Case Studies: Real Engagements, Real Results
Every engagement starts with a problem worth solving — a week-long power outage, ransomware on an ordinary weekday afternoon, an attacker quietly staging to redirect vendor payments. Here's how the work actually went.
Case Studies
How We Help Inland Empire Businesses
These case studies are drawn from real eTop engagements. Company names and identifying details have been removed to protect client confidentiality — the problems, the work, and the outcomes are as they happened.
When the Power Went Out for a Week, This Law Firm Decided Never Again
The Challenge
A mid-size Southern California law firm ran everything on-premises — file servers, domain controllers, billing and accounting applications. Then Southern California's grid instability turned into a pattern: every half-day outage meant attorneys locked out of case files and billable hours walking out the door. When the wildfires triggered a week-long regional outage, the firm's entire operation was on the line.
Our Solution
First, the bridge: eTop sourced and deployed a generator that same week, keeping the firm operational through the crisis. Then, the fix: a phased migration to Microsoft Azure — files first, then application servers and identity, validating each phase — with the firm's legal billing and accounting systems preserved exactly as attorneys knew them. Security modernized along the way: Zero Trust remote access replacing VPN, consolidated Microsoft Defender, cloud disaster recovery.
The Results
- Core infrastructure now runs beyond the reach of local power failures
- Attorneys reach case files from court, home, or office — no VPN headaches
- A firm-wide migration with no disruptive cutover — billing never stopped
- The modernized monitoring later caught and contained a sophisticated phishing attack within minutes
The Ransomware Attack That Lasted Four Minutes
The Challenge
On an ordinary January afternoon, ransomware made its move on a workstation at an Inland Empire manufacturer: an encoded PowerShell command attempting token manipulation and secondary process execution. No suspicious attachment, no malware file sitting on disk — the exact attack pattern traditional antivirus misses, because there's no known-bad file to match.
Our Solution
The layered defense did its job, layer by layer. Behavioral detection identified the activity as ransomware staging and blocked execution before encryption started. Within minutes, 24/7 monitoring automatically isolated the host from the network — policy, not heroics. A critical incident report was triaged in seconds, and a senior engineer approved a formal remediation plan the same hour: credentials rotated, perimeter and endpoint logs audited, environment verified clean.
The Results
- Ransomware blocked at execution — zero files encrypted
- Compromised host automatically isolated from the network within minutes
- Structured remediation completed and verified the same day
- Production never stopped — most of the company never knew it happened
The Attacker Was Already Staging to Redirect Their Vendor Payments
The Challenge
A Southern California manufacturer lives on vendor email — invoices, remittance advice, payment details. That's exactly the traffic business email compromise (BEC) attackers want to sit inside. During routine monitoring, eTop's identity-monitoring stack flagged hidden inbox rules in a staff mailbox, built to intercept and bury payment-remittance emails from a major vendor — the classic staging pattern for diverting payments to attacker accounts.
Our Solution
The rules were disabled and the account secured the same day, before any payment moved. Then the whole pipeline got hardened: spam filtering re-tuned (moving roughly 6,000 additional junk messages a month out of inboxes), quarantine locked so confirmed phishing can't be self-released, and domain authentication strengthened so the company's own identity can't be spoofed. When attackers returned two months later with an adversary-in-the-middle attack, the monitoring caught that too.
The Results
- Two distinct email-compromise attempts caught before money moved
- Roughly 6,000 fewer junk messages reaching inboxes every month
- Email authentication hardened across company domains
- 24/7 monitoring that has proven itself twice against real adversaries
They Found the Same Server Cheaper. We Helped Them Buy It.
The Challenge
A mid-size Southern California engineering firm needed its aging core server replaced — right as the AI boom sent enterprise storage prices climbing 5–10% per week and stretched lead times past 90 days. eTop spec'd the right build and said the uncomfortable part out loud: prices had nearly doubled since fall, and we wouldn't cut the spec to hide it. The firm's operations team then did what good operators do — took our spec to the manufacturer directly and found it cheaper.
