Artificial intelligence consulting services

Without the right strategy, AI initiatives can create more confusion than results. Clarify priorities, reduce risk and accelerate adoption with guidance tailored to your organization.

Turn AI hype to ROI
Turn AI hype to ROI

See how our DRIVE framework can help move your organization from AI exploration to execution and measurable results.

How we help you

Mid-market leaders don’t need hype. You need clarity. Whether you’re exploring use cases, assessing organizational readiness or beginning to build, our AI consulting team works with you to turn strategy into action. 

Create a unified AI strategy, with policies to guide experimentation, adoption and risk.

Connect systems and implement effective data management and governance practices.

Access business advisors, engineers and analysts without adding headcount.

Design for responsible use and prioritize use cases grounded in practical value.

Focus on ROI and the right automation for your strategy.

AI isn’t the future. It’s your next move.

Our AI consulting services are built for the mid-market. While other firms push big-enterprise solutions, we focus our AI services on helping growth-focused companies use AI in ways that make sense for their size, culture and systems.

Explore our AI consulting services

Insights and Resources

  • Business team reviews financial data on a tablet.

    ARTICLE

    From compliance to confidence: Mastering the new CMMC 2.0 requirements

    The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the newest iteration of the Department of Defense’s (DoD) cybersecurity rules for contractors. This framework aims to ensure that all defense contractors implement necessary cybersecurity safeguards to protect controlled unclassified information (CUI) and federal contract information (FCI). CMMC 2.0 compliance requirements were originally scheduled to take effect in four phases from November 2025 through 2028. However, in July 2026, the DoD paused Phase II indefinitely , although most other CMMC requirements remain active. Keep reading to learn what’s changing and how your business may need to adapt. What is CMMC 2.0? The Cybersecurity Maturity Model Certification (CMMC) 2.0 is a cybersecurity compliance framework for defense contractors and other vendors who work with the Department of Defense (informally referred to as the Department of War). CMMC 2.0 is the latest version of the CMMC framework and now appears in all DoD contracts with the goal of raising cybersecurity standards for the defense industrial base (DIB). Is CMMC compliance mandatory? DoD contractors who wish to continue bidding on federal defense contracts must meet CMMC 2.0 compliance requirements . However, the Phase II pause means you no longer have to complete a third-party assessment in order to demonstrate compliance. Who does CMMC 2.0 apply to? CMMC 2.0 applies to all contractors, vendors and other third-party organizations that do business with the Department of Defense. Especially in light of the Phase II pause, expect that CMMC will continue to evolve in the coming years. What is the CMMC 2.0 Phase II pause? On July 13, 2026, the DoD announced it was pausing Phase II of the CMMC 2.0 rollout indefinitely. Phase II, which was supposed to begin on November 10, 2026, originally required organizations handling higher levels of sensitive information to complete third-party CMMC compliance assessments. However, due to the pause, organizations no longer have to complete third-party assessments to demonstrate CMMC 2.0 compliance. Most other requirements remain in effect, and DoD is continuing to include CMMC in new contracts. It is likely that DoD will announce significant revisions to the rest of the CMMC rollout at some point in the future. Before the pause, CMMC 2.0 had originally established a three-year phased implementation period CMMC 2.0 was originally scheduled to roll out in four phases from 2025 through 2028. While the Phase II pause means the entire rollout schedule will likely be revamped, here is that original schedule as it was first established: Phase I: The first phase began on November 10, 2025. During this phase, the DoD can begin to include CMMC 2.0 requirements in new contracts. Contractors will need to meet Level 1 or Level 2 self-assessment requirements as a condition of contract award. Phase II: Before the pause, the second phase was originally scheduled to start one year after Phase I, on November 10, 2026. In this phase, contractors handling CUI would have been required to undergo a third-party assessment by a certified assessor organization as a condition of award. Phase III: The third phase was scheduled to begin on November 10, 2027. This phase would have involved the DoD itself conducting Level 3 CMMC assessments for contracts involving the most sensitive CUI, but will also likely