
DESSS works with Chicago trading houses, insurers, manufacturers, rail and freight operators and health systems to lock down privileged access, watch for intrusions, test defenses and segment plant networks, through assessment, delivery and managed security support.
DESSS delivers cybersecurity programs for Chicago organizations that span Microsoft security (Active Directory, Entra, Defender, Intune, and Purview), identity governance and PAM, SOC and MDR, vulnerability assessment and red teaming, cloud and network security, endpoint and data protection, GRC and regulatory alignment, secure software delivery, and OT, ICS, and IoT protection.
Work is available as a standalone assessment, a scoped build-out, or continuing managed support. DESSS is a Texas firm headquartered in Houston that works with Chicago companies across all of these areas.
The Chicago economy rests on a few systems that simply cannot fail quietly. Derivatives and futures trading built around CME Group depends on low-latency platforms, tightly controlled administrator rights and clean audit trails. Insurers and banks in the Loop protect policyholder and account data under GLBA and SOX. Manufacturers across the region run PLC-driven lines next to their ERP, and the city remains a crossroads for the nation's railroads, intermodal yards and trucking networks. When any of those systems is compromised, the damage shows up in missed trades, stopped lines or stranded freight.
Our cybersecurity consulting and advisory practice treats each of those environments differently. A trading firm needs strict privileged identity management and monitoring that does not add latency; a plant needs segmentation and passive visibility that never risks a safety system; an employer using fingerprint time clocks needs biometric data handled in line with the Illinois Biometric Information Privacy Act (BIPA). We design controls around the operation, not the other way round.
DESSS is a Texas firm headquartered in Houston that works with Chicago organizations on assessments, implementations and ongoing support. Because one team handles discovery and remediation, a finding like an unmanaged trading-desk admin account or an exposed historian server moves straight into a fix, with documented evidence your auditors and risk committee can review.
Chicago combines dense financial infrastructure, heavy industry and national transport links. Attackers know that disruption in any of them carries a high price, which is why they invest effort here.
Derivatives, proprietary trading and asset management firms hold strategies, positions and client funds. Compromised admin credentials or a poisoned build server can expose all three, so privileged access and change control matter most.
Carriers, brokers and third-party administrators store policyholder, claims and health information. That data is attractive for extortion and identity fraud, and GLBA expectations apply to how it is safeguarded.
Manufacturers link PLCs, HMIs and historians to ERP and cloud analytics. Without segmentation, ransomware on an office laptop can spread to the production floor and halt output.
Rail, intermodal and trucking operators exchange EDI, tracking and billing data with shippers and carriers constantly. A breached partner connection or spoofed invoice email can delay loads and divert payments.
Fingerprint time clocks, facial recognition and voice authentication are common in Illinois workplaces. BIPA sets notice, consent, retention and destruction rules for that data, so security and privacy controls must line up.
Examiners, auditors, reinsurers and cyber insurers increasingly ask for MFA coverage, logging, tested backups and a governed incident plan. Producing that evidence on demand needs a program, not a scramble.
DESSS organizes its security work into five Microsoft platforms and ten security domains. Use the cards below to open each service page and review scope, deliverables and how engagements are structured.
Microsoft security platforms
AD DS design, hardening, migration, and forest recovery for the on-premises identity core.
Entra ID, Conditional Access, PIM, and identity governance for cloud identity and Zero Trust.
Defender XDR and Microsoft Sentinel SIEM deployed, tuned, and run as a working detection capability.
Intune security baselines, Autopilot provisioning, and co-management for compliant devices.
Information protection, DLP, records management, and eDiscovery across Microsoft 365.
Security domains
Joiner-mover-leaver lifecycle, SSO and MFA, RBAC design, and privileged access control.
SIEM implementation, detection engineering, threat hunting, and incident response.
Vulnerability assessment, penetration testing, and red and purple team exercises.
Posture management, cloud entitlements, workload and container security, IaC guardrails.
Next-generation firewalls, segmentation, Zero Trust network access, and SASE.
EDR and XDR, email threat protection, endpoint hardening, and patch management.
