
Founded in October 2001, DenMar Services, Inc. is an employment agency headquartered in Lawton, OK. DenMar is a woman-owned small business with extensive work experience and expertise in the U.S. Government service contracting business.
Technologies Used
● Dell PowerEdge T560 and T160 Servers
● Microsoft Windows Server 2025 with Hyper-V
● Sophos XGS 108 Firewall with Xstream Protection
● Ruckus R550 Access Points
● HPE Switch Networking
● ArmorPoint 360 Managed Security
● SentinelOne with integration to ArmorPoint
● Mimecast Email Security
● Datto Encrypted Local and Cloud backup solution
● Datto RMM for Remote Management and Monitoring
Services Used
● IT Infrastructure
● Cybersecurity and SecOps
● Incident Response
● Procurement
● Managed Services
When Everything Stops
Ransomware doesn’t announce itself. The team at DenMar Services arrived at work one morning to find their systems had been hit overnight. Files were inaccessible. Servers were down. Operations had stopped.
This kind of attack can happen to any organization, and increasingly, it does. For DenMar, a government contractor whose employees support FAA and Department of Defense operations, the timing added a specific pressure: Mission-critical operations had a hard deadline, and their reputation within the government contracting community depended on meeting it.
They reached out to InterWorks. We got to work.
The First Hour
DenMar connected with InterWorks through a referral — a former contact who had worked alongside our team at a different company years earlier and remembered the relationship. The call came in, and within minutes it was in the hands of our client services and engineering team.
Our first step was understanding the scope of what they were dealing with: What systems were affected, what their backup situation looked like and what recovery options might exist. With that picture established, the InterWorks SecOps joined the conversation immediately to assess the ransomware variant and begin mapping the response.
Within an hour of that initial call, one of our engineers was on-site at DenMar’s Oklahoma City office.
“We lost 25 years’ worth of computer files and not only in one company but in two companies. We had planned and thought we had the perfect back up plans in place and in less than 3 seconds everything was encrypted including backups.”
—Quetta Fritsch, President, DenMar Services
The Complication Nobody Plans For
Most incident response conversations focus on getting systems back up. For a government contractor, there’s an additional layer that runs parallel to recovery: Compliance obligations.
Federal contractors have specific reporting and documentation requirements when a security incident occurs. Our SecOps team knew what those were and guided DenMar through every step — ensuring they met their obligations to the appropriate government agencies while the engineering team worked in parallel on recovery.
That combination matters. A lot of IT providers can handle one or the other. Handling both at once, without dropping either, is what kept DenMar’s situation from becoming more complicated than it already was.
“Being a government contractor brought in special reporting requirements and included the FBI. InterWorks knew the requirements and the processes to keep us on track with all the immediate reporting security requirements. InterWorks was on site within one hour of our initial conversation. InterWorks’ customer service standard is taken seriously and beyond any level of expectations.”
—Quetta Fritsch, President, DenMar Services
The Overnight Server
Here’s what the response actually looked like on the ground.
Most IT providers in an emergency like this would have told the client to wait — two days for parts to ship, a week to schedule an engineer. DenMar didn’t have that kind of time, so our team found another way.
We sourced server equipment from our own reserves that same night, configured a new domain for DenMar and had it on-site the next morning alongside spare Sophos firewalls we reallocated from our inventory.
Our engineers joined DenMar’s new laptops to the domain, stood up terminal services and SQL Server, and worked with DenMar’s accounting software vendor to restore their business systems.
Mission-critical operations were back up within days. DenMar met their obligations to their federal clients on time, and their reputation in the government contracting community was preserved.
The Infrastructure Refresh
Getting DenMar back online was the immediate goal. But the team didn’t stop there.
The forensic investigation gave the InterWorks team useful insight into how the attack had come in and what an updated environment should address. That informed the full infrastructure refresh scoped the day after the incident. Hardware was scoped and ordered in a matter of days and was supported by a client who was fully committed to moving fast with an InterWorks team that matched that energy.
The new environment included Dell PowerEdge servers at both the Lawton and Oklahoma City locations, Sophos XGS firewalls with Xstream Protection, Ruckus wireless and switching, ArmorPoint 360 for managed 24/7 security monitoring, Mimecast for email security and Datto cloud backup with remote monitoring across both sites.
Once the new hardware arrived, virtual machines were migrated from the temporary server to the production hosts. DenMar had a modern, well-secured infrastructure.
“We are forever grateful to the InterWorks Team for their experience and professional knowledge in the management of this unimaginable project. InterWorks remains an extension of our DenMar Corporate Team and will be a continued partner ensuring our system is the best it can always be. We are now back to daily management of our files and software since the cyber attack, and we are loving our systems designed by InterWorks.”
—Quetta Fritsch, President, DenMar Services
A Path to CMMC
The refresh addressed the immediate need. It also revealed a critical opportunity.
DenMar, like many government contractors, had CMMC Level 2 certification on their roadmap — the Cybersecurity Maturity Model Certification required by the Department of Defense to continue working on federal contracts. The new infrastructure created a realistic foundation for pursuing it.
Our team worked with DenMar’s leadership to produce a formal remediation document covering every action taken and every compliance requirement addressed through the incident response. DenMar’s vice president described it as exactly what he needed to start working through the 110-question CMMC assessment.
That work is ongoing. With a modern environment and a clear compliance record, DenMar is well-positioned to complete certification and strengthen their standing in the government contracting market.
Don’t Wait for an Incident
DenMar’s story isn’t a cautionary tale about one company’s mistakes. It’s a reminder that sophisticated attacks happen to real organizations doing real work, and that the gap between a bad day and a business-ending event often comes down to how quickly you can respond.
Most small and midsize businesses, and many larger ones, have never had their security posture formally assessed. They know their systems mostly work. They don’t always know where they’re exposed.
This is the work InterWorks does proactively, before an incident creates the urgency.
Our SecOps team conducts structured security posture assessments covering eight domains: Authentication, endpoint protection, cloud security, physical security, email security, network exposure, data backup and recovery, and logging and visibility. The result isn’t a long report full of findings that get filed away. It’s a prioritized set of recommendations — what to address now, what to plan for this year and what to revisit once the foundation is stronger.
For organizations holding or pursuing government contracts, there’s an added dimension: CMMC certification is increasingly a baseline requirement, not a differentiator. Getting ahead of it proactively is a different conversation than scrambling to meet it after an incident.
If you’re not sure where your organization stands, that’s a good reason to find out. Talk to our team about a security posture assessment.
“Per the statistics on the ever-increasing cybersecurity incidents happening every day, and as the FBI told us, ‘It is not a matter of if, but when’ your system will be next. Don’t hesitate to make that call to the best company available to assist with support, strategy and solutions — InterWorks!”
—Quetta Fritsch, President, DenMar Services