Strategic IT · Cyber Defense · Infrastructure Management

We think like a CIO.

We govern like a CISO.

We build like a

SECURITY TEAM.

Most providers wait for tickets. We govern your environment against NIST CSF 2.0 and CIS Controls v8, report on it in terms your board understands, and hold the standard as you grow.

Fig. 01 — the scorecard every client receives. Rows are NIST CSF 2.0 functions, columns are control areas.

Approach

The difference isn’t the tools. It’s the posture.

The difference isn’t the tools. It’s the posture.

Every provider in this market resells the same platforms. What separates them is whether anyone is governing the environment, defining the process, and measuring the result — or just answering the phone.

Traditional MSP

Site Systems

Success measured by

Traditional MSP

Tickets closed and uptime

Site Systems

Controls verified against a published framework

Security

Traditional MSP

A product line you can add on

Site Systems

The design constraint on every decision

Configuration

Traditional MSP

Whatever each environment accumulated

Site Systems

One documented baseline, enforced and drift-checked

Reporting

Traditional MSP

Ticket volume and response times

Site Systems

Posture, drift, remediation rate, and open risk by severity

Who you deal with

Traditional MSP

A queue

Site Systems

A named principal accountable for the outcome

When we disagree

Traditional MSP

Does what it’s told

Site Systems

Tells you what the risk is, in writing, and asks you to decide

The baseline

Two frameworks, not opinions.

Two frameworks, not opinions.

Every environment we manage is measured against the same published standards. Our recommendations aren’t preferences you have to take on trust, and your auditor, your insurer, and your board all read the same map we do.

Try thisAsk your current provider which framework they map to. The answer tells you whether you have a security program or a support contract.

NIST CSF 2.0

The reporting structure. Six functions give leadership one view of posture that needs no technical translation — and it’s the language your insurer and your clients’ auditors already use.

Govern

Identify

Protect

Detect

Respond

Recover

CIS Controls v8

The build standard. Prescriptive, ordered by real-world attack data, and grouped into implementation tiers so we can be honest about where you are today and what the next tier costs.

IG1 — Essential

IG2 — Risk-based

IG3 — Advanced

What we manage

Eight domains, one accountable owner.

Each domain runs on a platform we’re a partner on, configured to the same baseline every time. No bespoke builds nobody can support later.

COVERAGE

24/7 monitored detection and response, delivered with eSentire.

MAPPING

Every control traced to a NIST CSF 2.0 function and a CIS v8 safeguard.

001 · Microsoft

Identity & access

Entra ID hardening, conditional access, privileged access control, break-glass procedure. Where modern attacks land, so where we start.

002 · Microsoft · eSentire

Endpoint & detection

Defender deployment plus 24/7 managed detection and response. Tamper protection, application control, analysts on escalation.

003 · Microsoft · Proofpoint

Email & collaboration

Phishing and impersonation defence, DMARC enforcement, link and attachment protection. Email is still the front door.

004 · Fortinet · Cisco

Network & perimeter

Firewall policy, segmentation, secure remote access, wireless. Designed to a documented standard, not accumulated over years.

005 · Tenable

Vulnerability management

Continuous scanning, risk-ranked remediation, and a patch cadence you can show an insurer. Findings that close, not accumulate.

006 · Datto

Backup & continuity

Immutable backup, restores tested on a schedule, documented recovery targets, ransomware recovery runbooks.

007 · NIST CSF · CIS

Governance & compliance

Policy set, risk register, SOC 2 and HIPAA readiness, FTC Safeguards, cyber insurance questionnaires answered accurately.

008 · Dell · Lenovo

IT leadership & lifecycle

Roadmap and budget ownership, vendor management, hardware standards, refresh planning, quarterly business reviews.

Who we work with

Mid-market companies, wherever they operate.

Roughly twenty to five hundred users. Regulated, insured, or contractually accountable for someone else’s data — companies where a breach or an outage stops revenue the same day. We’re based in Houston and currently support clients in Texas, Florida, and New York.

Every platform we manage is cloud-administered, so location doesn’t change what we can do. Where hands are needed on site, we coordinate vetted local technicians against our documented standard.