Encryption and key management, immutable backup, disaster recovery, and continuity.
Risk register, policy and framework development, audit readiness, and vCISO advisory.
Threat modeling, SAST and DAST, secrets management, and secure pipelines in the SDLC.
OT assessment, Purdue-model segmentation, SCADA monitoring, and IoT device security.
Which tools make up the Microsoft security stack? The Microsoft security stack groups Active Directory, Microsoft Entra, Microsoft Defender, Microsoft Intune and Microsoft Purview into one layer for identity, device management, threat detection and data governance. Many enterprises already own large parts of it through existing Microsoft agreements but run it with default settings.
Chicago financial firms and insurers tend to have mature but crowded Microsoft estates: on-premises Active Directory that still authenticates trading and claims applications, an Entra ID tenant for cloud apps, and several overlapping security tools. DESSS rationalizes that estate, removes standing administrator rights with privileged identity management, and connects Defender signals to a single detection workflow.
In manufacturing and logistics, we draw a clear line between Microsoft-managed office systems and plant or yard equipment, so endpoint agents and policies stay on devices that can handle them while OT monitoring covers the rest.

Microsoft Active Directory — Forest health checks, Kerberos and delegation fixes, and admin tiering for directories that still back trading and claims systems.
Microsoft Entra — Privileged Identity Management, Conditional Access and phishing-resistant MFA for traders, adjusters, brokers and plant engineers.
Microsoft Defender — Defender XDR signals routed into Microsoft Sentinel with playbooks for credential theft, insider data movement and ransomware staging.
Microsoft Intune — Hardened baselines for trader workstations, insurance field laptops and shared shop-floor terminals managed from one console.
Microsoft Purview — Data loss prevention and labeling for client portfolios, policyholder files, engineering drawings and biometric records.
The first five domains determine how hard it is to break in, how far an intruder can travel, and how soon your team finds out.
How do IAM and PAM differ? IAM manages every user identity, from sign-in and MFA to the roles that decide which systems each person may use. PAM focuses on the small set of powerful accounts, such as domain admins, database owners and service accounts, adding vaulting, approval workflows and session recording.
Trading and asset management firms need to prove that only authorized staff can change order-routing or risk systems. We introduce CyberArk or Entra PIM where it fits, rotate service account secrets, and run quarterly access certification for traders, quants and operations staff so entitlements match current roles.
What is the difference between a SOC and MDR? A SOC is the function, whether in-house or outsourced, that monitors security telemetry, triages alerts and leads incident response. MDR is a managed service that supplies that monitoring, hunting and containment capability on an ongoing basis.
Insurers and banks often run a legacy SIEM that produces volume without clarity. DESSS handles SIEM implementation or migration to Microsoft Sentinel, writes detections for privileged misuse and data exfiltration, and can run or co-manage triage with your staff, supported by an incident response retainer.
Why combine vulnerability assessment with penetration testing? Vulnerability assessment scans broadly for known flaws, while penetration testing has skilled testers exploit and chain those flaws to demonstrate real-world impact. Red teaming adds stealth and objectives to measure how well people, processes and tools detect an attack.
For financial firms, objectives might be reaching a trading system or a client data store without triggering alerts. For insurers, it may be abusing an agent portal. We run red and purple team exercises around those goals, plus internal network and Active Directory testing, and hand over findings with clear reproduction steps.
Why does cloud security need its own discipline? Cloud platforms change the attack surface: identities, APIs and configuration replace physical network edges. Cloud security therefore centers on account design, entitlement control, workload protection, container security and continuous checks for misconfiguration.
Chicago insurers and manufacturers are moving claims processing, analytics and supply-chain applications into Azure and AWS. DESSS performs a cloud migration security review before cutover, designs landing zones with guardrails, and sets up posture monitoring so a public storage bucket or wide-open role is caught quickly.
How does Zero Trust security change network design? Zero Trust assumes breach. Instead of trusting anything on the internal network, it verifies each user, device and session, grants the narrowest access needed, and divides the network into small zones so lateral movement is blocked.