Our Solution
We didn't defend the markup. We reviewed the direct quote line by line, confirmed it met the environment's needs — and then upgraded it, swapping the storage to higher-performance NVMe drives that made the direct purchase better than our original quote. The firm ordered direct, with our blessing; eTop kept the work that actually needs an IT partner: deployment, migration, validation, and management. We also root-caused a year-old CAD crash problem (a deterministic profile-initialization fault — not the hardware) and rebuilt the deployment so it can't recur.
The Results
- Server purchased at the best available price — advice untied from markup
- New workstation fleet onboarded to a verified security and management standard
- Mission-critical CAD software stabilized with a documented root cause, not a shrug
- Entire fleet moved to Windows 11 ahead of Microsoft's end-of-support deadline
What a Structured Provider Transition Actually Looks Like
The Challenge
A Southern California construction company signed with eTop needing a full transition — new server, network, Microsoft 365, and security stack — while the previous provider's tooling was still on every machine and the business kept estimating, building, and billing. This is the scenario that keeps owners with the wrong provider for years: the fear that switching means chaos.
Our Solution
A project plan, not an act of faith. When the server's delivery date slipped, the client heard about it immediately — and everything that didn't depend on the server started anyway: network configuration, Microsoft 365 planning, and endpoint preparation ran in parallel. Discovery caught the previous provider's remote-management agents still running — including tooling nobody could account for — and every legacy agent was catalogued and removed. The phone cutover was deliberately held until the carrier confirmed timing, instead of forcing a date and breaking phones.
The Results
- Operations ran throughout the transition — no chaos, no dead air
- Previous provider's agents fully catalogued and removed from every endpoint
- Parallel workstreams with named owners instead of a single waiting line
- Monitoring and automation configured before go-live, not bolted on after
Modernizing a 75-Endpoint Dealership Without Closing the Showroom
The Challenge
A Southern California dealership — sales floor, service bays, parts counter, and back office on one network — had outgrown the legacy server-and-group-policy model: files on mapped drives, device settings that only applied when machines talked to the domain, and per-machine print and kiosk setups maintained by hand across roughly 75 endpoints. As a dealer handling consumer financing data, FTC Safeguards Rule expectations loomed over all of it.
Our Solution
Audit first, then migrate. eTop ran a full four-way endpoint audit — every machine cross-referenced across the service desk, deployment, remote access, and security monitoring platforms — clearing out ghost records and surfacing coverage gaps before anything moved. Then the phased shift: department files and home directories to SharePoint and OneDrive (with every mapping verified before cutover), device management to cloud-based Intune policy — including kiosk mode for shared floor machines and universal print — and endpoint security consolidated under Microsoft Defender.
The Results
- Every endpoint verified across four management platforms before migration
- Files reachable securely from any managed device — no file-server dependency
- Kiosk, print, and security policy enforced from the cloud, not per-machine
- Access controls and monitoring the dealership can demonstrate for FTC Safeguards and insurers
Our Approach
The Principles Behind Every Engagement
Every engagement follows the same principles that separate proactive IT from the break-fix cycle.
Security-First Design
Every environment starts with SOC monitoring, EDR, conditional access, and zero-trust principles as standard. Security is the foundation, not an add-on.
Compliance Expertise
Deep knowledge of the CIS Controls, WISP, the FTC Safeguards Rule, and industry-specific frameworks means compliance is built into every solution from day one.
Dedicated Teams
We intentionally limit our client count so every organization gets people who know their environment, their users, and their business goals — and who stay with the account over time.
Which of These Sounds Like Your Business?
Book an intro call. We'll review your current environment, identify risks, and show you exactly what a security-first managed IT partnership looks like for your organization. Qualifying businesses receive our $2,500 IT Risk Assessment complimentary.
Book an Intro Call →Or call us directly: (951) 398-0021