
DESSS works with El Paso freight, manufacturing, healthcare and defense-supply organizations to secure the trading-partner connections, plant networks and identities that keep goods and services moving across the border, from first assessment to ongoing monitoring.
DESSS delivers cybersecurity assessment, implementation, and managed support to El Paso organizations across fifteen disciplines: Active Directory, Microsoft Entra, Defender and Sentinel, Intune and Purview; identity and privileged access; SOC and MDR; vulnerability assessment, penetration testing, and red teaming; cloud security; Zero Trust networking; endpoint and email security; backup and data resilience; GRC; application and API security; and OT, ICS, and IoT security for plants and warehouses.
Work can stop at a written assessment, continue into a remediation project, or move into managed support, with one team accountable throughout.
El Paso and Ciudad Juárez function as one industrial region split by an international boundary. Maquiladora plants on the Mexican side depend on El Paso warehouses, customs brokers, trucking companies and engineering offices on the Texas side, and every shipment moves with a stream of EDI messages, portal logins, shared spreadsheets and email approvals. That chain of trading partners is exactly what modern attackers exploit: a single compromised broker mailbox or supplier VPN can redirect a payment, delay a crossing or open a route into a plant network.
DESSS is a Texas technology consulting firm headquartered in Houston, with a second office in Austin, and we serve El Paso organizations through remote assessments, planned working sessions and managed services. Our security consultants work alongside cloud, Microsoft and integration engineers, which matters here because the weak spot is usually a connection between systems, such as an ERP feeding a carrier portal, rather than a single server.
Most engagements start with a scoped review of identities, partner connections and the boundary between office IT and production equipment. If you need longer-term strategic guidance, the DESSS security advisory practice explains our advisory and virtual CISO model; this page focuses on the hands-on technical services that follow.
Threat actors follow money and leverage. In El Paso both sit in the flow of goods between two countries, the plants that produce them, and the hospitals and federal programs that serve the region.
Shippers, brokers, carriers, warehouses and plants exchange orders, invoices and customs documents through EDI, portals and email. Every integration and shared credential is a doorway that needs ownership and monitoring.
Business email compromise thrives where invoices cross companies and languages. A spoofed message asking to change bank details can divert a freight or supplier payment before anyone notices.
Production lines, test benches and warehouse automation report to MES, ERP and cloud dashboards. Without segmentation, malware on an office PC can halt a line or a distribution center.
Customs filings, dispatch and yard systems run on tight schedules. A ransomware outage at a broker or carrier backs up shipments for customers on both sides of the border.
Contractors supporting Fort Bliss and other Department of Defense programs must protect Controlled Unclassified Information and demonstrate NIST SP 800-171 controls to win and keep contracts.
Manufacturers, retailers and CBP partnership programs increasingly ask suppliers for security questionnaires, MFA, endpoint protection and incident plans. Weak answers can cost a contract.
Our practice is built on five Microsoft security platforms and ten security domains. Each card leads to a full service page describing scope, deliverables and how an engagement is structured.
Microsoft security platforms
AD DS design, hardening, migration, and forest recovery for the on-premises identity core.
Entra ID, Conditional Access, PIM, and identity governance for cloud identity and Zero Trust.
Defender XDR and Microsoft Sentinel SIEM deployed, tuned, and run as a working detection capability.
Intune security baselines, Autopilot provisioning, and co-management for compliant devices.
Information protection, DLP, records management, and eDiscovery across Microsoft 365.
Security domains
Joiner-mover-leaver lifecycle, SSO and MFA, RBAC design, and privileged access control.
SIEM implementation, detection engineering, threat hunting, and incident response.
Vulnerability assessment, penetration testing, and red and purple team exercises.
Posture management, cloud entitlements, workload and container security, IaC guardrails.
Next-generation firewalls, segmentation, Zero Trust network access, and SASE.
EDR and XDR, email threat protection, endpoint hardening, and patch management.
Encryption and key management, immutable backup, disaster recovery, and continuity.
Risk register, policy and framework development, audit readiness, and vCISO advisory.