be revamped in light of the Phase II pause. Phase IV: The final phase was supposed to start three years on November 10, 2028. This phase would have marked the full implementation of the CMMC requirements across all applicable solicitations and contracts. This phased approach was intended to address ramp-up issues, provide runway to train the necessary number of assessors and allow companies the time needed to understand and implement CMMC requirements . Key clarifications around CMMC 2.0 compliance requirements As the newest version of DoD cybersecurity rules, CMMC 2.0 provides several key clarifications that are crucial for CISOs and compliance officers at defense contractors to understand. These include: The operational plan of action allows contractors to identify temporary vulnerabilities and deficiencies, as opposed to documenting in a plan of action and milestones (POA&M). This allows for management to remediate vulnerabilities or deficiencies identified through the normal operation of detective controls without causing you to go out of compliance. Contractors must retain artifacts used in evidence for an assessment for at least six years after the date of their certification assessment. This retention obligation extends to the annual self-certifications that contractors must perform. External service providers are not required to have CMMC certification, but are “in-scope” if they store, transmit or process CUI. An endpoint hosting a virtual desktop infrastructure (VDI) client configured to disallow processing, storage or transmission of CUI beyond keyboard/video/mouse sent to the VDI client is considered an out-of-scope asset. How should you implement the CMMC 2.0 cybersecurity framework? Even with the Phase II pause, most CMMC 2.0 requirements remain in effect. Defense contractors must take several steps to become compliant and properly flow down the compliance requirements to their subcontractors, including: 1. Understand the three CMMC 2.0 levels Based on the type of sensitive information or CUI your organization handles, you should determine the appropriate CMMC level for your organization. This will guide your compliance efforts and help you identify the specific requirements you need to meet. The three levels are: Level 1: Basic protection of FCI, requiring an annual self-assessment. Level 2: General protection of CUI, which can now be achieved through a self-assessment in light of the Phase II pause. Level 3: Enhanced protection against advanced persistent threats. This would have required an assessment led by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), starting with Phase III in November 2027, but may now be revamped. 2. Conduct proper scoping of your environment. Proper scoping of your environment for CMMC 2.0 is crucial because it clearly defines the boundaries where CUI is stored, processed and transmitted within your organization. This allows you to focus security efforts only on the relevant systems and data, minimizing the scope of your assessment and ultimately reducing the cost and complexity of achieving compliance while ensuring the most critical assets are adequately protected. If not done correctly, your entire network could be considered “in-scope” for assessment, leading to unnecessary overhead and potential noncompliance issues. 3. Perform a gap analysis. Assess your current cybersecurity posture against the CMMC 2.0 standards. Conduct a thorough gap analysis to identify deficiencies in your existing cybersecurity controls. This will help you develop a POA&M to address these gaps and achieve compliance. 4. Implement required controls. Based on the results of your gap analysis, implement the necessary cybersecurity controls to meet the CMMC requirements. This may involve updating your policies, procedures and technical controls, or implementing new technology. 5. Prepare for assessment. You’ll need to complete a self-assessment to demonstrate CMMC 2.0 compliance. Before you begin, ensure that you have all the required documentation and evidence in place. This includes maintaining control evidence for six years and being prepared for potential audits by the DoD. 6. Flow down requirements to subcontractors. Ensure that your subcontractors are also compliant with the CMMC requirements. Flow down the relevant requirements to all subcontractors at every tier and verify their compliance. By following these steps, defense contractors can help ensure that they are fully compliant with the CMMC 2.0 requirements and are well-prepared to protect sensitive information from evolving cyberthreats. A third-party advisor can help you navigate this process and implement solutions to bring you up to speed. Read more Cybersecurity is a financial issue The right cybersecurity framework boosts a business’s value 5 common CMMC 2.0 pitfalls

  • Male building contractors cooperating.

