IT and cybersecurity for Staffing & Recruiting
You are held to SOC 2 / client audits; HIPAA (healthcare staffing) – and, like most firms your size, you are expected to meet it without anyone in-house whose job it is to own it. We run the IT and the security program so the obligation is actually covered, not just acknowledged.
Where we usually start: ATS breach + client SOC 2 audit (revenue-tied).
If this sounds familiar
“Our ATS is the entire business – if a recruiter gets phished and it’s breached, we lose our candidate data and our clients’ trust in one stroke.”
Everything the firm has built lives in the ATS, and recruiters are exactly who attackers target for those credentials.
“We hold Social Security numbers, pay data, and background checks on thousands of people – a breach would be catastrophic, and we’d have to notify every one of them.”
The concentration of PII and payroll data across candidates and placed workers makes the firm a high-value target with painful notification obligations across many states.
“Enterprise clients now send security questionnaires before they’ll award a contract, and every time we either scramble or lose the deal.”
Security posture has become a condition of winning work, and being unable to answer cleanly – or lacking SOC 2 – directly costs revenue.
Who this is for
Typical size: 15–150 employees, revenue $5M–$100M. If that is roughly you, the rest of this page will land.
What working with us looks like
A named team that knows your stack, monitoring and patching that happens whether or not anyone chases it, and a written security program kept current – with the evidence to back it up when a client, an auditor or an insurer asks. We report to the Owner + Ops/Finance, not to a ticket queue.
Talk to us
Call 206-850-1496 or email mhasse@itwerx.net and we will set up a short call – no audit, no pitch deck, just a conversation about what you have and what is worrying you.

