CASE STUDIES
How mid-market organizations are closing the Observability Gap
Armorstack publishes customer case studies as engagements complete and customers authorize publication. Each case study is built on real customer work with explicit written customer authorization. The library is organized by vertical for easy navigation; templated examples are available where authorized published work is not yet ready.
Healthcare
Mid-market hospital and health system case studies covering Epic and Oracle Health (Cerner) environments, HIPAA Security and Privacy Rule alignment, HITRUST CSF implementation, Joint Commission information management, and AI risk management across clinical workflows.
- Healthcare case study template example — A 600-bed Wisconsin community hospital system closing its clinical AI Observability Gap in 90 days. Representative template demonstrating engagement structure and outcomes.
- Additional healthcare case studies will publish as customer engagements complete and customers authorize publication.
Manufacturing
Mid-market manufacturer case studies covering OT/IT convergence, ICS/SCADA security, NIST 800-171 + CMMC 2.0 compliance, ITAR and EAR considerations, customer security flow-downs, and AI risk management across engineering, quality, and production workflows.
- Manufacturing case studies will publish as customer engagements complete and customers authorize publication. Engagement candidates include precision manufacturers in the defense supply chain and automotive Tier 1 suppliers.
Defense contractors
Mid-market defense contractor case studies covering CMMC 2.0 readiness and assessment preparation, DFARS 252.204-7012/7019/7020 compliance, ITAR and EAR-controlled technical data, NIST 800-171 implementation, and AI risk management across engineering, procurement, and personnel workflows.
- Defense contractor case studies will publish as customer engagements complete and customers authorize publication.
Financial services
Mid-market financial services case studies covering community banks, credit unions, broker-dealers, registered investment advisers, and insurance carriers. Coverage includes GLBA Safeguards Rule, FFIEC examination preparation, SR 11-7 model risk management, NYDFS Part 500, NAIC Insurance Data Security Model Law, and FINRA / SEC compliance considerations.
- Financial services case studies will publish as customer engagements complete and customers authorize publication.
K-12 education and libraries
K-12 school district and public library case studies covering FERPA, COPPA, CIPA, E-Rate program eligibility, state student-data privacy laws, and AI governance for districts and library systems operating with limited security staff.
- K-12 case studies will publish as customer engagements complete and customers authorize publication.
Why our case studies are different
Every Armorstack case study is built on real customer engagement work with explicit written customer authorization for publication. The case study program follows a defined process:
- Identification. Engagement candidates are identified during the engagement itself based on operational outcomes and customer authorization signals.
- Outreach. The relationship owner approaches the customer’s executive sponsor within 30 days of engagement close with a specific publication ask.
- Authorization conversation. The customer chooses the identification level (full identification with logo, named-by-vertical, fully anonymized), the specific content scope, and the publication timeline.
- Drafting and customer review. Unlimited customer revisions during review. Final publication requires explicit written customer authorization.
- Internal review. Legal counsel review for confidentiality, BAA / DFARS / FERPA compliance considerations, and fact-check by the delivery team.
- Publication. Publication includes the customer’s chosen identification level and content scope; the customer receives a printed copy and LinkedIn recognition where authorized.
The standard is no fabricated case studies, no composite scenarios presented as single-customer work, no quantified outcomes that were not actually produced.
Become a future case study.
Apply for the free 30-day AI Risk Assessment. The strongest engagements produce the next case studies.