Case studies

The systems were working. That was not the question.

Temspec Inc. and Goodkey, Weedmark & Associates, a division of Englobe, both had an experienced managed service provider already in place, and systems that were running normally. What neither leadership team had was an independent answer.

Editorial illustration of a pair of reading glasses resting on a printed report, one lens picked out in yellow
A second pair of eyes on the same page.
Case study 01 Manufacturing

Temspec Inc.

Risks the day-to-day management had not surfaced.

Systems were operating, tickets were being resolved and users were being supported. From the outside, everything appeared healthy. Leadership was explicit that what it wanted was not an assessment of the provider.

The engagement
Sector
Manufacturing, HVAC equipment
Established
1971
Region
Canada
IT arrangement
Established managed service provider
The ask
An independent assessment of overall technology risk
Additional scope
Risk management and operational maturity
Existing provider
Retained
Editorial illustration of five devices in a row, four of them enclosed by a bracket and the fifth circled in yellow outside it
What is inside the bracket, and what is not.

What the review found

The environment was generally well maintained. The review still identified several significant risks that had not previously been identified or addressed, including gaps in security and governance that raised business risk while day-to-day operations continued normally.

None of them were the result of negligence. They are what happens when the organization that operates the technology is also the organization expected to assess its own work.

What was delivered

01A prioritized list of business technology risks
02Executive-level explanations of each issue
03Practical recommendations for remediation
04Independent guidance that could be shared with the existing IT provider
In their words

The review gave us an objective perspective we simply weren’t getting anywhere else. It wasn’t about criticizing our IT provider; it was about helping us better understand our technology risks so we could make informed business decisions.

Executive Team, Temspec Inc.
Case study 02 Engineering consulting

Goodkey, Weedmark & Associates Limited

A firm whose own profession is built on independent review.

Project documentation, engineering software, building models, financial systems and client communications all run through technology, and every one of them affects whether a project is delivered on time and whether intellectual property stays protected. Leadership was not looking for another provider. It wanted independent assurance.

The engagement
Sector
Mechanical and electrical engineering consultancy
Established
More than 65 years
Part of
Englobe
Region
Canada
IT arrangement
Experienced managed service provider
The ask
Independent assurance that the technology was supporting the business securely
Additional scope
Infrastructure resilience, documentation maturity, technology leadership
Existing provider
Retained
Editorial illustration of a printed report, one row struck through and swiped with a yellow highlighter
The line that mattered, marked.

What the review found

The review identified several opportunities to strengthen the organization’s technology posture, across security, governance, operational resilience and technology management.

None of it indicated that technology was being poorly managed. It reflected the difference between operating technology and independently evaluating it.

What was delivered

01An executive-level technology risk assessment
02A prioritized roadmap for strengthening the environment
03Independent recommendations focused on business outcomes rather than product sales
04Greater visibility into technology governance and operational resilience
05Actionable guidance that could be implemented alongside the existing IT provider
In their words

The Actually Review provided a level of strategic insight that went beyond day-to-day IT support. It gave our leadership team an independent perspective on technology risk and a clear roadmap for strengthening our environment.

Leadership Team, Goodkey, Weedmark & Associates Limited

What both reviews had in common

Neither review began with a problem.

In both cases the technology was being managed, the tickets were being closed and the reporting looked fine. Neither leadership team was shopping for a new provider. Both wanted an independent view of the risk the business was carrying.

Rather than asking whether the systems were working, both reviews asked a different question: what is the business carrying if something goes wrong tomorrow?

Ground covered in both reviews

Cybersecurity
Microsoft 365 configuration
Identity and access management
Backup and disaster recovery
Infrastructure
Governance
Documentation
Strategic alignment

Each review also covered ground specific to that business, recorded with the engagement above.

The outcome in both cases

Neither review replaced a provider. Both changed what leadership knew.

In both engagements the recommendation was not to change providers. It was to give the existing relationship clearer expectations, and to give leadership independent information about what was actually in place. More on what independence means, and what we are not.

Two colleagues seen from behind, side by side at a table, reading the same printed report, black and white
The guidance was written to be handed to the provider.

What we publish about an engagement.We describe engagements in general terms only. We do not publish findings, configurations, evidence, or any detail that could identify a weakness in a client’s environment. A client is named only where that client has approved the use of its name in writing, a client quotation appears only where the quotation has been approved in writing, and each mark shown here remains the property of its owner.

Ask the same question about your own business.