Assessment first
Before we change anything we inventory what exists: devices, users, permissions, network gear, backups and where sensitive data actually lives. Free, remote, and yours to keep.
Remote IT Support · San Antonio, TX
Orca IT supports San Antonio businesses remotely from Gilbert, Arizona with managed IT, help desk, network administration and layered security. You get one pod of our own engineers on every ticket. In a city where cyber security is a local industry, we are happy to be held to that standard.
San Antonio, TX
Few metros have this much cyber expertise concentrated in one place, which raises the bar for anyone selling IT services here.
The military and defense presence around Joint Base San Antonio and the cluster of contractors at Port San Antonio have made information security a genuine local industry. That has a knock-on effect: suppliers, engineering firms and professional services businesses in this market get asked harder questions than their counterparts elsewhere. NIST SP 800-171 controls and CMMC readiness are ordinary conversation for a small manufacturer here, not an exotic project. We build and document those technical controls, access control, MFA, encryption, audit logging, media protection, incident response procedure, and prepare the evidence. We are not a certified assessor and will never claim to be.
The second pillar is health. The South Texas Medical Center anchors a wide network of specialty practices, imaging centers, bioscience firms and the vendors who serve them. Their needs are practical and constant: EHR servers that stay responsive, imaging workstations that do not stall, secure messaging, encryption everywhere, and backups that have been restored in a test rather than trusted on faith. HIPAA technical safeguards get built and written down so a risk assessment has something to reference.
Then there is the visitor economy. The River Walk, the convention business, hotels, restaurants and attractions run on point-of-sale, property management and booking systems that must not fail on a Saturday. Card data brings PCI DSS obligations, and the biggest practical risk is usually a flat network where the guest Wi-Fi, the back office and the terminals all share a broadcast domain. Segmentation, isolated guest networks, controller-managed access points and monitored uptime are the fix, and every part of it is done remotely.
Orca IT operates from Gilbert, Arizona and has no staff in San Antonio. The configuration, monitoring, security and help desk work all happen through remote support and Pod Care. When something has to be physically touched, a switch racked, a dead workstation, cable run to a new suite, we arrange a vetted local technician for that step with your approval and direct the work live. Texas neighbours run the same model in Austin, Houston and El Paso.
Pod Guard is layered by default: EDR, MFA and conditional access, email authentication, DNS filtering, phishing simulation, dark web monitoring and tested backups.
Services
Defense supply chain, healthcare, hospitality and the professional firms that serve them.
Control-by-control implementation of the technical requirements, a system security plan your team can actually maintain, and a plan of action for the gaps. Evidence packaged for your prime contractor’s review.
Separating and protecting sensitive contract data: scoped access, encryption, removable media policy, secure file transfer, and logging that shows who touched what and when.
Encryption at rest and in transit, unique user identification, audit controls, automatic logoff, secure messaging and restore-tested backups for practices around the Medical Center.
Card-handling systems separated from guest and staff networks, isolated guest Wi-Fi, monitored point-of-sale connectivity, and a network diagram that survives an assessor’s questions.
Entra ID hygiene, MFA and conditional access, joiner and leaver processes that actually run, mailbox audit, and licensing right-sized instead of renewed on autopilot.
Pod Watch on every endpoint and server: operating system and third-party patching, disk and RAID health, backup job verification and alerting that catches failures before your staff do.
How It Works
Before we change anything we inventory what exists: devices, users, permissions, network gear, backups and where sensitive data actually lives. Free, remote, and yours to keep.
Live sessions start with a one-time link you launch. Unattended agents go only on devices you approve, and we will show you the full list any time you ask.
Connections are outbound and encrypted, your screen stays visible throughout, and you can end a session with one click. Every connection is recorded.
Fixes, changes and test results are written down. In a market full of security questionnaires, that written trail turns out to be as valuable as the fix itself.
We do not observe daylight saving, so we are two hours behind San Antonio in summer and one in winter. Our desk is still working after yours closes.
No. We are a family-owned Arizona company working from Gilbert, and we support San Antonio clients remotely. Physical work is arranged through a vetted local technician when it is genuinely needed, with your approval and with our engineers directing the visit and doing the configuration.
No vendor can. Certification comes from an authorised assessment organisation. What we can do is implement and document the technical controls in NIST SP 800-171, help maintain your system security plan and plan of action, and prepare the evidence so an assessment is not a scramble.
The priority is segmentation. Guest Wi-Fi, staff devices and card-handling systems go on separate networks with firewall rules between them, access points are controller-managed and monitored, and point-of-sale connectivity is alerted on. That removes the most common way a hospitality business gets breached.
Arizona time, which does not shift for daylight saving. From March to November we are two hours behind San Antonio, and one hour behind for the rest of the year. Maintenance windows are always scheduled and confirmed in your local time.
We do. We hold the technical call with the vendor, gather the evidence from monitoring and packet-level checks, and either prove the network is clean or fix what is wrong. Either way your practice manager stops being the go-between.
It is worth scrutinising, which is why we treat it as production security. Named engineer accounts with MFA, least-privilege rights, encrypted outbound connections, no exposed RDP, visible session indicators and full logging. You can review the list of agents we can reach at any time.
Start with a free remote assessment of your controls and exposure. The findings are yours regardless.
Talk to Your Pod
The Deep Dive is a remote assessment of your devices, identity, access control, backups and exposure, delivered as a prioritised plain-English list you keep either way.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.