    ARTICLE

    Cybersecurity in construction: How CIOs can better protect their firms

    Construction firms face a rising level of cybersecurity risk. But too many firms still don’t have a proper cybersecurity strategy in place, which is likely why Wipfli’s survey of 308 construction executives found that 80% reported experiencing at least one data breach within the past year. However, there are proven steps and processes you can implement to strengthen your defenses. Done thoughtfully, a cyber strategy will not only protect your business, data and infrastructure but also give you an opportunity to modernize your systems to meet the changing demands of the industry . Let’s explore further. Why does cybersecurity matter for construction firms? For construction firms, investing in modern cybersecurity and IT infrastructure, whether as an internal capacity or through outsourcing, carries clear business benefits. Beyond mitigating the risk of a cyberattack , stronger cybersecurity also creates business opportunities and even makes it easier to recruit top talent. Key benefits include: Reduced risk of attack: This is obviously a big one. With better defenses and more modern systems in place, you’ll be less likely to experience a major (and majorly expensive) cybersecurity incident or suffer significant ripple effects if an attack does get through. DoD contracts: If you meet CMMC requirements, you’ll be able to bid on DoD and other government contracts. Data center bids: Strong cybersecurity is also often necessary to compete for complex private sector projects like data centers. Competitive advantage: If you get ahead of competitors in upgrading your systems, you’ll be able to move faster, with a lower risk of being slowed by an attack. Recruiting: You’ll have an easier time recruiting talented employees who want to work for innovative companies. Top cybersecurity challenges faced by construction firms Every industry is vulnerable to cyberattacks, but construction may be especially so. The construction business tends to be fairly traditional, with an emphasis on following proven processes rather than chasing new ideas — a tendency which has left firms more exposed than their counterparts in other industries. Here are some of the top reasons that construction firms are vulnerable to cybersecurity incidents: Underinvestment: Construction companies have historically underinvested in IT and cybersecurity. Manufacturers, for example, spend 3% to 5% of revenue on IT, while construction typically spends closer to 1% to 2%. Large financial transactions: Construction firms buy large amounts of materials and expensive equipment. They also receive large draw payments from their clients. This makes them lucrative targets for cybersecurity attacks due to their historically poor security investments. Rising insurance premiums: Insurance providers are now charging construction companies higher cybersecurity insurance premiums because of the higher risk those firms face. Cyber requirements in contracts: The Department of Defense and other federal agencies now require construction firms to meet cybersecurity maturity model certification (CMMC) requirements in order to bid for contracts. Private data center contracts will often have similar rules. National Institute of Standards and Technology (NIST) security requirements are also appearing in many contracts. Disconnected systems: As many construction firms still rely heavily on older software and technology, they frequently don’t have integrated, cloud-based systems in place. This usually leads to fragmented, siloed data and a larger footprint for an attack. Slowed productivity: Companies using outdated tech systems are often less productive than their peers. From a cyber-specific perspective, consider the impact an attack could have on your ability to conduct day-to-day operations. Limited IT talent: Construction firms using legacy tech solutions may struggle to hire skilled IT employees, as talented candidates typically prefer to work for businesses that use the latest tech. All of these elements either increase the risk of a cyberattack, prevent your business from bidding on certain contracts or otherwise limit opportunities. Fortunately, there is a relatively straightforward solution to this problem. Cybersecurity best practices for