top of page

The $20,000 Question: A county government's CSaaS success story

Project Details

Untitled design - 2026-05-07T011343.200.png

Client:

Sector County government
Location Virginia
IT Model In-house
Engagement CSaaS

Download Case Study

Project Information

THE CHALLENGE

The county needed a vendor to do three things.

01 Identify technical vulnerabilities in its external network and recommend effective remediation.

02

Assess how well its end users were retaining security awareness training and determine where retraining was needed.

03

Determine whether an aging, internally developed web application needed to be replaced with a commercial solution, or could be secured through remediation instead.

Replacing the application meant buying and implementing a commercial product, and keeping it meant proving it could be secured. The county wanted an independent answer before it spent money and time on either.

THE CLIENT

A Virginia county government, and a Securance client for more than 15nyears. The county transitioned to our CSaaS program after working with us for years on individual engagements, and the assessments described below were performed under that program. Like many county governments, it runs its own IT and security functions in-house, across multiple departments and resident-facing digital services, rather than outsourcing them. The county's security team manages a broad and uneven portfolio: modern, vendor-supported systems alongside older, internally developed applications built up over the years by staff and contractors, some of whom have since moved on.

THE SECURANCE SOLUTION

  • Performed a vulnerability assessment of the external network.

  • Reviewed the configuration of the internet-facing firewall.

  • Assessed user security awareness via an email phishing test.

  • Reviewed how user access is granted, modified, and terminated for the internally developed web application at the center of the replace-or-remediate question.

  • Assessed the security posture of the web application.

THE RESULTS

The external network assessment gave the county's security team a prioritized remediation list to work from rather than an undifferentiated inventory of findings, and the phishing test showed where security awareness was working and where retraining would do the most good. The web application assessment answered the county’s most pressing question: the internally developed web application could be secured through remediation rather than replaced outright. That finding saved the county at least $20,000 — the cost of a commercial replacement and because the county buys these assessments as one program rather than five separate engagements. Securance team returns each year already knowing the environment — so each assessment builds on the last, confirms prior fixes held, and digs deeper instead of starting from scratch. Securance remains actively engaged with the county today, continuing to work alongside its team to strengthen its cybersecurity posture and resilience over time. Talk to us about building your CSaaS program.

bottom of page