Every server and workstation in CATG's environment runs SentinelOne, an AI-driven endpoint detection and response (EDR) platform that watches for suspicious activity around the clock and can automatically isolate and roll back a threat before it spreads, without waiting on a technician to respond.
| Coverage | Devices | Status |
|---|---|---|
| Servers | 12 of 12 | Protected |
| Workstations & Laptops | 81 of 81 | Protected |
Workstations and servers are patched on an ongoing, automated schedule. Two pockets of the environment need attention:
| Area | Status | Details |
|---|---|---|
| Windows Server 2012 R2 (4 servers) | Urgent | Accounting, Timecard, Access Control, and File Server. Extended Security Update coverage ends October 13, 2026 — see the Server Report and Section 4 of the main IT Partnership Report for upgrade planning. |
| Unsupported Workstations (2) | At Risk | Running genuinely outdated operating systems no longer receiving security patches. |
| ESU-Only Workstations (7) | Needs Attention | Windows 10 devices patched only through paid Extended Security Updates rather than mainstream support. |
| Windows 11 Devices Pending Feature Update (18) | On Track | Confirmed by our field techs as Windows 11 Enterprise 23H2, supported until November 2026. A routine feature update is already scheduled to bring these current — not a current risk. |
| Remaining Servers & Workstations | Current | Patched on the standard automated schedule with no action needed. |
Our field techs confirmed the Windows 11 devices below are running the Enterprise 23H2 build, which stays supported until November 2026, not the end-of-life status originally flagged by the automated inventory scan.
| Group | Status | Details |
|---|---|---|
| 18 Devices — Windows 11 Enterprise 23H2 | On Track | Supported until November 2026. A feature update to the latest build is already scheduled as routine maintenance. Includes the Arctic Village and Venetie JACO carts. |
| 2 Devices — Legacy Operating Systems | Unsupported OS | CATG-EMR-AVD (Windows 11 21H2 multi-session, EOS Oct 2024) and CATG-BEAVER-1 (Windows 10, build from 2017, EOS Oct 2018). These need replacement or a full rebuild, not just an update. |
Every CATG location, Fort Yukon and all three villages, sits behind a managed Cisco Meraki firewall that enforces traffic rules and gives Vicinity visibility into network activity site by site. See the Network Report for the full equipment list at each location.
| Location | Firewall | Status |
|---|---|---|
| Fort Yukon — Health Center | Meraki MX85 | Active |
| Fort Yukon — Administration | Meraki MX75 | Active |
| Fort Yukon — Addie Shewfelt | Meraki MX75 | Active |
| Arctic Village | Meraki MX75 | Active |
| Beaver | Meraki MX75 | Active |
| Venetie | Meraki MX75 | Active |
| ANTHC Telehealth Connection | Meraki MX67 | Active |
The MX75, MX85, and MX67 are all current, actively-sold Meraki models — Cisco has not published an end-of-sale or end-of-support date for any of them as of this report.
Of 189 active accounts, only 24 have multi-factor authentication (MFA) set up. That means a stolen or guessed password is often the only thing standing between an attacker and an account.
MFA is required for Azure management and for admin accounts, but is not yet required for general staff logins, and blocking of older, less secure sign-in methods is only in monitoring mode, not fully turned on. Closing this gap is the single biggest opportunity to improve CATG's security posture.
| Policy Area | Status |
|---|---|
| MFA — Admin & Azure Management Accounts | Enforced |
| MFA — General Staff Logins | Not Enforced |
| Legacy Authentication Blocking | Monitoring Only |
CATG is already ahead of similar organizations. Closing the MFA gap above is the single biggest opportunity to push this score higher.