
Who Needs to Follow NIST 800-171?
Many businesses first hear about NIST 800-171 from a customer rather than from a government
Lawrence runs on a mix you will not find anywhere else in Kansas: a major research university, a manufacturing base out east on K-10, clinics and firms holding sensitive records, and a workforce that turns over with the academic calendar. MDL Technology has provided managed IT services in Lawrence, KS, and across Douglas County since 2003, and we build around those realities instead of around a template.
Most of what breaks, we fix remotely within minutes. For everything else, we schedule on-site time in Lawrence rather than telling you to ship a laptop somewhere and wait.
You are not buying a helpline. You are handing off the parts of your technology that quietly eat your week.
One flat monthly fee. No surprise invoice after a bad week.
Douglas County is not one business community. It is about four, and they need different things.
KU Innovation Park on West Campus is the largest business incubator in Kansas, and its Phase IV building is the Kansas National Security Innovation Center, a $55 million facility on Becker Drive built on $22 million in federal funding. The National Weather Service has already signed as its first tenant. If you are a KU spinout or chasing federal or DoD work, the security questionnaire arrives before the contract does: NIST 800-171 controls, DFARS clauses, and eventually CMMC certification.
That is our daily work. We are ISO 27001-aligned and support CMMC readiness and NIST 800-171 assessments for regulated and public sector clients. We will tell you which controls you meet, which you do not, and what the gap costs to close.
East Hills Business Park and the adjoining 200-acre Lawrence VenturePark carry a serious share of Lawrence’s payroll, with Amcor, Hallmark, Amarr, Lawrence Paper Company, Grandstand, and Hershey’s Salty Snacks all running production here. Plant IT is its own animal: line-control PCs running software nobody wants to touch, an office network that should never reach the plant floor, and shifts running long after most IT companies have gone home. When a line stops, cost is measured per hour, not per ticket.
The Panasonic battery plant in De Soto, twenty minutes down K-10, is expected to spin off roughly 4,000 supplier jobs regionally. Bid into that supply chain, and your customer’s security review will be tougher than anything you have filled out before.
LMH Health anchors a large network of independent clinics, dental offices, and specialty practices around Lawrence. Every one of them is holding protected health information on a network somebody set up years ago.
We handle HIPAA security compliance the boring way: documented risk assessments, encryption where it belongs, access logs that exist before you need them, and tested backups so a ransomware event does not become a breach notification.
Law offices, CPA firms, agencies, and retailers along Massachusetts Street run lean. So do the nonprofits and public bodies here.
That last group has reason to be nervous. Franklin County, just south of Douglas County, had a ransomware attack that exposed data on approximately 30,000 residents. The Kansas Judicial Branch lost online court access for months. Wichita went cash-only for city services after an attack. Kansas public entities are being hit, and smaller organizations are being hit precisely because they are smaller.
We are not going to tell you we care more than the next IT MSP. Here is what is actually different.
You should never have to guess what your IT partner is doing. Our process for taking over your technology is simple, and you can follow along at every step:
We inventory your servers, endpoints, firewalls, licensing, backups, and who has access to what, then test whether your backup actually restores. A risk assessment does the heavy lifting here.
We map out what to fix first, what it costs, and which rules apply to your industry, whether that is HIPAA, NIST 800-171, or CMMC. One flat monthly number, with no line items you have to decode.
Monitoring, MFA, EDR, and backups go in without shutting down your team or your workday. Your lead technician is assigned early, so somebody already knows your setup before day one.
Once you are live, we monitor around the clock and jump on anything that looks wrong. Most issues get resolved remotely, and we schedule on-site time in Lawrence when hands-on work is needed.
Your business changes, and so does your risk. We check in quarterly on ticket trends, aging hardware, and what needs budgeting for next year, instead of waiting for something to break.
Already have an IT person? Our co-managed IT services back up your internal staff without taking over.
Most providers price per user or per device on a flat monthly plan, and your number depends on headcount, how much coverage you want, and whether you carry compliance requirements like HIPAA or CMMC. MDL builds a quote after reviewing your actual environment, so you are not comparing guesses. Request a proposal for a real figure.
Typically help desk support, continuous network monitoring, patching, cybersecurity tooling, backup management, cloud and Microsoft 365 administration, and ongoing technology planning. The important question is what a provider excludes, since after-hours work, projects, and on-site visits are often billed separately elsewhere.
Break-fix means you call when something is already broken and pay by the hour to fix it. An IT MSP is paid a flat fee to keep things from breaking, which flips the incentive: we lose money when your systems fail, so we work to prevent it.
If losing your systems for a day would seriously hurt you, yes. Attackers target small Kansas organizations specifically because they have no dedicated security staff, as several public entities in this region have learned. Managed IT costs far less than one full-time hire and covers considerably more ground.
Yes, and it is one of our core specialties. We run gap assessments, build out the required controls, write the policy documentation, and support you through audit preparation. This is increasingly relevant for firms connected to KU research or federal contracting.
We resolve the large majority of issues remotely, usually faster than waiting for a technician to drive over. When physical work is required, we dispatch from North Kansas City and schedule on-site time in Lawrence, typically the same day or the next day, depending on urgency.
Absolutely. Our co-managed IT services are built for exactly that. We take on monitoring, patching, security, and after-hours coverage while your internal staff handles the applications and relationships they know best.
Yes. We work with production environments across Kansas and Missouri, including network segmentation between office and plant systems, support for aging line-control machines, and coverage that accounts for multiple shifts.
Bring us the thing that has been bothering you: the backup you are not sure works, the compliance questionnaire sitting in your inbox, the fact that nobody actually knows who has admin access anymore. We will tell you straight whether it is a problem and what fixing it involves.
MDL Technology has kept Kansas and Missouri businesses secure and running since 2003, and we would like to do the same for you with managed IT services in Lawrence, KS.
Call 816-781-3006 or request your free proposal.

Many businesses first hear about NIST 800-171 from a customer rather than from a government

Most cyberattacks do not wait for business hours. Attackers often strike at night, on weekends,

A common assumption inside the defense supply chain is that CMMC replacing NIST is already