Skip to content

Service area

Managed IT services in Olympia and Lacey

The state capital produces a business base unlike anywhere else in the South Sound: a large concentration of firms whose principal customer is a government agency. That changes the IT requirements, because the demands arrive through contract security schedules rather than through a regulator.

Where the requirements come from

Contract schedules

not a regulator

Contractual security obligations are enforceable commercially. Read the schedule before signing, not at renewal.

A government adjacent economy

Olympia and Lacey carry a dense population of consultancies, professional services firms, technology suppliers and contractors whose revenue depends substantially on state agencies. Around them sit healthcare, education and the commercial base serving a large public sector workforce.

For an IT provider the relevant consequence is that a great many businesses here have security obligations they did not choose and did not expect, written into agreements by a customer rather than imposed by a regulator.

What a contract security schedule asks for

The specifics vary by agency and by contract, but the recurring themes are consistent and none of them are exotic.

  • Multi factor authentication on any system touching agency data
  • Defined access control with periodic review, evidenced
  • Incident notification within a stated timeframe from discovery
  • Data handling and retention rules, sometimes including where data may be stored
  • Subcontractor flow down, so your own vendors carry the same obligations
  • In some cases, the right to audit or to require evidence on request

The demanding word in nearly every one of those is evidenced. Doing the thing is not sufficient if you cannot demonstrate it happened, which is why logging and review records matter more here than in a comparable commercial business.

Common questions

Answered before you ask.

We contract with state agencies. Does that bring IT requirements?

Often yes, and they arrive through the contract rather than through a regulator. Public sector agreements increasingly carry security schedules covering data handling, access control, incident notification and sometimes the right to audit. These are contractual obligations, which means failing them is a commercial problem rather than a regulatory one, and they are enforceable in ways that catch suppliers by surprise. Read the security schedule before signing rather than at renewal.

Olympia is in Thurston County. Are you actually local?

It is at the outer edge of our working radius rather than the centre of it, and we would rather say that plainly. Remote support is unaffected. For onsite work, response is realistically same day rather than within a couple of hours. If your operation genuinely needs someone in the building within an hour, a provider based in Thurston County is a better fit and we will say so.

What is different about supplying government rather than commercial clients?

Evidence and documentation. Commercial clients generally take security assurances at face value. Public sector contracts increasingly require you to demonstrate controls, sometimes with the right to inspect, and payment or renewal can depend on it. That means logging, access reviews and incident procedures need to be recorded as they happen rather than reconstructed when someone asks.

Start with the assessment, not the contract.

We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.

CallFree assessment