FAQs about IT services for manufacturers
Can you support legacy CNC controllers still running Windows XP or Windows 7?
Yes. Most shops we walk into have at least one machine running an out-of-support Windows version because the controller software does not run on anything newer. We do not pretend the controller can be patched. We isolate it on a dedicated network segment, lock down what it can reach, monitor it for behavior changes, and put the rest of the shop floor behind a firewall so a compromise of one machine does not become a compromise of the whole plant.
We are bidding on a DoD subcontract that requires CMMC 2.0. Can you help?
Yes. CMMC 2.0 Level 1 is largely about basic safeguarding of FCI. Level 2 is the heavier lift: 110 controls aligned to NIST SP 800-171, plus an SSP, a POA&M, and either a self-assessment or a C3PAO assessment depending on the contract. We build the documentation, deploy the controls, run the assessment prep, and produce the artifacts a defense prime or the DoD will actually ask for. A federal-grade engineering background makes that work straightforward, not theoretical.
We have engineers across three sites who need to share CAD files. Best way?
Depends on file size, version-control needs, and whether export controls are in play. For most small shops, a properly configured PDM system on a single hub with replicated read caches at the satellite sites beats trying to share through generic cloud storage. We have built variants of this for engineering teams running SolidWorks PDM, Autodesk Vault, and lighter setups on shared file servers. The deciding factor is usually whether the data falls under ITAR, EAR, or a customer-specific protection requirement, because that changes the architecture.
We had a ransomware scare on the shop floor. How do we segment OT from IT?
Start with a real inventory: every device on the shop floor, what it connects to, what it actually needs to talk to. From there it is a network architecture project: a dedicated OT VLAN, a firewall with explicit allow rules between OT and IT, no broad RDP or SMB across the boundary, and isolated management for the OT side. Most shops we work with did not have an OT VLAN at all when we started. That is the first fix. The second is monitoring, because you cannot defend what you cannot see.
We make medical devices. What does FDA 21 CFR Part 11 mean for our IT?
Part 11 is the FDA rule for electronic records and electronic signatures in regulated activities. The IT side is access control, audit trail integrity, system validation documentation, time-synced logs, and a retention policy that survives an FDA inspector asking for a record from four years ago. For small medical device manufacturers we layer those requirements into the ERP, QMS, document control, and email systems, and we keep the validation paper trail current as systems change.
Who will I actually talk to?
Ulises Paiz, the owner, directly. There is no tier-1 queue and no offshore call center: the engineer who knows your environment answers the phone, and critical incidents carry our 4-hour notification commitment.