Security & data protection initiative
Steve's & Sons, Inc. — a 3-phase program to secure company data, identity, and AI usage
Updated — week of August 3, 2026
Program Lifecycle
6
Phase 1 workstreams
1
Decision needed
6
Future workstreams
3
Phases to complete
Vendor decision — awaiting executive sign-off
This decision funds and staffs Phase 1. It does not include Phase 2 or Phase 3 — those will be scoped separately once Phase 1 is underway.
- Identity security + full Purview build, ~13–17 weeks
- Lower price, broader Phase 1 scope, includes a Copilot-readiness track
- Open-ended cancellation / milestone fees
- Requires naming Patriot partner-of-record for 1+ year
- No post-project support window
- Purview only — no identity/Conditional Access work
- Includes licensing validation step
- 3 months of post-launch support included
- Cleaner cost ceiling, no hidden fees found
- No week-by-week schedule provided yet
Neither proposal includes Phase 2 or Phase 3 work — those will need separate scoping and pricing once a Phase 1 vendor is selected.
This week & what's next
Progress this week
- Compared the Patriot and Avertium security proposals line by line for executive review
- Piloted confidential email and document labels — confirmed working, including PDF labeling
- Flagged that a single "confidential label" request is really a 3-phase data security program
Coming up
- Get an executive decision on Patriot vs. Avertium — this funds the whole Phase 1 SOW scope (identity, DLP, insider risk, Copilot readiness) in one move
- Enroll the HR pilot group (~18 people) on E5 licensing and sensitivity labels
- Schedule BitLocker rollout — Phase 2, ready now, no cost, doesn't need to wait on the vendor decision
- Start scoping Phase 2's data cleanup and Phase 3's AI-governance conversation so they're ready the moment Phase 1 wraps
Program roadmap
All three phases delivered, not just Phase 1. Expand a phase to see its workstreams.
Phase 1 — Foundation (now)6 workstreams
Identity & access management
In progressConditional access applied to some users, not yet org-wide. MFA active. In Patriot's SOW; Avertium's proposal does not include identity work.
35% complete
Data classification & labeling (Purview)
Testing5 document labels + 3 email sensitivity labels built and piloted with a test user. Confidential email, document, and PDF labeling confirmed working end to end. In both vendors' scope.
40% complete
Data loss prevention, insider risk & endpoint DLP
Not startedNo real-time DLP or insider risk monitoring yet — files can still be freely downloaded, forwarded, or emailed externally today. Named in both SOWs; Avertium's DLP is audit-first.
5% complete
Communication compliance, retention & data discovery
Not startedAIP file-scanner POC and retention policies are named in Patriot's SOW. Legacy file shares (some dating to 2008), Lebanon/Richmond servers, and laptops not yet scanned for PII.
10% complete
Copilot readiness
Not startedNamed explicitly in Patriot's SOW as part of the compliance workstream. No work started — this is the AI groundwork Phase 3 builds on.
0% complete
Governance, licensing & vendor selection
Decision neededTwo vendor proposals in hand. Access groups drafted (HR, Accounting, Executives, Purchasing, IT). Blocked on an executive decision to fund the entire Phase 1 scope above.
60% complete
Phase 2 — Expansion & enforcement (next)2 workstreams
Endpoint protection (BitLocker)
PlannedLaptop hard-drive encryption — flagged in the executive meeting as the fastest, no-cost win. Not in either vendor's SOW; doesn't have to wait on the vendor decision.
0% complete
Legacy data cleanup & org-wide rollout
Not startedGoes beyond the Phase 1 scan to actually archive or delete data past retention, extend Conditional Access to all users, and roll protections out beyond the HR pilot.
5% complete
Phase 3 — Maturity & AI governance (later)2 workstreams
AI governance beyond Copilot
Not startedSecure connectors for enterprise AI tools like Claude, flagged on the Patriot call as a separate future conversation — not in either vendor's current SOW.
0% complete
Continuous monitoring, training & audits
Not startedQuarterly security reviews, phishing/security-awareness training, and a data-retrieval policy for platforms like Infor and Kronos — begins once Phase 1 and 2 controls are operating.
0% complete
Prepared for the executive team. Figures reflect the state of Phase 1 as of the update date above; Phase 2 and Phase 3 scope is indicative until formally costed.