Secure Cloud Migration That Moved a Government Contractor Off Aging On-Premise Servers into a Scalable Environment
The defense subcontractor successfully migrated its entire infrastructure from eight aging on-premise servers to a secure, scalable, and compliant Azure environment. The migration was completed in 14 weeks with zero unplanned downtime, replacing an estimated 5–7 day recovery window and 36-hour data loss risk with a validated recovery time objective of 4 hours and a recovery point objective of 1 hour. The organization emerged from the engagement with a CMMC Level 2-aligned posture, a fully documented compliance matrix, and the operational independence to manage its new environment without ongoing external support.

A defense subcontractor with 30 employees was operating its entire IT infrastructure on eight aging on-premise servers, several of which were past their manufacturer-supported lifecycle. The organization handled Controlled Unclassified Information (CUI) and was required to maintain compliance with CMMC (Cybersecurity Maturity Model Certification) standards, making any infrastructure change a high-stakes undertaking.
The contractor needed a phased, secure migration to the cloud that would eliminate hardware risk, reduce IT costs, achieve compliance-ready posture, and establish a disaster recovery capability that its on-premise environment could not provide.
Client: A defense subcontractor
Employee Size: 30 employees
Industry: Government & Public Sector
Services: - Cloud Migration & Infrastructure - Security Hardening & Compliance - Disaster Recovery Planning - Managed IT Services
The subcontractor's on-premise infrastructure had been built incrementally over eight years. The oldest servers were running Windows Server 2012 R2, which had exited extended support. Three of the eight servers had experienced hardware failures in the prior 18 months, each resulting in partial outages that disrupted operations for between four hours and two full business days. The most recent failure affected the file server that housed active project documentation, and recovery required restoring from a backup that was 36 hours old, resulting in lost work.
Disaster recovery was the organization's most significant vulnerability. Backups were stored on a NAS device in the same server room as the primary infrastructure. A fire, flood, or major hardware failure would have put both primary data and backups at risk simultaneously. The recovery time objective, if the organization needed to rebuild from offsite tape backups stored at the CEO's residence, was estimated at five to seven business days, a period the organization acknowledged would likely result in contract defaults and potential loss of its government client relationships.
CMMC compliance added a layer of complexity to any migration plan. The organization was required to meet Level 2 requirements, which mandated specific controls around access management, encryption, monitoring, incident response, and data protection. The existing on-premise environment met these requirements through a combination of physical controls and software configurations that had been painstakingly documented. Any migration would need to replicate or exceed every existing control in the new environment without introducing gaps that could jeopardize certification.
The organization's IT was managed by a single systems administrator who also served as the help desk, network engineer, and security officer. This individual was stretched to capacity maintaining the current environment and did not have the bandwidth to plan and execute a migration while keeping day-to-day operations running. Previous attempts to scope a migration with general IT consultants had stalled because those firms lacked familiarity with CMMC requirements and could not guarantee compliance continuity.
Cost was also a concern. The organization's leadership understood that cloud hosting would involve ongoing subscription costs rather than periodic capital expenditures. They needed confidence that the total cost of ownership would be favorable and that the migration would not require replacing or significantly modifying the business applications their teams used daily.
The organization needed a solution that would: - Migrate all workloads off aging on-premise servers - Maintain uninterrupted CMMC Level 2 compliance - Establish a disaster recovery capability with hours-level recovery time - Reduce total IT infrastructure costs - Minimize disruption to daily operations during the transition
JSG executed a phased cloud migration to Microsoft Azure, purpose-built for the organization's compliance requirements, operational constraints, and budget parameters. The migration was planned and executed over 14 weeks with zero unplanned downtime.
Key Components
Compliance-First Architecture Design The Azure environment was architected from the ground up around CMMC Level 2 requirements. Every infrastructure decision, from network segmentation and encryption standards to access control models and logging configurations, was mapped to specific CMMC practices. A compliance matrix was maintained throughout the project and delivered as a living document for ongoing audit readiness.
Phased Workload Migration Workloads were migrated in a deliberate sequence designed to minimize risk and validate the environment incrementally. Non-critical systems such as development tools and internal documentation moved first. Production workloads including the file server, email, ERP, and project management systems were migrated in subsequent phases, with parallel running periods to verify data integrity and application functionality before decommissioning on-premise instances.
Security Hardening & Monitoring Azure Security Center was configured to provide continuous security posture assessment, threat detection, and compliance monitoring. Multi-factor authentication was enforced across all accounts. Conditional access policies restricted data access based on device compliance, location, and role. Endpoint detection and response tooling was deployed to all workstations, and security event logs were centralized for monitoring and incident response.
Disaster Recovery & Business Continuity Geo-redundant backup and replication were established across two Azure regions. Automated daily backups with 30-day retention replaced the previous NAS-based backup approach. Recovery procedures were documented and tested, achieving a validated recovery time objective of 4 hours and a recovery point objective of 1 hour, compared to the previous 5-7 day estimated recovery time with 36-hour data loss risk.
Migration Orchestration & Health Checks N8N was used to automate the migration validation process, running post-migration health checks on each workload to verify service availability, data integrity, network connectivity, and security configuration. Automated monitoring workflows continued post-migration, running daily system health assessments and alerting the team to any configuration drift or performance anomalies.
Staff Transition & Documentation The organization's systems administrator was trained on the new Azure environment, including the management portal, security tools, backup procedures, and incident response workflows. Comprehensive runbooks were created for all routine operations and emergency procedures, ensuring the organization could manage its environment independently.
## Quantifiable Impact
- 40% reduction in total IT infrastructure costs ($142,000 annual savings)
- 99.99% uptime achieved in the first 12 months (up from 96.8% on-premise)
- Disaster recovery time reduced from 5-7 days to under 4 hours (validated)
- Recovery point objective improved from 36 hours to 1 hour
- CMMC Level 2 compliance maintained throughout and after migration with zero gaps
- 8 on-premise servers fully decommissioned
- Zero unplanned downtime during the 14-week migration
- Cloud Platform: Microsoft Azure (Azure Virtual Machines, Azure Storage, Azure Active Directory)
- Security: Azure Security Center (continuous posture assessment, threat detection), Microsoft Defender for Endpoint
- Backup & DR: Azure Backup (geo-redundant, 30-day retention), Azure Site Recovery
- Compliance: CMMC Level 2 control mapping, Azure Policy (configuration enforcement)
- Workflow Orchestration: N8N (migration health checks, post-migration monitoring, configuration drift alerts)
- Identity: Azure Active Directory with MFA and Conditional Access
- Monitoring: Azure Monitor, Log Analytics
- Communication: SendGrid (system alerts, status notifications)
Ready to Modernize Your Business?
Let's talk about where technology can move the needle first.

