Case Study · Impact

Enterprise Cybersecurity Program.

A multi-year cybersecurity program — MFA, patching cadence, and endpoint hardening — across the field operations of a national multi-site retail and fuel operator with 800+ locations.

Engagement at a glance.

TitleEnterprise Cybersecurity Program
CategoryEnterprise Cybersecurity
OrganizationA national multi-site retail and fuel operator (800+ locations)
Scale800+ distributed field locations
RoleSenior Project Manager III
DurationMulti-year program

A threat surface the size of a country.

The operating footprint was 800+ stores and fuel sites, each running point-of-sale, back-office, and corporate-managed endpoints behind inconsistent access controls. Multi-factor authentication rollout had stalled in the field. Patch cadence drifted quarter to quarter. Endpoint hardening standards existed on a slide deck but were not enforced at the site level, and reporting back to executive leadership was loose compared to what the threat surface demanded. As the footprint grew, the exposure window widened with it.

Owning the program, not just the rollout.

I program-managed the cybersecurity program and partnered with InfoSec leadership to align priorities, capacity, and budget. I directed the rollout of MFA, the patching cadence, and the endpoint hardening standards across the fleet, and I coordinated with Operations and Store Operations so that field rollouts did not collide with store-level activity. I designed the executive steering rhythm, oversaw the reporting cadence that surfaced exposure trends, and coordinated with Technology and Legal on the regulatory posture the program needed to hold. The work was governed, staffed, and measured — not a one-time project.

Governance, alignment, risk, and systems.

Governance ran on a regular cadence: a maintained risk register reviewed with executive leadership, vulnerability scoring that prioritized remediation by business impact, and remediation SLAs tied to severity bands. I coordinated with the CISO function, Operations, and field-site general managers so the program reflected the realities of distributed retail: weekend cutovers, regional variations, and the constraints of store-level bandwidth. Risk management meant deciding what to fix first, accepting residual risk in writing, and reviewing it quarterly — not running an endless backlog or letting the loudest voice set the schedule.

The systems did the heavy lifting. Multi-factor authentication was rolled out across 800+ locations on a phased schedule tied to operational risk. Patch management moved to a defined cadence with documented exceptions and a clear owner at the regional level. Endpoint hardening standards were written down, deployed through management tooling, and audited against a measurable baseline. I partnered with Procurement on the contract terms behind the tools so renewal cycles did not break the operating rhythm. The program was designed to outlast any single tool, vendor, or team — that was the point.

What changed.

The program delivered a 40% reduction in threat exposure — measured across the MFA rollout, patching cadence, and endpoint hardening deployed across 800+ locations. The result came from disciplined program management and stakeholder alignment, not from a single product purchase or a one-time deployment.

Working on something similar?

If a distributed environment needs a cybersecurity program with real governance behind it, let's talk.

Book a Call →