Threat modeling, SAST and DAST, secrets management, and secure pipelines in the SDLC.
OT assessment, Purdue-model segmentation, SCADA monitoring, and IoT device security.
What is the Microsoft security stack? It is a connected toolset: Active Directory and Microsoft Entra govern who signs in, Microsoft Defender and Sentinel detect and investigate threats, Microsoft Intune keeps devices compliant, and Microsoft Purview classifies and protects information. Most Microsoft 365 business and enterprise plans include parts of it that sit unused.
Cross-border operations tend to accumulate identities: plant engineers, broker staff, drivers with shared tablets, and partner users invited as guests into Teams and SharePoint. We bring that sprawl under control first, using Entra ID governance, guest access reviews and Conditional Access rules that treat a warehouse kiosk differently from an executive laptop.
Once identity is clean, we connect Defender signals to a monitored SIEM, enroll devices in Intune, and use Purview to label commercial documents such as pricing, bills of materials and customs paperwork. Where plants run equipment that cannot host Microsoft agents, we define where OT monitoring takes over.

Microsoft Active Directory — Cleanup of legacy trusts, shared service accounts and plant-floor domain joins that expose the corporate directory to production networks.
Microsoft Entra — Guest and B2B access reviews for trading partners, plus Conditional Access for shared warehouse tablets and cross-border travelers.
Microsoft Defender — Defender XDR and Sentinel tuned for business email compromise, suspicious inbox rules and unusual partner sign-ins.
Microsoft Intune — Enrollment and compliance baselines for rugged scanners, dispatch tablets and laptops used by staff who cross the border daily.
Microsoft Purview — Labels and DLP for bills of materials, rate sheets, customs records and patient information shared with outside parties.
These services control who reaches your systems and partner connections, catch intrusions early, and prove whether your defenses survive a real attack attempt.
What are IAM and PAM? IAM is how an organization decides and enforces who may sign in to which systems, through directories, single sign-on, multi-factor authentication and role-based permissions. PAM focuses on the powerful accounts, such as domain, ERP and firewall administrators, adding vaulted credentials, approvals and recorded sessions.
El Paso operations often share logins across shifts, plants and partner companies, and former employees of a broker or contractor keep access far too long. We replace shared accounts with named identities, set up access certification for partner and guest users, and put just-in-time elevation in front of ERP, EDI gateway and plant domain administration.
What are SOC and MDR? A SOC is a function, staffed by analysts and supported by a SIEM, that monitors security telemetry, investigates alerts and leads containment. MDR delivers that function as a managed service, adding proactive threat hunting and guided response for organizations without a full in-house team.
For a logistics firm the critical signals are mailbox rule changes, unusual partner sign-ins and file transfers outside normal patterns; for a manufacturer they include traffic crossing into the plant network. We tune detections for those scenarios, add threat hunting for slow-moving intrusions, and run or co-manage monitoring with your staff, supported by an incident response retainer.
What is VAPT? VAPT is a two-part security test. Vulnerability assessment scans systems for known flaws and misconfigurations; penetration testing has a skilled tester exploit and chain those flaws to show what an attacker could actually reach. Red teaming adds stealth and objectives to test detection and response.
Typical El Paso scopes include carrier and customer portals, SFTP and EDI endpoints exposed to trading partners, remote access gateways used by plant vendors, and the path from a warehouse workstation to the domain. We schedule testing around shipping peaks and production windows and report findings with clear reproduction and retest steps.
What is cloud security? Cloud security is the practice of configuring and monitoring Azure, AWS and SaaS environments so identities, storage, networks and workloads are not exposed. It includes landing zone design, permission management, posture monitoring and container and infrastructure-as-code controls.
Freight visibility platforms, supplier portals and analytics for plant output often run in Azure or AWS, built quickly to meet a customer deadline. We review those environments for exposed storage, over-broad API keys and missing logging, apply cloud security posture management, and secure integration points where cloud apps talk to on-premises ERP systems.
What is Zero Trust security? Zero Trust means granting access one request at a time based on verified identity, device condition and context, rather than trusting a user because they are connected to the office network or a VPN. Each person or system reaches only the resources it needs.