construction companies Implementing a practical, up-to-date cybersecurity strategy will help mitigate your company’s cyber risks and reduce the likelihood of suffering a costly cyberattack. Think holistically In many cases, you’re often better off upgrading your cybersecurity and IT infrastructure over one defined upgrade period rather than doing it piecemeal over several years. This holistic approach allows you to modernize your entire tech stack to not only strengthen your cyber defenses but also transition to cloud-based, integrated systems that will help you remain competitive with your peers. Do a cybersecurity assessment An effective cybersecurity risk management strategy should be tailored to your specific threats and vulnerabilities. Start by working with a cybersecurity advisor to do an IT health and cybersecurity assessment , which will often be based on the NIST Cybersecurity Framework (NIST CSF) assessment. This will help you identify high-priority weak spots that need to be addressed, as well as which vulnerabilities may be lower-priority. Create a roadmap Based on the results of your assessment, create a roadmap for strengthening your cybersecurity and IT capabilities. When developing your roadmap, also consider tech trends within the construction industry , the age of your own systems, and any critical control gaps you’ve identified. Establish a budget Once you know what needs to be upgraded, put together a budget based on criticality. A full tech and cybersecurity upgrade might take over a year, although this can vary depending on your organizational needs, so your budget can help you plan out how to make good use of that time by deciding which systems to upgrade first. You can use the priority ranking from your assessment to good effect here. Leverage outsourcing If upgrading your cybersecurity and tech stack on your own sounds like a lot to handle, consider outsourcing and managed services support . Outsourcing is especially useful for construction firms because modern cybersecurity typically requires more resources than a single, in-house IT person can bring to bear. An outsourcing relationship can allow you to access top-tier cybersecurity talent without needing to hire your own larger internal team, and can also include strategic leadership like a vCIO or vCISO. Train your team An outsourcing partner can’t do everything for you. You’ll still need to train your own team on how to limit cybersecurity risks by avoiding phishing attempts or other common attacks. For maximum effect, this training should be ongoing, not just a one-time event. What are the key barriers to change that construction CIOs must overcome? Construction leaders who want to spearhead a cybersecurity and IT upgrade may first need to overcome several barriers to change. These include: Lack of clarity around risks: Some leaders may not realize just how vulnerable their business is. To create buy-in around an upgrade, you can ask an advisory firm to conduct penetration testing of your existing systems. Cultural resistance: Construction firms that still rely heavily on legacy systems and processes may also be culturally resistant to change. Confusion around regulatory requirements: Construction isn’t used to being a regulated industry, so many firms may be unaware or not fully under CMMC or similar requirements. Communications: Your internal IT person may struggle to articulate the business case for tech upgrades because they don’t have the knowledge and background. Transition or succession complications: An owner who is preparing to exit may see cybersecurity upgrades as something that the next owner can worry about — but should consider that implementing an effective, modern tech stack will actually boost the value of the business in a sale. Learn how 308 construction leaders are deploying technology to deliver impact Wipfli interviewed 308 construction executives to find out how firms are deploying technology today. Read the full report, “The state of technology in the construction industry” to gain fresh insights on cybersecurity, AI, data strategies and growth. Get the original research report Read more Cybersecurity is a financial issue, not just an IT problem AI in construction 101: How to keep your firm competitive How to improve performance with smarter construction technology management

