Compliance
Services

As companies grow and evolve, they often must deal with one form of compliance if not multiple! Most IT companies can offer rudimentary technical support. However, one of our main differentiators is our compliance services. Often growing companies need to seek a 3rd party consulting firm outside of their IT department to handle the compliance. Not with ICE! We have helped countless companies with a variety of compliance requirements over the years.
Not only do we staff compliance specialists that can be assigned to your technical team of experts, but we also are SOC 2 Type II Certified. If your company is looking for
help with compliance from an IT provider they must have their SOC 2 certification, and only about 5% of managed IT providers have their actual certification.
Time consuming and tedious compliance can chew up an immense amount of time and resources. With ICE, your teams can remain focused on growing your core business while we take care of the rest!
Types Of Compliance We Can Assist You With:
Here are some
recent examples
of companies
we helped with
their compliance:

Biotech Company Enlists
ICE Consulting’s Assistance
in ISO 27001 Compliance
Industry: Biotech & Life Sciences
Company size: 1,000+ Employees ($4 Billion Market Cap)
Location: South San Francisco, California
Read Case Study
Challenge:
A $100-million-a-year biotech company was seeking compliance based on the ISO 27001:2013 standards published by the International Standards Organization (ISO) located in Switzerland. The ISO 27001 standard is the framework that quantifies the vulnerabilities and threats of the ISMS (information security management system) of an international organization. It includes assessing the processes and policies of how a company uses and controls data. ISO 27001 is considered one of the toughest compliance certifications to obtain and maintain.
Solution:
This synthetic biology company hired ICE Consulting for help with the IT-related portions of both the preparation and evidence gathering phase, and the audit phase of the ISO certification process beginning in 2018. ICE provided the necessary documents for:
- Capacity planning and incident response planning
- Diagrams such as network time standards and physical network layout
- General policy and security consulting
- Consultation with the company during the audit process to assist and answer questions from the auditors
- 100+ hours of consultation
Results:
With the help of ICE Consulting’s compliance specialists, our biotech client became ISO 27001 certified in late 2019, and we have continued to help the company maintain its certified status every year since then. We also assisted our client in obtaining an additional ISO certification for the manufacture of medical equipment, ISO 13485.

ICE Helps Medical Technology Company
Meet Hi-Trust Compliance—HIPAA
on Steroids
Industry: Biotech & Life Sciences
Company size: 1,000+ Employees ($4 Billion Market Cap)
Location: South San Francisco, California
Read Case Study
Challenge:
ICE Consulting has helped with the IT needs for some of the most innovative biotech startups in the San Francisco Bay Area— a hotbed of biotech activity. A growing biotech company needed help setting up, designing, and building out the IT infrastructure at its first site so it could concentrate on research and development activities.
Solution:
ICE Consulting brought together a team of highly skilled and experienced IT project managers, IT architects, and IT project network/system engineers to help facilitate the needs of this and many other biotech clients in the design and building of these new sites. ICE helped the client expand and relocate into their first new workspace in a brand-new building from an incubator space. ICE helped in these ways:
- Designed and built a new office IT plan by working with the site General Contractor (GC) and participated in the construction meetings during the initial phase of the project to ensure all IT-related requirements were coordinated in the construction plans.
- Designed the structured wiring plan with the low-voltage cabling contractor to ensure adequate cabling to meet the needs of the client.
- Worked with ISP vendors to establish service in the new building for the client including IP requirements, bandwidth needs, and proper handoff to the planned client hardware.
- Partnered with an audio/video consulting firm to plan out the conference room design and equipment needs including room schedulers, room controllers, cameras, speakers and microphones, and auxiliary equipment and connections necessary for the client, as well as sound-deadening equipment to reduce the ambient noise in the workspace.
- Evaluated the design and sizing of the server/MDF (Main Data Feed) and IDF (Intermediary Data Feed) rooms and passed on the GC for inclusion in the final plans
- Evaluated, documented, and provided the power requirements and HVAC (Heating, Ventilation, & Air Conditioning) requirements for the Server / MDF room and the IDFs to the contractors, for the planning of the respective portion of tenant improvements.
- Designed the IT infrastructure (both Systems and Networks) for the new site using industry design guides and infosec compliance regulations to ensure cybersecurity is an integral part of the design, not an afterthought.
- Recommended the appropriate security and threat management capabilities for the selection of the new firewalls and edge infrastructure (ISP to the internal network). ICE only recommends the industry-leading vendors for Firewalls such as FortiGate or Palo Alto Networks.
- Leveraged ICE partner relationships with technology vendors such as VMware, Okta, CarbonBlack, Code 42, Microsoft, and others.
- Designed and executed the cloud technology stack for the client including Identity Management, Single Sign-On (SSO) & Multi-Factor Authentication (MFA) using Okta, implemented a Mobile Device Management (MDM) solution using Workspace One, and Corporate Productivity and E-mail with Microsoft M365.
- Emphasized security of the client’s corporate data, ICE installed and configured disk encryption solutions, and much more.
Results:
Thanks to ICE Consulting, the biotech client now has an infrastructure that is properly designed, configured, and installed. This will allow the biotech company to fully use the latest technology today and tomorrow as the biotech company grows and prospers. For this client and others, ICE continues to update, maintain, and improve the security and performance of the installed infrastructure.
ICE has performed this kind of work many times in the San Francisco Bay area and has developed a reputation for these “greenfield” builds with biotech start-ups. Our solutions have met client needs by providing highly scalable, secure, and reliable infrastructure. With ICE Consulting’s IT infrastructure assistance, many of these clients have grown from small start-ups to more than 1000-employee, multi-national enterprises.

US Government Contractor Adopts
NIST 8000-Cybersecurity Framework,
Thanks to Assistance from ICE
Industry: Department of Defense (DOD) Prime Contractor
Company size: 300+ Employees (Private company)
Location: Palo Alto
Read Case Study
Challenge:
This US government contractor is required to comply with the standards of NIST regulation 800-171. The Cybersecurity Framework (CSF) details the policies, procedures, and steps necessary to protect an organization from possible threat situations that government organizations and contractors face from bad actors both internal and external.
Solution:
ICE worked with the contractor to make the necessary changes to their IT infrastructure. We worked with the customer’s security personnel to set up the right hardware including new next-generation firewalls, advanced management software, and compliant VPN services to meet the standards.
Results:
Thanks to ICE Consulting, the government contractor met the standards to become NIST 800-171 compliant. ICE is currently assisting the customer on the CMMC (Cybersecurity Maturity Model Certification) process.