In El Paso this usually starts with network segmentation between office, warehouse, guest and production networks, then VPN modernization for vendors and staff who connect from plants, trucks and home. Partner connections move from broad tunnels to application-specific access, so a breach at one trading partner cannot spread into yours.
These services harden the devices and records your operations rely on, demonstrate compliance to customers and assessors, and extend protection to production lines and warehouse automation.
What is endpoint security? Endpoint security keeps computers, servers, scanners and phones protected through EDR or XDR monitoring, hardened configurations and consistent patching. Email security is its partner control, stopping the phishing, spoofing and payment-change requests that start most incidents.
Dispatch desks, shipping offices and plant supervisors handle a constant flow of invoices and partner email, which makes them prime targets. We roll out EDR, enforce patch and vulnerability management, lock down rugged handhelds with mobile device and BYOD security policies, and configure email security and anti-phishing controls including DMARC to stop impersonation of your brand and your suppliers.
What is data protection? Data protection keeps business information confidential and recoverable. Core elements are classification, data loss prevention, encryption, database hardening and an immutable backup design that ransomware cannot encrypt or erase, backed by tested recovery procedures.
If a customs, transportation management or MES database goes down, trucks and lines stop. We build immutable backup copies of those systems, set recovery priorities with operations leaders, rehearse restores, and protect sensitive files such as engineering drawings, pricing and patient records with encryption and access controls.
What is GRC in cybersecurity? GRC brings structure to security: governance assigns ownership and policy, risk management identifies and ranks threats to the business, and compliance demonstrates to customers, regulators and assessors that required controls are in place. A virtual CISO often leads it.
El Paso companies answer to customer supplier audits, CMMC for defense work, HIPAA for providers and PCI DSS where cards are taken. We run third-party and vendor risk management across your carriers, brokers and software providers, build policies that cover cross-border operations, and give leadership a risk register in plain business terms.
What is application security? Application security reduces vulnerabilities in the software an organization builds or customizes. It combines threat modeling, secure code review, automated SAST and DAST, dependency and secrets scanning, and pipeline controls so flaws are caught before release.
Development groups in the region build shipment tracking pages, EDI translators, supplier onboarding forms and integrations between ERP, WMS and carrier systems. We review that code, add scanning to the build pipeline, and perform API security testing to make sure one customer cannot read another customer's shipments or rates.
What is OT security? OT security protects the systems that run physical work, such as PLCs, HMIs, robotics, conveyors and connected sensors. Because uptime and safety come first, it relies on passive monitoring, careful segmentation and tightly controlled vendor access.
Manufacturers supplying or operating maquiladora lines, and distribution centers with automated sortation, increasingly link equipment to MES and cloud reporting. We start with an OT security assessment and asset inventory, design zones and conduits under ISA/IEC 62443, add ICS and SCADA monitoring, and give machine builders secure remote access for vendors in place of always-on modems.
Security needs follow the business model. These are the sectors where DESSS most often works with El Paso organizations and the problems each one brings.
Customs brokers, freight forwarders, 3PLs and cross-dock operators: EDI and portal security, business email compromise defense and recovery planning for time-critical systems.
Plants and their El Paso support offices: IT and OT separation, engineering data protection, vendor remote access and evidence for customer supplier audits.
Carriers and fleet operators: dispatch and telematics system protection, mobile device control for drivers and identity hardening for shared terminals.
Hospitals, clinic networks and specialty practices: HIPAA risk analysis, ransomware resilience, medical device segmentation and patient data protection.
Suppliers supporting Fort Bliss and federal programs, plus public agencies: CMMC and NIST SP 800-171 readiness, CUI handling and Microsoft 365 hardening.
Accounting, legal, engineering and trade-consulting firms serving cross-border clients: client data protection, secure file exchange and phishing defense.
A cybersecurity assessment measures how well your current controls protect the operations that matter and produces a prioritized plan to close the gaps. DESSS runs it in five stages.
