Q2 2026 vCIO Report
Composite mid-market client Β· Mid-market manufacturing Β· Greater Toronto Area, plus US plant
Headline + asks
On-track on every metric we publish, with one strategic risk that needs leadership decision this quarter.
Annual ransomware tabletop drill ran clean against the new playbook. SOC 2 Type II audit passed with zero findings.
Legacy ERP system reaches end-of-life Q4 2026. Vendor stops issuing security patches. Migration scoping needs board approval this quarter.
- Approve Q3 hardware refresh budget
- Decide ERP migration kickoff date β July recommended
- Decide Copilot rollout scope (50-seat pilot vs 220 enterprise)
Open + recently closed risks
| ID | Area | Severity | Status | ETA | Note |
|---|---|---|---|---|---|
| R-2026-04 | Legacy ERP system | open | Q4 2026 | Vendor patch cycle ends Sept 2026. Migration plan drafted; needs board approval. | |
| R-2026-05 | Plant 2 Wi-Fi infrastructure | Watch | in-progress | 2026-06-15 | Replacing aging APs; OT segmentation review in progress. |
| R-2026-06 | Privileged access management | Watch | in-progress | 2026-05-30 | JIT elevation rolling out to remaining 3 admin accounts. |
| R-2026-07 | Backup verification cycle | On track | closed | Closed Q1 | Weekly restore tests automated. Q1 spot-check passed clean. |
Actual vs target + 12-week trend
- P1 incident response < 1hr12-week trend100% actual100% targetβ
- Tickets touched within 15 min12-week trend94.2% actual95% target
- Monitored infrastructure uptime12-week trend99.97% actual99.9% targetβ
- Same-day callback acknowledgement12-week trend100% actual100% targetβ
- On-site arrival GTA < 2hr12-week trend98% actual95% targetβ
Quarterly horizon β start, completion, impact
- M365 β E5 license consolidation
- Plant 3 firewall replacement
- Copilot pilot β engineering team (12 seats)
- ERP migration scoping
- Annual DR drill
M365 β E5 license consolidation
Q2 2026Consolidates Defender + Purview + Power BI under one SKU. Per-seat saving estimated at low-double-digit %.
Plant 3 firewall replacement
Q2 2026Replacing EOL Fortinet appliance; new zero-trust segmentation policy + reduced PCI scope.
Copilot pilot β engineering team (12 seats)
Q3 2026Validates ROI + governance model before broader-rollout decision.
ERP migration scoping
Q3 2026High urgency β current platform EOL Q4. Discovery determines fixed-fee vs T&M scope.
Annual DR drill
Q4 2026Full failover from primary site to AWS DR region. Last drill (Q4 2025) passed; RTO 3.4hr against 4hr target.
Where to spend next
ERP migration kickoff (URGENT)
Must doCost band $$$Return horizon: 12-18 monthsCurrent ERP loses vendor support Q4 2026. Unpatched CVEs after that date materially raise insurance premiums and breach exposure. Migration cost is non-discretionary.
Copilot expansion to all 220 seats
Should doCost band $$Return horizon: 6 monthsPilot data lands Q3. Engineering team productivity expected to lead the case. License consolidation in current E5 plan reduces marginal cost.
Plant Wi-Fi refresh + OT segmentation
Should doCost band $$Return horizon: ImmediateOT/IT segmentation enables PCI scope reduction at retail-facing sites. Reduces cardholder data environment by an estimated 60%.
Optional: Defender for Cloud Apps for SaaS sprawl visibility
OptionalCost band $Return horizon: 3 monthsDiscovery audit found 47 unauthorized SaaS apps in use. Visibility is the precondition to governance.
Where we stand on each framework
SOC 2 Type II
Audit passedQ1 audit completed with zero findings. Continuous evidence collection via Vanta running. Next audit window: Q1 2027.
CIS Controls v8 (IG2)
AlignedIG2 baseline maintained; IG3 controls mapped, not yet enforced (decision deferred to next vCIO cycle).
ISO 27001
AlignedInternal ISMS in place; client deferred external audit to 2027 to coincide with ERP migration completion.
PCI-DSS 4.0
AttentionPlant 3 firewall refresh closes the last remaining gap. Compliant once project completes (Q3 2026).
What's under management
- 247endpoints
- 235identities
- 3sites
- 2cloud tenants
- 365dbackup retention
EDR coverage: 100% of corp endpoints + compensating monitoring on OT
Composition + spend trend + optimization finds
- Microsoft 365 + Azure42%
- AWS workloads18%
- Endpoint security stack16%
- Backup + DR12%
- VoIP + comms7%
- Other tooling5%
- 4 dormant Azure VMs in eastus2 β recommended decommission
- 23 unused E3 licenses identified β recommend reclaim or downgrade to E1
- AWS S3 lifecycle policies missing on 2 buckets β cold tier saves low-4-figures/yr
- Power BI Premium capacity rightsized β confirmed pre-implementation
Decisions for leadership this quarter
- 01Approve ERP migration discovery budget (cost band $$$) β kickoff July
- 02Decide Copilot rollout scope: 50-seat pilot vs 220-seat enterprise
- 03Confirm Q4 DR drill date β recommend October (before holiday freeze)
- 04Sign-off on PCI-DSS attestation post Plant 3 firewall completion
This is what every Kootechnikel vCIO client gets, every quarter.
No PowerPoint theatre. No invoice padding. Just an honest scored review with the decisions you actually need to make. Want one for your environment?
Book a free IT health check β first vCIO read for free