DESSS provides San Antonio organizations with security assessments, remediation projects and managed support.
The scope includes Microsoft security, identity and privileged access, SOC and MDR, penetration testing, cloud and network security, endpoint and email protection, data resilience, CMMC and HIPAA compliance, application security and connected-device security.
A consultant identifies which risks and compliance gaps matter most for your organization and helps close them in a sensible order.
In San Antonio that often means preparing a defense supplier for CMMC, completing a HIPAA risk analysis for a clinic group, or reducing account-takeover risk for an insurer or bank.
Yes.
DESSS assesses and hardens Azure and AWS environments, covering landing zones, identities and keys, storage exposure, network rules, containers and infrastructure-as-code, and then sets up posture management to catch configuration drift.
Yes.
DESSS runs vulnerability assessments and penetration tests of external networks, internal networks, web applications, APIs and mobile apps, along with Active Directory attack path reviews and red or purple team exercises. Findings include reproduction steps and retesting.
Zero Trust is a model that verifies every access request instead of trusting anything because it sits inside the network.
Identity, device health and context are checked each time, access is limited to what the task needs, and activity is logged and monitored.
DESSS supports Active Directory, Microsoft Entra ID, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Intune and Microsoft Purview, as well as Azure and AWS native security services.
Identity projects can also include CyberArk, SailPoint, Okta and Ping Identity when clients already use them.
An assessment defines the obligations and systems in scope, maps where sensitive data lives, validates technical controls through configuration review and testing, scores the gaps, and documents a remediation plan.
DESSS can then help implement the fixes and retest them.
Defense contractors, healthcare and biomedical research, insurance and banking, government agencies and their vendors, technology and aerospace firms, and professional services benefit most.
Their priorities range from CMMC evidence to patient safety and member fraud prevention.
Clients get one team that both assesses and implements, with strong Microsoft and identity skills and written deliverables they keep.
DESSS is a Texas firm headquartered in Houston with an Austin office, and it offers models from one-time assessments to ongoing managed support.
Yes.
DESSS scopes the CUI environment, runs a gap assessment against NIST SP 800-171, drafts the system security plan and plan of action, implements missing technical controls in Microsoft 365, Azure or on-premises systems, and organizes evidence ahead of a formal CMMC assessment.
DESSS performs the HIPAA Security Rule risk analysis, then addresses the highest risks it finds: MFA and access reviews for clinical systems, segmentation for medical devices, monitored logging, tested backups and a documented incident response plan.
San Antonio has a security profile unlike most Texas metros. Joint Base San Antonio anchors a large community of defense contractors, engineering subcontractors and IT service firms that handle Controlled Unclassified Information and now face CMMC assessments. The South Texas Medical Center concentrates hospitals, specialty practices and biomedical research labs that hold patient data and valuable intellectual property. Large insurance and banking employers run member-facing apps and contact centers that attract account-takeover fraud. Add city, county and state agencies, plus the technology tenants at Port San Antonio, and you get a market where compliance evidence and day-to-day defense have to work together.
DESSS is a Texas technology consulting firm headquartered in Houston, with a second office in Austin, and we work with San Antonio organizations through remote assessments, scheduled working sessions and managed services. Our security consultants sit alongside cloud, Microsoft and application engineers, so a finding about a misconfigured enclave, an over-privileged Entra role or a weak API can be fixed by the same group that found it rather than handed to another vendor.
A typical first step is a short discovery call followed by a scoped assessment against the framework that matters most to you, such as NIST SP 800-171 for a defense supplier or the HIPAA Security Rule for a clinic network. For leaders who want ongoing strategic guidance, the DESSS cybersecurity consulting practice covers advisory and virtual CISO engagements; this page describes the technical services behind them.
Attackers do not target cities, they target data and access. In San Antonio the data that matters most is defense program information, patient records, member financial accounts and public-sector systems, and each comes with its own rules.
DESSS organizes its security practice into five Microsoft security platforms and ten technical domains. Every card below opens a detailed service page with scope, deliverables and the engagement options available.
What is the Microsoft security stack? The Microsoft security stack is the group of products that handle identity (Active Directory and Microsoft Entra), threat detection (Microsoft Defender and Sentinel), device management (Microsoft Intune) and information governance (Microsoft Purview). Many organizations already own these through Microsoft 365 or Azure subscriptions but use only a fraction of their protective features.
For defense suppliers in San Antonio, the Microsoft decision often starts with tenancy: whether Controlled Unclassified Information should live in a commercial tenant with strict controls or in a government cloud environment such as GCC High. We help you weigh that choice against your contracts, then configure identity, device compliance and data labeling so the enclave is defensible and documented for an assessor.
Hospitals, insurers and agencies usually have the licenses already. Our work there is to clean up legacy directory permissions, apply Conditional Access consistently, connect Defender signals to a monitored SIEM, and use Purview labels so protected health information and member data are recognized wherever they travel.
