Bristol Bay Economic Development Corporation operates as a regional economic development nonprofit based in Dillingham, relying on fund/grant accounting, shared file storage, and hybrid Active Directory/Microsoft 365 identity to serve staff across the region. Vicinity took over management of BBEDC's environment at the start of 2026, following a transition from a prior IT provider — much of this year's work has focused on stabilizing the environment, deploying a consistent security stack, and retiring tools and hardware left behind from that transition.
Organizations that switch IT providers often carry forward legacy agents, tools, and hardware that no one is actively managing — these create blind spots for both security and support.
Since taking over in early 2026, we've deployed SentinelOne endpoint protection fleet-wide across every server and workstation, and we're actively identifying and retiring tools and hardware left behind by the prior provider — including a legacy virtual server and a decommissioned physical server still connected to the network. See Recommended Initiatives for the remaining cleanup items.
Nonprofits and regional development organizations that manage grant funds and vendor payments are frequent targets of email spoofing and wire fraud schemes, which increasingly bypass basic email filtering.
BBEDC has direct experience with this risk. MFA is already enforced org-wide; we're now prioritizing email anti-phishing configuration and scoping a tabletop security exercise for staff — see the Security Posture and Recommended Initiatives sections below.
Server and network hardware have a limited useful life, and running past end-of-support windows increases the risk of unpatched vulnerabilities and unplanned downtime.
A new network switch and a new Network Policy server (running Windows Server 2025) were deployed this year. We're tracking the remaining aging hardware — including a 2017 physical server nearing the end of its useful life — for a future refresh conversation.
How your IT environment supports BBEDC's business goals and operations.
| Business Priority | IT Dependency | Current Status | Notes |
|---|---|---|---|
| Grant & Fund Accounting | AccuFund Accounting Suite (hosted on-prem) | Attention | Managed jointly with 3rd-party vendor ComputerWorks NFP Solutions; runs on an aging server OS |
| Remote & Field Staff Access | WatchGuard SSL VPN Mobile | Healthy | Remote access functioning as expected |
| Shared File Access | BBEDC-FILE01 (mapped as Z:\ on workstations) | Healthy | Central file storage on hybrid AD/M365 environment |
| Phone & Communications | NEC phone system with Aastra handsets | Healthy | No issues reported |
| Fraud Prevention & Data Security | MFA, email security, endpoint protection | Attention | MFA is enforced org-wide; remaining gap is email anti-phishing configuration — see Security Posture |
| Area | Status | Details |
|---|---|---|
| Patch Management | Current | Servers and workstations patched via Vicinity RMM |
| Endpoint Protection | Active | SentinelOne deployed fleet-wide across all servers and workstations |
| Backup / BCDR | Attention | Datto SIRIS protecting 5 of 6 virtual servers; backup for the new NPS server is currently paused |
| Identity / MFA | Active | MFA enforcement is on org-wide; all 19 licensed staff have a registered MFA method |
| Network | Review | New firewall-side switch in place; legacy hardware pending confirmation of removal |
Key business applications in use at BBEDC.
| Application | Purpose | Vendor / Platform | Notes |
|---|---|---|---|
| AccuFund Accounting Suite | Fund & grant accounting | AccuFund, Inc. | Application support via ComputerWorks NFP Solutions |
| Microsoft 365 Apps | Email, documents & collaboration | Microsoft | Word, Excel, Outlook, Teams, OneDrive |
| Adobe Acrobat & Creative Cloud | Document & design work | Adobe | Renewal due August 2027 |
| Zoom Workplace | Video conferencing | Zoom Communications | |
| Google Chrome / Mozilla Firefox | Web browsers | Google / Mozilla | |
| Grammarly | Writing assistant | Grammarly Inc. | |
| WatchGuard Mobile VPN with SSL | Remote access client | WatchGuard | Used by remote & field staff |
| Document & Check Scanning Suite | Check processing & document capture | Nuance / PFU ScanSnap / Digital Check | Used for banking & records workflows |
What this score actually tells us
Microsoft Secure Score measures adoption of Microsoft-native security tools — it doesn't account for third-party solutions like SentinelOne. BBEDC's score of 41.6 reflects gaps in Microsoft's own stack, not the full picture of your protection.