  • A corporate business meeting.

    ARTICLE

    Cyber risk management: How to reduce cyber risk across your business

    As cybersecurity threats grow ever more potent, your business needs to adapt. This starts with adopting a more cohesive cyber risk management strategy to protect your operations, finances and reputation. Embracing a cyber risk strategy elevates cybersecurity beyond being just an IT concern into a core pillar of your overall enterprise risk management efforts — which helps make your whole organization safer and more resilient. Keep reading to learn more about why this approach matters, plus how to get started. What is cyber risk management? Cyber risk management is a strategy that addresses cybersecurity and cyber resilience as enterprise-level risks rather than siloed problems for your IT department. This proactive approach, which also contrasts with compliance-based models of cybersecurity that focus on meeting compliance requirements, aims to not just stop cyberattacks but also help you recover more quickly if an attack does break through your defenses. Executing a cyber risk management strategy involves identifying cyber-related threats or risks, assessing your current defenses, controls, governance and backup capabilities, strengthening your protections to meet your current risks and then making continuous improvements as needed. The end result is a business that is better able to navigate today’s threat environment and avoid significant losses. If your business has an overall enterprise risk management strategy to mitigate your risk in all areas (not just cybersecurity), then your cyber risk management efforts will fit neatly into that framework. Why cyber risk management matters for business leaders Cybersecurity incidents — like a data breach, business email compromise or ransomware attack — increasingly impact not just large corporations, but businesses of all sizes. That impact shows up directly on your balance sheet. A successful ransomware attack can cost you an upfront ransom payment that may stretch as high as seven figures, as well as ongoing financial, operational and reputational damages ranging from lost productivity or customers to regulatory fines. This isn’t a hypothetical. In one prominent incident, hackers compromised domain-level credentials for Stryker’s Microsoft ecosystem and used that access to remotely wipe data from up to 200,000 company laptops and phones, severely disrupting its worldwide operations. Consider what costs might you incur if you were suddenly locked out of your core systems or lost access to your most sensitive internal or customer data (or worse, found it for sale on the dark web)? In this environment, you can’t afford to write off cyberthreats as minor inconveniences. A cyberattack is a genuine risk to your business, no different than a new competitor, changing customer needs or a sudden hit to your supply chain. Cyber risk management is a way to recognize that — and act accordingly. Core components of an effective cyber risk management program An effective cyber risk management program views cyber risk as an enterprise-level challenge for your entire business to address and mitigate. Key aspects of this effort include establishing effective governance, identifying risks and continuously adapting to meet them. Governance and executive oversight Strong governance and active executive oversight help move cybersecurity from a siloed problem to an enterprise risk management issue. Governance helps mitigate your cyber risks by putting controls and policies around which technology you use and how you use it, while an executive leader like a chief information security officer (CISO) or vCISO can bring a strategic, big picture perspective to cyber risk that your frontline IT team doesn’t have. Risk identification and prioritization To mitigate your risks, you have to know them, so a cyber risk management strategy involves identifying the actual threats your business faces. But you can’t be strong everywhere, all the time, so it’s equally important to prioritize those threats and devote your resources to stopping the most urgent or dangerous. Continuous improvement and monitoring Cybersecurity threats are constantly evolving, so your risk strategy needs to, too. This involves active, ongoing cybersecurity and cyber resilience efforts, as well as a continuous assessment of what’s working and what needs to get better in light of your current threat environment. Build cyber resilience before an incident happens Cyber resilience is an essential aspect of cyber risk management that is focused on helping your business maintain operations during a cyberattack or recover more quickly after the attack ends. Cyber resilience is essentially a complementary activity to cybersecurity, which aims to stop attacks from succeeding in the first place. The overall goal of cyber resilience is to protect business continuity so that your team, customers, finances and outputs are less affected by a cyberattack. This is important because in today’s threat environment, it is unlikely you will be able to stop all cyberattacks at all times, so emphasizing cyber resilience means you will be better able to move forward if and when a breach occurs. It’s important to focus on cyber resilience before a breach or incident occurs. If you’re prepared ahead of time, then you’ll be ready to respond faster and with greater confidence. You’ll also have already taken steps, like backing up your data, that will make it easier to get back to business as usual. Assess your organization’s cyber readiness Understanding your cyber risks and your readiness to address them is key to managing your overall risk levels. But this can’t just be a one-time exercise. Cybersecurity-related risks are constantly changing. AI has made it easier than ever for even individuals without technical knowledge to launch attacks, and both the scope and vector of threats