In practice for Chicago firms, that means separating trading, corporate and guest traffic, putting plant and rail-yard systems behind their own zones, and replacing legacy VPN concentrators with identity-aware access. Network segmentation work is staged around market hours and production schedules to avoid disruption.
The remaining domains keep endpoints and records safe, satisfy examiners and auditors, and carry protection onto factory floors, rail yards and connected equipment.
Why are endpoints and email a priority? Most intrusions start on a user device or in an inbox. Endpoint security combines EDR or XDR, hardened builds and patch management, while email security blocks phishing, spoofing and malicious links before they reach staff.
Law firms, accountancies and brokers in the region see constant wire-fraud attempts disguised as client or vendor emails. We deploy EDR across workstations and servers, enforce DMARC, run phishing simulation for high-risk groups like finance and claims, and set patch cadences that respect trading and plant change windows.
What does cyber resilience mean for data? Cyber resilience means sensitive data stays protected and the business can recover after an attack. It brings together classification, encryption, data loss prevention, database hardening and backups designed to survive ransomware.
For a Chicago insurer or manufacturer, the critical question is how fast claims processing or production planning can resume after ransomware. We design immutable backup architecture, rehearse restores of core systems, harden databases holding policy and client data, and define retention and destruction rules for biometric records under BIPA.
What does a GRC program include? A GRC program defines security governance, maintains a risk register, sets policies and maps controls to the laws and standards an organization must meet. It also covers vendor risk, audit preparation and executive leadership through a virtual CISO.
Financial firms here answer to GLBA, SOX and exchange or customer due diligence, insurers to GLBA and state insurance regulators, and employers using biometrics to Illinois BIPA. We start with a cybersecurity risk assessment, consolidate controls into one framework, and support cyber insurance readiness and board reporting through vCISO advisory.
How does DevSecOps improve application security? DevSecOps builds security into the software pipeline instead of testing only at the end. It pairs threat modeling and secure code review with automated SAST, DAST, dependency checks and protected build systems.
Trading firms write in-house execution and risk tools; insurers build quoting engines and agent portals. We review code for logic and authorization flaws, secure the CI/CD pipeline and artifact repositories against tampering, and set up a secure SDLC program that developers can follow without slowing releases.
Why does OT security require a separate approach? Operational technology controls physical processes through PLCs, SCADA, HMIs and sensors. OT security prioritizes safety and uptime, uses passive monitoring instead of aggressive scanning, and follows standards such as ISA/IEC 62443.
Food processors, metal fabricators and chemical plants in the Chicago area, plus rail and intermodal operators, rely on control systems that were never designed for connectivity. We perform an OT security assessment, introduce ICS and SCADA monitoring, segment control networks from business IT, and control vendor access to equipment.
Security priorities shift from sector to sector. These are the parts of the Chicago economy where DESSS work typically concentrates, and what it addresses.
Proprietary trading, futures and investment firms: privileged access control, build pipeline integrity, low-impact monitoring and objective-based red teaming.
Banks, lenders and payment teams: GLBA safeguards, SOX access controls, wire-fraud prevention and SIEM modernization.
Carriers, brokers and administrators: policyholder data protection, agent portal testing, cloud migration reviews and cyber insurance readiness.
Food, metals, chemicals and industrial equipment makers: OT segmentation, passive control-system monitoring and supplier security questionnaires.
Railroads, intermodal terminals, trucking and warehousing firms: EDI and partner link security, yard system segmentation and payment fraud defenses.
Hospitals, clinics, law and accounting firms: HIPAA risk analysis, client confidentiality controls, BIPA-aware biometric handling and Microsoft 365 hardening.
A cybersecurity assessment measures how well your current controls protect the systems that matter and ends with a ranked action plan. DESSS runs it in five phases.
We agree on the business processes at risk, such as order execution, claims handling, a production line or freight dispatch, and document which sites, systems and tests are permitted.
Engagement charter and test rulesInterviews, configuration exports and discovery tools capture identities, privileged accounts, cloud subscriptions, endpoints, OT assets and partner connections.
