Our SOC 2 Type II was a condition of a nine-figure enterprise deal. NCPS took us from "we have a policy folder somewhere" to a clean opinion in seven months, and their evidence library meant our auditor stopped asking us for screenshots halfway through.
Clean SOC 2 Type II · 0 exceptions · deal closed
RSRasheed Sultani
VP Engineering, Cartograph LabsCompliance
The pen-test report was the first one I have read that a non-engineer could follow. It told a story: here is the door we opened, here is what we reached, here is what it would have cost you. Our board approved the remediation budget in one meeting.
14 findings · all remediated and retested in 60 days
EKElaine Kowalczyk
CFO, Harbison Precision ManufacturingPen test
Our cyber-insurance renewal was going to double until NCPS rebuilt the MFA and backup story and wrote the carrier a technical narrative in their own language. Premium came in under the prior year with a higher limit.
Premium down 11% · coverage limit up $3M
TBTomas Beaulieu
CFO, Ardsley Health PartnersvCISO
Eleven years with the same account team. That is the whole review. Nobody in this industry stays eleven years, and the fact that they know our plant floor better than some of our own staff is the reason we have never gone to bid.
Client since 2015 · 0 reportable incidents
MGMarisol Guzmán
CIO, Delaware Bay Logistics GroupManaged
The NCUA examiner asked for evidence of continuous monitoring. We forwarded the NCPS quarterly pack unchanged. His only comment was that he wished more institutions our size documented this well.
Exam passed · no findings on IT controls
JPJordan Pell
CEO, Brandywine Community FCUCompliance
Onboarding took eleven business days rather than the ten they quoted, which is the only complaint I have in four years. The tuning period was genuinely quiet — we were braced for a month of false alarms that never came.
640 endpoints monitored · 3 false escalations in year one
HNHenrik Nilsen
IT Director, Sable Ridge School DistrictOnboarding
A partner's mailbox was compromised nine days before a closing and the wiring instructions were altered. NCPS caught the forwarding rule the hour it was created. The client never knew there had been a problem.
$1.4M funds transfer protected
COClaudette Ossei-Bempah
Managing Partner, Ossei & Marchetti LLPMDR
We are a defense supplier with 90 people and no security staff. CMMC felt impossible. Their enclave design cut the CUI scope to eleven machines, which turned an unaffordable project into a manageable one.
CUI scope cut 84% · Level 2 readiness achieved
RARenata Aliyeva
President, Kestrel AerostructuresCMMC
I wanted a cheaper tier than the one they recommended and they let me have it, then showed me at the quarterly review exactly which two incidents the cheaper tier had slowed down. We upgraded. No pressure, just evidence.
Upgraded at month 8 on measured gaps
BFBill Fothergill
Controller, Trenton Mutual InsuranceManaged
Ransomware hit a vendor with a remote-support tunnel into our network on a Friday evening. Containment happened in under four minutes. We were back to normal operations Monday morning having lost one file server.
Contained pre-encryption · 1 server rebuilt · 0 ransom
SVSunil Varadarajan
VP Operations, Chesapeake Orthopaedic GroupIR
Their exposure scan found a file-transfer appliance a departed contractor stood up in 2019 that nobody had inventoried. It was internet-facing and unpatched. That single finding paid for the year.
7 unknown internet-facing assets retired
ADAmara Dieng
Director of IT, Wilmington Housing AuthorityExposure
We are 55 people and I expected to be the smallest client they had ever taken seriously. Our quarterly review is run by the same CISO who sits with institutions twenty times our size, and she has never once made us feel small.
Client since 2022 · full programme at 55 seats
GTGrace Tolliver
Executive Director, Riverbend Family ServicesvCISO