continue to evolve. That’s why you should think of assessing your cyber risks and readiness as an ongoing process. Ideally, this process should have executive leadership in the form of a CISO or vCISO (potentially a CIO in smaller organizations), and a third-party advisor can also provide an invaluable outside perspective that can help you identify gaps your internal team may be too close to notice. Establish strong cybersecurity governance Strong cybersecurity programs are built on a foundation of governance and effective leadership. Governance is crucial to understanding your risks and implementing the appropriate strategies to address them. Additionally, a CISO or vCISO can provide the leadership you need to help oversee the program, communicate with stakeholders and embed cybersecurity into culture and operations. As part of strong governance, your cybersecurity program should include: Annual cybersecurity program assessments to help ensure your program aligns with organizational objectives, regulatory requirements and best practices. Annual tabletop exercises that help you rehearse and strengthen staff’s incident response. Annual board security awareness sessions where your CISO educates leadership on cybersecurity risks, strategies and responsibilities. Quarterly employee training so that staff are aware of cyberthreats and equipped to defend against them. Implement a cyber risk framework A cyber risk framework is an organized, structured strategy for understanding and managing your cyber risks. A framework essentially lays out a series of actions or steps for your business to take to become better equipped to protect against and recover from cyber-related threats. You don’t need to develop your own cyber risk framework. Organizations like NIST and ISO have created detailed frameworks that you can use, sparing your team from attempting to reinvent the wheel. However, you may need help from a third-party advisor to successfully choose and implement a framework. Depending on your specific industry and needs, a particular framework may make more sense than other options or may even be necessary from a regulatory standpoint. Cyber risk management best practices Here are two best practices to help your business more successfully manage your cyber risk levels: Maintain active cyber defenses Cybersecurity operations (SecOps) refer to the tools, processes and personnel needed to monitor, detect, investigate and respond to security threats in real time. It’s a critical component of any cybersecurity program, helping protect your organization’s assets against evolving threats. Your SecOps can include: Endpoint detection and response to monitor activity on endpoints — such as laptops, desktops, servers and mobile devices — to detect threats and respond to them quickly. 24/7 security monitoring to detect threats in real time. Log retention to support forensic investigation if an incident does occur. DNS filtering to help prevent access to potentially malicious websites or sites you want to restrict. Threat intelligence to help you apply information about emerging cyberthreats to strengthen your defenses. Dark web monitoring to help identify any instances where your organization’s sensitive information may have been compromised. Regular vulnerability scanning to help your team proactively detect and address potential entry points before attackers can exploit them. Quarterly firewall configuration reviews to maintain strong defenses and align firewall rules with current security policies and business needs. With the right SecOps practices in place, you can minimize risk, reduce incident response time and maintain business continuity . Keep testing to find gaps Cybersecurity testing is your opportunity to evaluate your current level of effectiveness, with assessments and simulated attacks that can help identify any vulnerabilities, misconfigurations or weaknesses. Your cybersecurity program should include annual testing activities such as: Penetration testing, including internal tests to assess how far an attacker could go after gaining initial access and external testing to identify vulnerabilities in perimeter defenses. Comprehensive vulnerability assessments that identify, classify and prioritize security weaknesses across your organization’s entire IT environment. Cloud security reviews that provide a structured evaluation of your cloud environment to help ensure data, applications and services are properly secure. Social engineering tests, including phishing and pretext-calling attacks, to assess how staff recognize and respond to cybercriminals’ manipulation tactics. Ransomware attack simulations to test your organization’s ability to identify and respond to ransomware incidents. How cyber risk management supports enterprise risk management Effective cyber risk management serves as a supporting pillar of your overall enterprise risk management strategy. Think of cyber as one leg of a table, working in conjunction with other legs like operational risk, AI risk, regulatory risk and technology risk. As more businesses embrace enterprise risk management as a way to adapt to today’s uncertain business environment, operate more effectively and even identify growth opportunities, becoming better able to tackle cyberthreats is a critical part of that effort. To learn more about how managing risk can make your whole business stronger, work with a risk advisor to assess your vulnerabilities and understand your opportunities. Read more How to become a more cyber-resilient organization Cybersecurity is now a major financial risk Enterprise risk management: A strategy for turning risk visibility into business wins

Perspective changes everything.

Receive timely industry developments, regulatory changes and other news impacting your success.

Reach out to our team

Talk with our AI specialists to create a practical strategy that turns AI opportunities into measurable outcomes.