Review of delegated admin rights, stale accounts and Kerberos weaknesses in directories that support defense programs, clinics and agency workloads.
AD DS design, hardening, migration, and forest recovery for the on-premises identity core.
Phishing-resistant MFA, device-based Conditional Access and privileged identity management for administrators who touch CUI or patient systems.
Entra ID, Conditional Access, PIM, and identity governance for cloud identity and Zero Trust.
Defender XDR and Microsoft Sentinel connected so alerts from endpoints, email and identities reach one queue with tested response steps.
Defender XDR and Microsoft Sentinel SIEM deployed, tuned, and run as a working detection capability.
Compliance policies that block unmanaged laptops from CUI enclaves and keep shared clinical workstations patched and locked down.
Intune security baselines, Autopilot provisioning, and co-management for compliant devices.
Sensitivity labels, DLP and retention rules that recognize CUI markings, protected health information and policyholder data.
Information protection, DLP, records management, and eDiscovery across Microsoft 365.
These services decide who can reach sensitive data, how quickly suspicious activity is noticed, and whether your defenses hold up when someone tries to break them.
What are IAM and PAM? Identity and access management (IAM) is the discipline of granting each user the right sign-in method and the right permissions through single sign-on, multi-factor authentication and role design. Privileged access management (PAM) adds vaulting, approval and session recording for administrator and service accounts.
Defense subcontractors near Joint Base San Antonio need access limited to the people on each program, with removal the day someone leaves. Health systems juggle residents, rotating clinicians and vendor support accounts. We design role models and joiner-mover-leaver flows, add privileged identity management in Entra or CyberArk where it fits, and document access reviews so they satisfy NIST SP 800-171 and HIPAA evidence requests.
What are SOC and MDR? A security operations center (SOC) collects logs, correlates them in a SIEM and has analysts investigate and contain threats. Managed detection and response (MDR) provides that monitoring, hunting and containment as an ongoing service instead of an internal build.
San Antonio insurers and banks need detections for account takeover and fraud-adjacent activity, while defense suppliers must show audit logging and incident reporting under CMMC. We review your log sources, build detection content in a Microsoft Sentinel SIEM or your current platform, and then run or co-manage monitoring with your staff, with an incident response retainer behind it.
What is VAPT? VAPT pairs vulnerability scanning, which lists known weaknesses, with penetration testing, where a tester manually chains weaknesses together to prove real impact. Red team engagements simulate a determined adversary end to end, measuring whether detection and response actually work.
Common scopes here include patient and member portals, mobile apps, the boundary around a CUI enclave, and internal networks where one compromised workstation could lead to domain admin. Our web application penetration testing and internal tests run in agreed windows, and each finding comes with reproduction steps and a retest plan your team can schedule.
What is cloud security? Cloud security covers how accounts, networks, identities and data are configured in providers such as Azure and AWS. It includes landing zone design, entitlement control, posture monitoring, workload and container protection, and guardrails written into infrastructure-as-code.
Research groups move genomic and imaging data to cloud storage, insurers build customer platforms on Azure and AWS, and defense suppliers weigh government cloud regions for CUI. We assess each Azure landing zone or AWS organization for public exposure and excessive permissions, then set up posture monitoring so new resources follow the same rules from day one.
What is Zero Trust security? Zero Trust is an approach in which no user, device or network segment receives implicit trust. Access is granted per request after checking identity, device health and context, and it is limited to the specific application or data needed.
For San Antonio defense suppliers that usually means isolating the CUI environment and replacing open VPN access with identity-aware access. Hospitals need clinical, guest and building-system networks separated so one infected laptop cannot reach imaging or infusion equipment. We design the segments, update firewall policy and migrate users in phases to avoid disruption.
These services protect workstations and records, turn controls into audit evidence, and extend coverage to medical, building and lab equipment that cannot run a standard agent.
What is endpoint security? Endpoint security is the protection of laptops, desktops, servers and phones using EDR or XDR agents, secure configuration baselines and disciplined patching. Email security complements it by filtering phishing, malicious attachments and sender impersonation before they reach users.
Shared nursing-station computers, contact-center desktops and engineers on contractor laptops each need different policies. We deploy and tune EDR, apply hardening baselines through Intune, and configure DMARC, DKIM and SPF so nobody can spoof your domain to members, patients or prime contractors. Regular phishing simulations show where awareness training should focus next.
What is data protection? Data protection is the set of controls that keep sensitive records private, intact and recoverable: classification, DLP, encryption with managed keys, database hardening, and backups that attackers cannot alter or delete.
An electronic health record outage, lost research data or an encrypted claims system can stop operations for days. We run a ransomware readiness assessment, design immutable backups for clinical, research and policy systems, rehearse restores with your staff, and apply encryption and labeling so CUI and patient data stay protected wherever they are stored.