01 — Energy

Upstream, midstream, and oilfield services. Corporate IT for companies whose downtime is measured in barrels — Gulf Coast and beyond.

02 — Healthcare

Clinics and specialty practices. HIPAA posture, EHR uptime, and audit evidence that holds up under review.

03 — Professional services

Legal, accounting, engineering. Client confidentiality obligations and insurer requirements you have to prove.

04 — Auto retail

Dealer groups. FTC Safeguards compliance, DMS integration, one standard across every rooftop.

How it works

The same five steps, every environment.

01

Assess

Assess

Read-only review of identity, endpoint, cloud, email, and backup. Scored against the baseline. Nothing changes in week one.

Read-only review of identity, endpoint, cloud, email, and backup. Scored against the baseline. Nothing changes in week one.

02

Prioritise

Prioritise

Ranked by what’s actually exploitable in your environment, not by a tool’s severity score. You see the risk and you approve the order.

Ranked by what’s actually exploitable in your environment, not by a tool’s severity score. You see the risk and you approve the order.

03

Implement

Implement

Detect, fix, confirm. Every change scripted, tested on a pilot group, documented, and reversible.

Detect, fix, confirm. Every change scripted, tested on a pilot group, documented, and reversible.

04

Operate

Operate

Monitoring, patching, and monthly reporting on what drifted from baseline and what we corrected.

Monitoring, patching, and monthly reporting on what drifted from baseline and what we corrected.

05

Measure

Measure

Quarterly review against defined KPIs — control coverage, mean time to remediate, open risk by severity, drift events. The scorecard at the top of this page, updated for you.

Quarterly review against defined KPIs — control coverage, mean time to remediate, open risk by severity, drift events. The scorecard at the top of this page, updated for you.

Reporting

What you actually receive.

A finding register in plain English, each item traced to a framework reference, ranked by exploitability, with an owner and a close date. This is the deliverable, not a summary of it.

FormatSample structure from the standard assessment report. Illustrative findings, no client data.
RefFindingSeverityReference
F-014Directory permissions allow a non-tiered group to escalate to domain administrator.CriticalCSF PR.AA-05 CIS 5.4
F-021Legacy authentication path remains enabled for a subset of mailboxes, bypassing conditional access.HighCSF PR.AA-03 CIS 6.4
F-033Third-party application holds standing administrative consent beyond its functional requirement.HighCSF PR.AA-05 CIS 6.8
F-047Backup restore has not been tested within the defined recovery objective window.ModerateCSF RC.RP-01 CIS 11.5
F-052Domain-based message authentication is not enforced for a third-party sending service.ResolvedCSF PR.DS-02 CIS 9.2

Fig. 02 — illustrative finding register. Every item carries a framework reference and target date; no client data.

Fit

We’re not for everyone.

This model works when leadership treats technology as a business risk to be managed. When it doesn’t, we’d both rather find out in the first conversation than three months in.

A good fit

Leadership wants to understand risk, not just approve invoices

You need a documented standard you can show an auditor, an insurer, or a client

You’ll fund remediation once a finding is ranked and explained

You want one accountable advisor, not five vendors pointing at each other

Growth is coming and you’d rather build the foundation before it arrives

×

Not a fit

The deciding factor is the lowest per-seat price

You want the computer guy — fix it, don’t ask questions, don’t send reports

Critical findings get acknowledged and then deferred indefinitely

Systems past end of support are staying regardless of the risk

Security is something you’ll address after the audit fails

Start here

Microsoft 365 posture review.

Twelve control areas measured against our baseline, mapped to NIST CSF 2.0 and CIS v8. Written findings and a prioritised fix list in five business days. No cost, nothing installed, no obligation.

You’ll get the same report format shown above, and a call to walk through it. If we’re not a fit, you keep the findings.

Jonimis Services LLC

Houston, Texas · Clients nationwide

sales@sitesystem.net

We reply within one business day.

SITE SYSTEMS

SITE SYSTEMS

Managed IT and cybersecurity governed to NIST CSF 2.0 and CIS Controls v8. Houston, Texas — serving clients nationwide.

Services

Identity & access
Endpoint & detection
Email security
Governance & compliance

Company

Approach
Frameworks
Field notes
Trust centre

Legal

Privacy policy
Terms
Responsible disclosure