Identra

Locations / Houston, Texas

Microsoft security consulting for Houston energy, healthcare, and logistics.

Houston runs three industries that put unusual pressure on Microsoft 365: energy operators managing the corporate-OT boundary, Texas Medical Center institutions with the largest concentration of HIPAA-covered organisations in the world, and Port of Houston logistics operators subject to Coast Guard MTSA requirements. Identra configures the tenant so each of these vertical pressures gets a specific, documented control set rather than a generic security posture.

Service area
Houston, The Woodlands, Sugar Land, Katy, Baytown, Pasadena
Delivery mode
Remote-first, on-site available
License footprint
M365 E3 / E5 (E5 for full)
Delivery
Fixed scope, fixed price

01 / What we configure

Four Houston-specific practice areas.

  • 01

    Energy corridor operators

    Houston-headquartered upstream, midstream, and downstream energy operators face TSA Pipeline SD-02 and API 1164 obligations plus persistent OT/IT convergence risk. Identra configures OT-adjacent workstation isolation, vendor Global Secure Access, and Sentinel workbooks for the corporate-OT boundary.

    TSA SD-02Global Secure AccessCorporate/OT
  • 02

    Texas Medical Center

    Texas Medical Center is the largest medical complex in the world. TMC-affiliated hospitals, research institutions, and specialty practices all run Microsoft 365 under HIPAA. Identra configures HIPAA-aligned Conditional Access, PHI DLP, and 6-year audit retention with clinical device access patterns.

    HIPAATexas Medical CenterClinical devices
  • 03

    Port and maritime logistics

    Port of Houston logistics operators fall under Coast Guard MTSA requirements plus general commercial cybersecurity practice. Identra configures Conditional Access, Defender XDR, and Sentinel aligned to CIS Critical Security Controls with per-terminal segmentation.

    MTSAPort operationsCIS Controls
  • 04

    Manufacturing and chemical processing

    Houston-area chemical and heavy manufacturing operators combine OT/IT boundary risk with intellectual-property protection needs. Identra configures Purview Insider Risk, sensitivity labels on process design files, and Defender for Endpoint on engineering workstations.

    Insider RiskProcess design IPEndpoint protection

02 / What it looks like

Three Houston engagements.

Different Houston verticals, same Microsoft 365 platform, different regulator asks.

CISO at a Houston-headquartered midstream operator

Situation. TSA Security Directive SD-02 flowdown from a critical pipeline designation. Engineering laptops moved freely between corporate email and SCADA jump hosts. Auditor asked for evidence of documented segmentation.

Outcome. OT-adjacent laptops moved to a distinct Intune class. Sentinel workbook alerts on any workstation session touching both corporate and OT segments in the same 24-hour window. TSA evidence pack delivered in the annual filing.

CIO at a TMC-affiliated specialty hospital

Situation. Multi-site specialty hospital with clinical staff working across three campuses. Personal-device use is high because part-time providers are not issued laptops. Recent HIPAA audit flagged inconsistent device compliance.

Outcome. App protection policy lets personal devices reach Outlook and the EHR mobile app without device enrolment. Sign-in risk policy adds step-up MFA. Audit closed with no material findings.

IT Director at a Port of Houston terminal operator

Situation. Terminal operations mix corporate IT (Microsoft 365) with terminal operating systems (proprietary). MTSA facility security officer asked for evidence of cybersecurity controls on the corporate-side systems that could reach the terminal network.

Outcome. Terminal-adjacent workstations moved to a distinct Intune class with per-app policy. Vendor access via Global Secure Access with time-boxed windows. Sentinel workbook produced the MTSA cybersecurity evidence pack.

03 / Frequently asked

What buyers ask first.

Do you work with all four TMC affiliates?
Identra works with TMC-affiliated hospitals, research institutions, and physician practices based on the specific institution engagement. TMC comprises dozens of independent organisations, each with its own IT and compliance leadership. Engagements are scoped to the specific institutional IT organisation and workload, not TMC as a whole.
How does TSA Security Directive SD-02 apply to Houston energy operators?
SD-02 applies to owners and operators of TSA-designated critical pipelines and LNG facilities. Many of the largest pipeline operators are Houston-headquartered, and the Directive flows down to specific pipeline systems within their portfolios. If your organisation received a Security Directive from TSA, you are in scope. Identra covers the Microsoft 365 side of the technical controls.
What is MTSA and how does it affect Microsoft 365?
The Maritime Transportation Security Act (2002) with the subsequent MTSA cybersecurity guidance requires Facility Security Officers at MTSA-regulated facilities to include cybersecurity in the facility security assessment and plan. Coast Guard NVIC 01-20 (2020) added specific cybersecurity expectations. Microsoft 365 controls on corporate-side systems that could reach the terminal operating environment are in scope of the assessment.
Are you Houston-based?
Identra operates remote-first. Houston customers receive the same delivery model as any other US customer: remote configuration, remote evidence delivery, with on-site presence available for workshops, walkthroughs, and executive briefings. Local proximity is helpful for kickoff and executive readouts but not day-to-day work.
What is the typical Houston engagement size?
Energy corridor engagements typically run 12 to 18 weeks. TMC healthcare engagements run 10 to 14 weeks. Port logistics engagements run 10 to 14 weeks. Fixed scope, fixed price. Manufacturing and chemical processing engagements can run longer if IP protection scope is broad.

Next step

Book a Houston scoping call.

Thirty minutes on your Microsoft 365 posture and the regulator or auditor asking about it. Written scoping note within two business days.