Government and Public Sector
Spend public money on technology that lasts
The system was procured correctly, implemented on schedule, and is used by roughly half the staff it was bought for. The next council or board meeting will ask about the other half.
Public sector technology fails in public. A permitting portal that will not accept an application, a payroll run that misses a cycle, a records request that cannot be answered because the data lives in a system nobody supports — each becomes a meeting, a headline, or both. The accountability is personal and the record is permanent.
Procurement rules push agencies toward the lowest responsive bid and away from the flexibility to change course when a project starts drifting. So the drift continues to the demo, and the demo is where everyone learns the requirements were wrong.
IT21 provides oversight that is independent of the vendor and reports to you. On projects in flight, that means telling you at month four what the status report will say at month ten. On procurement, it means requirements written from how the work is done, with evaluation criteria a panel can actually apply. On operations, it means the controls and the continuity plan that a state audit, a single audit of federal funds, or a bad Tuesday will test.
What you get:
- Independent verification and validation on a project in flight, reported plainly enough for elected officials to read
- Cloud and hosted-service vendor review against the vendor’s real security authorization status, so you know what you are inheriting
- Access and change controls documented to survive a state audit or a single audit of federal funds
- Continuity planning for the services residents cannot go a week without
- Procurement support: requirements and evaluation criteria written to be evaluated against, not to be answered around
Cloud and hosted services carry a specific question for public buyers. A vendor’s security authorization is not always what its sales materials imply, and “in process” is not the same as “authorized.” When federal or state funds are involved, that difference can matter at contract signature and again at audit. We read the vendor’s real authorization status before you sign, so you know what you are taking on.
Assess is the current state, honestly reported. Transform is remediation or project correction, staged against your fiscal calendar since that is the constraint that actually governs. Optimize is the ongoing review cadence that keeps the next director from inheriting the same file.
Our background is the assurance side: sitting with auditors, testing controls, writing findings that hold up when someone disputes them. That is a useful temperament when the report goes into a public packet.
[PROOF: public sector engagement — entity type, region, scope, result — supply]
The IT Risk & Readiness Assessment is a defined, modestly scoped engagement that produces a documented risk picture — which is often exactly the artifact needed before a budget request or a board decision. It is measured against a recognized governance framework that public-sector auditors work from.
- Assess
- Transform
- Optimize
Oscar Chacon, CISA
Certified Information Systems Auditor since 1997
Not sure where you stand? Start with the assessment.
Request the AssessmentPublic-sector technology oversight — a brief
Vendor-independent project oversight, procurement criteria a panel can apply, cloud vendor authorization checked before signature, and continuity for the services residents depend on.
Get the PDF — enter your email
HubSpot form — assessment-request — not configured
Set portalId and forms.assessment-request in src/lib/hubspot.ts.
Start with the IT Risk & Readiness Assessment
A defined engagement, measured against a recognized control framework, that shows you which controls exist, which are documented but not operating, and which are absent — before you commit a budget.

