Technical control implementation
Access control, authentication, audit and accountability, configuration management, media protection and incident response, implemented and mapped control by control with evidence retained.
Remote IT Support · Washington, DC
Orca IT provides remote managed IT, cyber security and help desk to Washington DC organisations from Gilbert, Arizona. One pod of our own engineers owns your account. In a market shaped by federal requirements, we build controls that can be evidenced rather than described.
Washington, DC
Government contractors, trade associations, nonprofits, law and lobbying firms, media and universities, the common thread is that somebody with authority eventually asks for proof.
Contracting shapes the market. A small firm holding a federal subcontract, or hoping to, faces NIST SP 800-171 requirements, CMMC preparation, controlled unclassified information handling rules, incident reporting obligations and flow-down clauses written by organisations far larger than itself. The work is unglamorous and specific: scoped access to controlled data, multi-factor authentication, encryption in transit and at rest, audit logging with real retention, configuration management, media protection and a written incident response procedure. We implement and document those technical controls and prepare the evidence. We are not a certified third-party assessor and we will never tell you otherwise.
Associations and nonprofits along K Street and around Capitol Hill have a different profile with the same underlying need. They hold member and donor data, run association management and fundraising platforms, host events, and answer to boards and auditors who ask sharp questions about data protection. Their staff turnover is often high and their budgets are fixed, which makes standardised onboarding and offboarding, clean identity management and predictable flat monthly costs unusually valuable.
Law, lobbying, media and consulting firms round it out. These are targets, plainly: high-value information, tight deadlines, executives who travel, and adversaries who are considerably more capable than the average criminal. Phishing-resistant authentication, endpoint detection and response, controlled external sharing, mailbox rule monitoring and staff training are not optional extras here. That programme is Pod Guard.
We are a family-owned Arizona company in Gilbert with no Washington office and no staff in the district or Northern Virginia. Identity, cloud, server, network and help desk work is delivered through remote support and Pod Care. If hardware fails or a suite needs cabling, we arrange a vetted local technician for that task with your approval while your pod directs the work. Corridor neighbours are served the same way in Philadelphia, New York and Charlotte.
In this town, an undocumented control is an unfunded promise.Orca IT, Gilbert AZ
Services
Six services shaped by federal requirements, member data and a high-threat environment.
Access control, authentication, audit and accountability, configuration management, media protection and incident response, implemented and mapped control by control with evidence retained.
Identifying where controlled information actually lives, reducing the scope, separating it from general data, and controlling how it moves in and out of the organisation.
MFA with stronger methods where the risk warrants it, conditional access, separated administrative accounts, and access reviews that are performed and recorded on a schedule.
Controlled access to association management and fundraising platforms, encryption, retention policy, and clean onboarding and offboarding for a workforce that changes often.
Centralised, retained logs for identity, endpoints and cloud services, so an investigation can reconstruct what happened rather than guessing at it weeks later.
Same-business-day human help for the office, home and travel, with after-hours emergency response for Pod Care clients when something genuinely cannot wait.
How It Works
We document which systems we access before we access them, and which are excluded. Nothing is enrolled quietly and you can request the full inventory at any time.
Each engineer connects with an individual MFA-protected account holding only the rights the task requires. There are no shared logins and no standing domain administrator use.
Attended support runs from a one-time link you launch, over an encrypted outbound connection you can watch and end with one click. No inbound remote desktop exposure, ever.
Who connected, to what, when and for how long, retained and available to you. That record supports your own reporting obligations as well as our accountability.
Arizona does not observe daylight saving, so we sit three hours behind DC in summer and two in winter. Your late afternoon is our middle of the day.
No, and neither can any other IT provider. Certification is issued by an authorised third-party assessment organisation. We implement and document the technical controls in NIST SP 800-171, help maintain your system security plan and plan of action and milestones, and prepare evidence so the assessment is not a crisis.
No. Orca IT is family owned and based in Gilbert, Arizona, supporting Washington clients remotely with our own employees. Physical work is arranged with a vetted local technician for that specific task, with your consent, while our engineers direct the visit and handle the configuration.
The first job is scoping: finding where it genuinely lives and reducing that footprint, because a smaller boundary is cheaper and safer to protect. Then separation, access control, encryption, monitored transfer paths and logging. We document the boundary so it is defensible rather than assumed.
Arizona stays on Mountain Standard Time all year, so we are three hours behind Washington from March to November and two hours behind for the rest of the year. Our afternoon covers your close of business, and maintenance windows are always agreed in Eastern time.
Yes. We maintain a written record of controls, access reviews, patch compliance, endpoint coverage and backup test results. That turns board and audit questions into a document you already have rather than a fortnight of assembling screenshots.
Pod Care is flat monthly per-user pricing with no long-term contract required, which makes budgeting straightforward. We also start with the free assessment and tell you which few changes remove most of your risk, so you can sequence spending rather than facing it all at once.
Book the free assessment and get an honest map of where you stand against what you are being asked to meet.
Talk to Your Pod
The free Deep Dive maps your identity, endpoints, access, logging, backups and data handling against the requirements you are actually being asked to meet.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.