What is GRC in cybersecurity? Governance, risk and compliance (GRC) connects security work to business accountability. It covers written policies, a maintained risk register, control mapping to required frameworks, third-party oversight, audit preparation and executive reporting, often led by a virtual CISO.
This is the center of most San Antonio engagements. For defense suppliers we prepare the system security plan, plan of action and milestones, and evidence for a CMMC assessment. For providers we perform HIPAA risk analysis; for insurers and banks we align controls to GLBA and examiner expectations. Third-party risk reviews of your own vendors and audit readiness and evidence automation keep the work current between assessments.
What is application security? Application security makes software resistant to attack by addressing risk during design, coding, testing and deployment. Practices include threat modeling, code review, static and dynamic scanning, dependency and secrets checks, and hardened build pipelines.
San Antonio teams build patient scheduling tools, claims and policy portals, agency service apps and software delivered to defense programs. We add threat modeling to feature design, put SAST, DAST and software composition analysis into the pipeline, and test APIs for broken object-level authorization, the flaw most likely to expose one member or patient record to another user.
What is OT security? Operational technology (OT) security protects equipment that controls physical processes, including industrial control systems, building automation and connected IoT devices. Availability and safety take priority, so monitoring is usually passive and changes are planned carefully.
In this market the connected-device problem shows up in hospitals, labs and campuses more than in heavy industry: infusion pumps, imaging modalities, freezers, badge readers and HVAC controllers on the same networks as staff laptops. We inventory these assets, apply IoT device security controls and segmentation, and give equipment vendors brokered remote access instead of standing connections.
Each sector in the city carries different obligations and threats. These are the industries where our engagements most often begin and what they usually address.
An assessment gives leadership an evidence-based picture of security risk and a sequenced plan to reduce it. With DESSS, clients go through six stages, and each one produces something you keep.
DESSS is a Texas technology consulting firm, headquartered in Houston with an office in Austin, whose cybersecurity practice works with San Antonio clients. Here is what that means in practice.
DESSS provides San Antonio organizations with security assessments, remediation projects and managed support. The scope includes Microsoft security, identity and privileged access, SOC and MDR, penetration testing, cloud and network security, endpoint and email protection, data resilience, CMMC and HIPAA compliance, application security and connected-device security.
A consultant identifies which risks and compliance gaps matter most for your organization and helps close them in a sensible order. In San Antonio that often means preparing a defense supplier for CMMC, completing a HIPAA risk analysis for a clinic group, or reducing account-takeover risk for an insurer or bank.
Yes. DESSS assesses and hardens Azure and AWS environments, covering landing zones, identities and keys, storage exposure, network rules, containers and infrastructure-as-code, and then sets up posture management to catch configuration drift.
Yes. DESSS runs vulnerability assessments and penetration tests of external networks, internal networks, web applications, APIs and mobile apps, along with Active Directory attack path reviews and red or purple team exercises. Findings include reproduction steps and retesting.
Zero Trust is a model that verifies every access request instead of trusting anything because it sits inside the network. Identity, device health and context are checked each time, access is limited to what the task needs, and activity is logged and monitored.
DESSS supports Active Directory, Microsoft Entra ID, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Intune and Microsoft Purview, as well as Azure and AWS native security services. Identity projects can also include CyberArk, SailPoint, Okta and Ping Identity when clients already use them.
An assessment defines the obligations and systems in scope, maps where sensitive data lives, validates technical controls through configuration review and testing, scores the gaps, and documents a remediation plan. DESSS can then help implement the fixes and retest them.
Defense contractors, healthcare and biomedical research, insurance and banking, government agencies and their vendors, technology and aerospace firms, and professional services benefit most. Their priorities range from CMMC evidence to patient safety and member fraud prevention.
Clients get one team that both assesses and implements, with strong Microsoft and identity skills and written deliverables they keep. DESSS is a Texas firm headquartered in Houston with an Austin office, and it offers models from one-time assessments to ongoing managed support.
Yes. DESSS scopes the CUI environment, runs a gap assessment against NIST SP 800-171, drafts the system security plan and plan of action, implements missing technical controls in Microsoft 365, Azure or on-premises systems, and organizes evidence ahead of a formal CMMC assessment.
DESSS performs the HIPAA Security Rule risk analysis, then addresses the highest risks it finds: MFA and access reviews for clinical systems, segmentation for medical devices, monitored logging, tested backups and a documented incident response plan.
Tell us which obligation is most pressing, whether a CMMC deadline, a HIPAA finding, an insurer questionnaire or a recent incident, and DESSS will propose an assessment scoped around it.
The main DESSS cybersecurity page, cybersecurity consulting in other locations, and related reading.