How a Concord fabrication company connected its instruments to a shared network—and cut the duplicate data entry that came with keeping them apart—without loosening a single compliance control.
| Client | Precision fabrication company (name withheld at client request) |
| Industry | Fabrication / regulated manufacturing |
| Location | Concord, California |
| Previous IT Provider | East Coast managed service provider |
| Services Delivered | Onsite IT assessment, network security review, secure server deployment, VLAN network segmentation, ongoing managed IT support |
The Challenge
Three time zones away from the help they needed
This Concord manufacturer had been getting its IT through a provider based on the East Coast. On paper, the arrangement worked. In practice, the distance showed up every time something needed real attention.
Response times lagged. Nobody could walk the floor. And when the company wanted to plan upgrades to its systems, there was no partner close enough to sit down, look at the equipment, and help think it through. What they had was a vendor. What they needed was somebody local who would show up.
Security controls that quietly slowed the work down
The company operates in a regulated industry, so compliance and security are top priorities in every decision. Their instruments—the machines that actually produce and measure their work—were deliberately isolated from the rest of the network. Cutting a machine off from the network is a legitimate way to protect it.
But isolation has a cost, and this company was paying it every day. Because the instruments could not share data, staff moved information by hand: pulling files off one machine, re-entering them somewhere else, keeping parallel copies so the right people could see the right numbers. The result was a growing pile of duplicate records, greater chances of transcription errors, and hours spent on work that a properly configured network should handle on its own.
The Core Tension
Every manual workaround existed for a good reason: to stay secure and compliant. The problem was not that the controls were wrong, it was that nobody had built an architecture where security and efficiency could both be true at the same time.
What We Did
We started onsite, not on a sales call
Before recommending anything, we ran a full onsite assessment of the environment—the network, the servers, how data actually moved between the shop floor and the office. That visit is where the real opportunities surfaced: two of them, one in network security and one in data management, and they turned out to be the same problem viewed from two angles.
Then we rebuilt the network so the machines could talk safely
- A new secure server environment. We deployed a server designed to hold the instrument data in a single governed location, with the access controls and protections required by the company’s regulatory obligations. This became the single destination every machine writes to.
- VLAN segmentation for the instruments. A virtual local area network (VLAN) divides one physical network into separate, walled-off lanes. Traffic in one lane cannot reach another unless we explicitly permit it. That is what let us connect the instruments to a shared network without exposing them: the machines now reach exactly the server they need and nothing else, and nothing else on the network can reach back into them.
- Security controls carried forward, not traded away. The isolation the company relied on remains in substance. We replaced a physical wall with an enforced logical one, which performs the same protective role while allowing data to flow where it belongs.
Why this matters if you run a regulated shop
Air-gapping a machine is the blunt version of security. It works, and it is expensive in ways that never show up on an invoice—they show up in your team’s hours. Segmentation gets you the same protection with the data still moving.
The Results
The instruments now save their files directly to a central location instead of being emptied manually.
- Duplicate data dropped. The same record no longer has to exist in three places because three people need to see it.
- Workflow efficiency improved. Time that went into moving and re-keying information now goes back into production.
- Compliance and security requirements were met. The strict controls the company operates under were maintained throughout—nothing was relaxed to make the workflow easier.
- They have a local partner again. Assessments, upgrades, and day-to-day support now come from a team that can be onsite in Concord when it matters.
Is This Your Situation?
This project is a close match if your business looks like the following:
- You manufacture or fabricate in the Bay Area and work under regulatory or contractual security requirements.
- Your production or measurement equipment is cut off from the network, and your team bridges the gap manually.
- You are carrying duplicate records across systems and suspect it is costing more than anyone has measured.
- Your current IT provider is somewhere else, and you have stopped expecting them to show up.
Let’s look at your floor.
PC Professional has supported Bay Area businesses and nonprofits since 1981, with on-site and remote support, a 15-minute response commitment, and service agreements that do not lock you into a long-term contract. Start with a free 30-minute consultation—or call us and talk to a person who can help.

