate scoping and pricing once a Phase 1 vendor is selected.

This week & what's next

Progress this week

  • Compared the Patriot and Avertium security proposals line by line for executive review
  • Piloted confidential email and document labels — confirmed working, including PDF labeling
  • Flagged that a single "confidential label" request is really a 3-phase data security program

Coming up

  • Get an executive decision on Patriot vs. Avertium — this funds the whole Phase 1 SOW scope (identity, DLP, insider risk, Copilot readiness) in one move
  • Enroll the HR pilot group (~18 people) on E5 licensing and sensitivity labels
  • Schedule BitLocker rollout — Phase 2, ready now, no cost, doesn't need to wait on the vendor decision
  • Start scoping Phase 2's data cleanup and Phase 3's AI-governance conversation so they're ready the moment Phase 1 wraps

Program roadmap

All three phases delivered, not just Phase 1. Expand a phase to see its workstreams.

Phase 1 — Foundation (now)6 workstreams

Identity & access management

In progress

Conditional access applied to some users, not yet org-wide. MFA active. In Patriot's SOW; Avertium's proposal does not include identity work.

35% complete

Data classification & labeling (Purview)

Testing

5 document labels + 3 email sensitivity labels built and piloted with a test user. Confidential email, document, and PDF labeling confirmed working end to end. In both vendors' scope.

40% complete

Data loss prevention, insider risk & endpoint DLP

Not started

No real-time DLP or insider risk monitoring yet — files can still be freely downloaded, forwarded, or emailed externally today. Named in both SOWs; Avertium's DLP is audit-first.

5% complete

Communication compliance, retention & data discovery

Not started

AIP file-scanner POC and retention policies are named in Patriot's SOW. Legacy file shares (some dating to 2008), Lebanon/Richmond servers, and laptops not yet scanned for PII.

10% complete

Copilot readiness

Not started

Named explicitly in Patriot's SOW as part of the compliance workstream. No work started — this is the AI groundwork Phase 3 builds on.

0% complete

Governance, licensing & vendor selection

Decision needed

Two vendor proposals in hand. Access groups drafted (HR, Accounting, Executives, Purchasing, IT). Blocked on an executive decision to fund the entire Phase 1 scope above.

60% complete

Phase 2 — Expansion & enforcement (next)2 workstreams

Endpoint protection (BitLocker)

Planned

Laptop hard-drive encryption — flagged in the executive meeting as the fastest, no-cost win. Not in either vendor's SOW; doesn't have to wait on the vendor decision.

0% complete

Legacy data cleanup & org-wide rollout

Not started

Goes beyond the Phase 1 scan to actually archive or delete data past retention, extend Conditional Access to all users, and roll protections out beyond the HR pilot.

5% complete

Phase 3 — Maturity & AI governance (later)2 workstreams

AI governance beyond Copilot

Not started

Secure connectors for enterprise AI tools like Claude, flagged on the Patriot call as a separate future conversation — not in either vendor's current SOW.

0% complete

Continuous monitoring, training & audits

Not started

Quarterly security reviews, phishing/security-awareness training, and a data-retrieval policy for platforms like Infor and Kronos — begins once Phase 1 and 2 controls are operating.

0% complete

Prepared for the executive team. Figures reflect the state of Phase 1 as of the update date above; Phase 2 and Phase 3 scope is indicative until formally costed.