ProArch Logo

Lewis Services Achieves 90% Efficiency Gains

With ProArch’s Dataware Data Platform

Lewis Services

About Lewis

Lewis Services is one of North America’s largest vegetation management companies. With over 4,000 staff members and 200 customers across the country, Lewis plays a critical role in the US energy infrastructure.

 

Solutions Used

 

 

Situation: Painful Invoice Processes & Time-Consuming Timesheets

Without a centralized system, Lewis’s payroll processing and customer invoicing were challenging, slow, and manual. To put it in perspective, the company processed 86,000 spreadsheets for payroll each year. This required nearly 45 full-time employees to complete, and the General Foreman had to enter the same data four times.

“The general foremen were being pulled in so many directions that it was causing inefficiencies in operations,” says Huntley Hedrick, VP of IT at Lewis.

Weekends of time-consuming work made for unhappy employees, payroll delays, slow revenue realization, and poor customer experiences.

 

Solution: Data Platform & Custom Application

Using ProArch’s Dataware Data Platform, the team integrated the HR and ERP systems into a data warehouse and then developed a custom application called “Tiempo.”

The data modeling in the background simultaneously calculates payroll and invoices based on customized rules by location, job type, pay rate, employee, and start/end time. 

 

Results: A Game-Changer All Around

  • Lewis has experienced a 90% reduction in the overall effort with a clear, streamlined process for time entry, timesheet creation, and approval.
  • Advanced reporting capabilities using data from different systems.
  • Before, Lewis experienced a high volume of invoice adjustments. Now, it is a 3% adjustment rate.
  • Customers have a better experience, and Lewis can realize revenue faster.
  • Lewis owns the tool so they can avoid future costly and complex ERP upgrades and customization.

For the general foremen, Tiempo has been transformational. Hedrick added, “What I’ve observed with the rollout of Tiempo has been greater than anything that I’ve ever seen in my career with how accepted it’s been in such a short amount of time.”

How Far Could an Attacker Get? Validating Cloud Identity Resilience at MDC Research

Overview

MDC Research, a market research organization, engaged with ProArch for independent verification that its cloud identity environment that is heavily dependent on Microsoft Entra ID and SaaS applications was protected from evolving identity based threats.

MDC Research wanted to understand whether its cloud identity environment, the primary target of modern threat actors, could withstand advanced attacker tradecraft.

Services

  • External Penetration Testing
  • Cloud Identity Penetration Testing
  • Microsoft Entra ID Security Assessment
  • Security Recommendations & Cloud Identity Hardening Roadmap
Challenge

MDC Research wanted a clear answer to a critical question:

If an attacker obtained a low privilege user token, how far could they get?

The organization’s key concerns included:

  • Increasing identity‑centric attacks targeting Microsoft cloud tenants
  • Evaluating exposure across public‑facing IPs and SaaS‑integrated apps
  • Determining if compromised user tokens could be abused for escalation
  • Understanding how delegated Microsoft Graph API permissions could be exploited
  • Ensuring Conditional Access, token governance, and directory restrictions were effective
  • Validating resilience against reconnaissance and privilege abuse attempts
  • Validation of device compliance restrictions preventing attackers from joining malicious devices into the customer’s Microsoft tenant
Solution

ProArch executed a comprehensive penetration test combining external perimeter analysis and cloud identity exploitation attempts.

Real world attacker tooling and techniques were used to simulate:

  • Token compromise
  • Graph API enumeration
  • Privilege escalation attempts.

Identity controls such as Conditional Access, least privilege app permissions, token lifetimes, and device compliance gating were tested extensively and shown to be effective, remaining resilient to even known bypass techniques.

Result

ProArch’s assessment validated MDC Research’s strong identity governance model and provided a clear, prioritized roadmap for further tightening Graph API scopes and delegated access permissions.

MDC Research now has reinforced confidence that its cloud identity environment is secure, resilient, and aligned to security and Microsoft best practices.

Industry

  • Market Research

Challenge

  • Risk of token abuse, Graph API exposure, and identity control gaps.

Solution

  • ProArch simulated real-world identity attacks to test controls and access paths.

Result

  • Validated strong security posture with clear steps to tighten access and permissions.

Fast Track Unlocking Value from Your Data

Connect With Us