Consolidated asset inventorySettings are compared with CIS and vendor baselines, scans run across in-scope systems, and approved penetration or segmentation tests confirm what is actually exploitable.
Verified findings with evidenceFindings are mapped to NIST CSF and obligations such as GLBA, SOX, HIPAA, ISA/IEC 62443 or BIPA, then rated by likelihood and business impact.
Risk-rated control gap reportLeadership receives a sequenced roadmap with owners, effort, quick wins and longer projects, and DESSS can deliver the remediation with your staff.
Prioritized security roadmapDESSS is a Texas technology consulting firm headquartered in Houston, with a cybersecurity practice that both advises and implements. These are the reasons Chicago firms engage us.
Request a scoping callDiscovery and remediation sit with the same consultants, so a privileged access gap or flat plant network is corrected rather than handed to another vendor.
Changes are planned around market hours, production schedules and freight cutoffs, so security work does not interrupt revenue.
Active Directory, Entra, Defender, Sentinel, Intune, Purview and PAM tooling are core DESSS practice areas, suited to firms with large Microsoft estates.
The same engagement can cover office systems and control networks, keeping IT agents off equipment that cannot support them.
Risk registers, designs, runbooks and test results are delivered in writing and organized for examiners, auditors and insurers.
Choose advisory, implementation, integration and migration, managed support, or training and change management, sized to the problem.
DESSS offers assessment, implementation and managed cybersecurity support to Chicago organizations.
Coverage includes Microsoft security, identity governance and PAM, SOC and MDR, penetration testing and red teaming, cloud and Zero Trust network security, endpoint and data protection, GRC, DevSecOps and OT, ICS and IoT security.
A cybersecurity consultant gives you an outside, evidence-based view of where you are exposed and a practical plan to fix it.
In Chicago that commonly means tightening privileged access at financial firms, segmenting plant networks, modernizing a SIEM and aligning biometric data handling with BIPA.
Yes.
DESSS reviews migrations before cutover, designs Azure and AWS landing zones with guardrails, removes excessive entitlements, secures containers and Kubernetes, and sets up posture monitoring that flags misconfigurations as they appear.
DESSS performs external and internal network tests, web, API and mobile application tests, Active Directory attack path reviews, phishing simulations and objective-based red and purple team exercises.
Each test is run under written rules of engagement and reported with reproduction steps.
Zero Trust is a security model built on the assumption that attackers may already be inside.
It verifies every user, device and session continuously, limits each identity to the access it needs, and splits the network into zones that contain any breach.
DESSS supports Active Directory, Microsoft Entra ID and PIM, Defender XDR, Microsoft Sentinel, Intune and Purview, along with Azure and AWS security tooling.
For identity and privileged access, DESSS also works with CyberArk, SailPoint, Okta and Ping Identity in client environments.
A cybersecurity assessment sets objectives and scope, catalogues assets and identities, validates controls with scans and agreed tests, maps results to frameworks and regulations, and closes with a prioritized roadmap that names owners and effort.
Trading and derivatives firms, banks, insurers, manufacturers, rail and freight operators, healthcare providers and professional services firms gain the most in Chicago.
Their priorities range from privileged access and audit evidence to plant uptime and client confidentiality.
DESSS combines advisory and hands-on delivery across Microsoft, identity, cloud, network and OT security, so Chicago businesses deal with one team from assessment through remediation.
DESSS is a Texas firm headquartered in Houston and documents every engagement in deliverables your staff keep.
Illinois BIPA requires organizations that collect biometric identifiers, such as fingerprints or face geometry, to give notice, obtain written consent, publish a retention policy and protect the data with reasonable care.
DESSS helps map where biometric data lives, restrict and monitor access, encrypt it and enforce retention and destruction rules, working alongside your legal counsel.
Yes.
DESSS relies on passive discovery and monitoring for control networks, coordinates segmentation changes with operations and safety staff, and schedules any active testing inside approved maintenance or outage windows.
Share the process you can least afford to lose, from order execution and claims handling to a production line or freight dispatch, and DESSS will scope an assessment that protects it first.
The main DESSS cybersecurity page, the same services in other locations, and related reading.