Your real posture is stronger than the score suggests. Identity (MFA) and endpoint security are solid. The genuine gap is email security configuration — several of Microsoft Defender's anti-phishing and impersonation protections aren't fully enabled yet, which matters given BBEDC's prior experience with email fraud. That's where we'll focus.
BBEDC currently scores below the 46.8 average for organizations of similar size — closing the email security gaps is the fastest path to closing that difference.
MFA enforcement is on org-wide via Microsoft Entra Conditional Access, and all 19 licensed staff have a registered MFA method. This layer is covered.
SentinelOne EDR is deployed across every server and workstation — a best-in-class solution Secure Score doesn't credit. This layer is covered.
Impersonation protection, phishing thresholds, and quarantine rules in Microsoft Defender aren't fully configured. This is the primary gap driving the lower Secure Score — and the highest priority to fix.
| Control | Solution | Status |
|---|---|---|
| Endpoint Detection & Response | SentinelOne | Active |
| Email Security | Microsoft 365 Defender | Attention |
| Multi-Factor Authentication | Microsoft Entra Conditional Access | Active — Enforced |
| Backup / BCDR | Datto SIRIS | Attention |
| Firewall / Network Security | WatchGuard Firebox T40-W | Active |
| Patch Management | Vicinity RMM | Active |
| Microsoft Secure Score | Microsoft 365 Defender | 41.6 / 100 |
- MFA enforcement is on org-wide, with all 19 licensed staff carrying a registered MFA method — a strong identity posture that Secure Score doesn't fully reflect.
- SentinelOne EDR is deployed across every server and workstation, replacing antivirus tools inherited from the prior IT provider — also uncredited by Secure Score.
- Microsoft Secure Score sits at 41.6 / 100, below the peer average of 46.8, driven almost entirely by open email anti-phishing recommendations.
- Nearly all top-recommended Secure Score actions relate to email impersonation and phishing protection — directly relevant given BBEDC's prior experience with email fraud.
- Anti-phishing protections incomplete — Microsoft Defender recommends enabling impersonation protection, adjusting the phishing confidence threshold, and quarantining messages from impersonated domains; none are yet enabled. This is directly relevant given BBEDC's prior email spoofing incident, in which a fraudulent wire transfer was narrowly stopped by Wells Fargo before funds were lost.
- Legacy hardware still network-connected — a decommissioned physical server remains powered on and connected to the network, and a legacy backup appliance's status is still being confirmed.
Strategic IT projects and improvements recommended for BBEDC in the coming period.
| Initiative | Priority | Timeline | Rationale |
|---|---|---|---|
| Address Secure Score anti-phishing recommendations | High | Next 30 days | Primary gap driving Secure Score; directly reduces email fraud exposure |
| Scope & schedule tabletop security training | High | Before end of 2026 | Requested by BBEDC; reinforces fraud/phishing awareness for staff |
| Resume paused backup protection for BBEDC-NPS1 | High | Next 30 days | Backup agent is currently paused; server has no active backup coverage |
| Decommission legacy physical server (BBEDC-HOST2) | Medium | Next 90 days | Powered on and network-connected with no active management |
| Confirm & retire remaining legacy network/backup hardware | Medium | Next 90 days | Older switches and legacy backup appliance pending confirmation of removal |
| Review legacy virtual server from prior IT provider | Low | Ongoing | Running outdated security tooling from before the transition to Vicinity |
- Smooth transition of IT management from BBEDC's prior provider with no service disruption
- Fleet-wide deployment of SentinelOne endpoint protection across all servers and workstations
- Deployment of a new Network Policy server (BBEDC-NPS1) and a new network switch
- Migration to Datto SIRIS as the primary backup and disaster recovery platform
- Adobe Creative Cloud / Acrobat renewal due August 26, 2027
- Potential hardware refresh for aging on-prem servers running Windows Server 2016
- Tabletop security training engagement (scoping in progress)
- Finish closing out tooling and hardware left behind from the prior IT provider transition
- Close the remaining email anti-phishing and impersonation protection gaps in Microsoft Defender
- Build a hardware refresh roadmap ahead of Windows Server 2016 reaching end of support
- Continue reliable support for AccuFund and BBEDC's fund/grant accounting operations
Thank you, Bristol Bay Economic Development Corporation.
We appreciate the trust you place in Vicinity to support your business. Our commitment is to keep your IT reliable, your data secure, and your team focused on what matters most.
Questions? Reach us anytime at support@vicinity.team · (866) 520-6414