We identify the processes that must keep running, such as customs filing, dispatch, a production line or patient care, and the systems and partners involved.
Critical process map and scopeWe inventory users, devices, cloud tenants and every inbound and outbound partner connection, including EDI, SFTP, VPNs and portal integrations.
Asset and partner connection inventoryConfiguration reviews, vulnerability scanning and, where approved, penetration tests show which weaknesses an attacker could actually use.
Validated findings with evidenceFindings are mapped to NIST CSF and any customer or contract requirements, then ranked by how much disruption or loss each could cause.
Ranked risk registerWe produce a phased remediation plan with owners and effort, and DESSS can implement it alongside your team and retest the key fixes.
Remediation roadmap and retest reportDESSS is a Texas technology consulting firm headquartered in Houston, with an office in Austin, and its cybersecurity practice supports El Paso clients. These are the reasons organizations bring us in.
Speak with the DESSS security teamWe understand how ERP, WMS, EDI and carrier systems connect, so controls protect partner data flows without breaking the integrations your shipments depend on.
Office networks, warehouse automation and production equipment are assessed together, with changes scheduled around production and shipping windows.
The same team that assesses also implements identity, cloud, endpoint and network changes, so the roadmap gets executed rather than shelved.
Deliverables are written for auditors and customer questionnaires: risk registers, policies, network designs and test results you can share.
Assessment, implementation, integration and migration, managed support, or training and change management, matched to your size and timeline.
DESSS provides El Paso organizations with cybersecurity assessments, remediation and managed support covering Microsoft security, identity and privileged access, SOC and MDR, penetration testing, cloud and Zero Trust network security, endpoint and email security, data resilience, GRC, application and API security, and OT and IoT security.
A consultant pinpoints the weaknesses most likely to disrupt your operations and leads the work to fix them.
For El Paso businesses that often means securing trading-partner connections, stopping invoice fraud, separating plant networks from office IT and answering customer security audits.
Yes.
DESSS reviews Azure and AWS environments for exposed storage, excessive permissions, weak key handling and missing logging, secures integrations with on-premises systems, and sets up continuous posture monitoring to catch drift.
Yes.
DESSS tests partner-facing portals, APIs, SFTP and remote access gateways, internal networks and Active Directory, and can run red and purple team exercises. Testing windows are planned around shipping peaks and production schedules.
Zero Trust is a security approach that requires every user and device to prove who they are and that they are healthy before reaching any resource.
Access is narrow, networks are segmented, and nothing is trusted simply because it is inside the corporate network.
DESSS works with Active Directory, Microsoft Entra ID, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Intune and Microsoft Purview, plus Azure and AWS security services.
Identity engagements can include CyberArk, SailPoint, Okta and Ping Identity where they are already in place.
It begins by identifying the processes that must not stop, then inventories assets and partner connections, tests exposed weaknesses, ranks findings by business impact against frameworks such as NIST CSF, and ends with a phased remediation roadmap that DESSS can help execute.
Logistics and customs brokerage, manufacturing and maquiladora supply chains, transportation, healthcare, government and defense contractors, and professional services see the most benefit.
Each faces different pressures, from payment fraud to plant downtime and CMMC requirements.
DESSS combines assessment and hands-on delivery, understands how ERP, EDI and plant systems interconnect, and leaves written deliverables suited to customer audits.
It is a Texas firm headquartered in Houston with an Austin office, offering engagements from a single assessment to managed support.
Start with an inventory of every partner connection and the credentials behind it.
Then retire shared accounts, enforce MFA on portals, restrict SFTP and VPN access to specific systems, monitor transfers for anomalies, and include partners in third-party risk reviews.
Yes.
DESSS defines where Controlled Unclassified Information lives, assesses controls against NIST SP 800-171, drafts the system security plan and plan of action, implements missing technical controls and organizes evidence before a CMMC assessment.
Tell us which operation you can least afford to lose, a border crossing schedule, a production line, a hospital system or a defense contract, and DESSS will scope an assessment around protecting it.
The main DESSS cybersecurity page, the same services in other locations, and related reading.