
The information security officer.
Sits at a utility, owns the risk decision, and has stopped opening the platform because the output does not arrive in a form she can use.
A single product can carry 300 vulnerabilities and only 20 that matter. We turned Fortress’ three siloed tools into one platform built to surface the 20.

Fourteen weeks from discovery to boardroom.
The company securing the grid nobody thinks about.

Fortress Information Security is a supply chain cybersecurity company built for one job: protecting the vendors, products, and software that critical infrastructure runs on. From Orlando, Florida, it assesses supplier risk, analyzes software and hardware bills of materials, monitors products continuously, and tells utilities and federal agencies which of their thousands of suppliers is the one worth worrying about.
Customers had quietly stopped opening the platform.
A company protecting the nation’s power grid was delivering its findings as a 200-page PDF assembled from three separate tools, and the security officers it was written for had decided it was not worth reading. The work had moved to email.
Vendors, products, and assessments each lived in a separate platform, and within each one the information map was flat: no hierarchy, everything surfaced at once, the same content repeated in multiple places. Clicking a link often landed you somewhere unrelated. The basics of UX were simply absent.
A single software product analysis could surface 300 vulnerabilities of which roughly 20 were genuine threats. Customers described navigating a sea of red findings with no way to tell which ones mattered, and the platform offered no ranking to help them.
Monthly reports ran to 200 pages, were regenerated from scratch each cycle, and called out no deltas against a baseline. One customer had stopped using the continuous monitoring service outright, not because it was wrong, but because they had nobody to sift through it.
If Fortress did not spot something, the customer could not either. Assessments closed, results were emailed to the line of business and the vendor, and nobody logged in. White-glove service was covering for a product that offered no self-service path, and collaboration ran through inboxes where it could not be tracked.
Internal account handlers, vendors submitting evidence, customers making risk decisions, and insurance carriers pricing that risk all needed the same data for entirely different jobs. Not everyone even cared about the same pillar of it.
Drag the handle to see the shift: three separate internal tools a customer had to stitch together themselves, beside Fortress Fusion, a single platform that assembles the picture for them.




Research ran on both ends of the assessment: twelve internal sessions across Fortress’ siloed teams, seven interviews with security officers and risk assessors at AEP, Exelon, PSEG, Xcel Energy, Southern Co, and PJM, and two industry SMEs on where the SBOM standard was actually heading. In a sector where almost everything sits behind a wall, those SME conversations were the only way to see the ground we were designing on. Three findings shaped the platform.
A single software analysis could return 300 vulnerabilities against roughly 90% of a product’s components, of which about 20 were genuine threats. As one SME put it, out of a hundred vulnerabilities, ninety-seven are not anything you need to worry about. Customers were being handed all one hundred and left to find the three.
Reports were regenerated monthly with no deltas called out and no baseline to compare against, so assessors had to re-read the whole thing to find what moved. One customer had dropped the continuous monitoring service entirely, saying they lacked the personnel to sift through it. Monitoring only works if something tells you when to act.
The research resolved into three things users actually track: risk across files, products, and vendors; progress, meaning what is open, in flight, and assigned to me; and compliance against internal and industry standards. Critically, not every client cared about all three, and people inside the same company cared about different ones.

Sits at a utility, owns the risk decision, and has stopped opening the platform because the output does not arrive in a form she can use.

Runs assessments day to day and needs streamlined, actionable reports with change callouts and baselines, not another 200-page document to read end to end.

On the supplying side of the assessment, asked to upload the same evidence into multiple platforms multiple times, with no visibility into what happens to it next.

Underwriting risk across the same supply chain and reading the same data for an entirely different purpose: comparability across a portfolio
The old platform put everything on the surface at once. The new architecture leads with what matters most and lets a user go a level deeper only when they need to, then deeper again, grouped around the three pillars rather than around Fortress’ org chart.
The old product modeled how Fortress runs an assessment. The new one models how a security officer thinks about risk: my ecosystem, my vendors, my products, my outstanding items.
Customers and assessors independently asked for the same thing: call out what changed and against what baseline. Reports had to surface movement since the last assessment rather than reprint 200 pages each cycle.
Static scores read as ambiguous and rarely drove action. What mattered was the trend line: is this vendor responsive, are findings actually getting remediated, is the number moving and why. Score changes had to be explained, not just displayed.
Severity colour coding, portfolio scoring, and status indicators so a user can read pass or fail without parsing a paragraph. In a product built almost entirely from tables and charts, that is the difference between scanning and reading.
In information security, compartmentalizing information is a discipline. At Fortress it had become an accidental product strategy. Three tools existed because three teams did, and each team held one piece of a story nobody was telling end to end. People knew their own step and not how it affected the process around it.
The clearest evidence of that was uncomfortable. By the close of the engagement, the person who best understood what Fortress does end to end was our product strategist, because she was the only one who had spoken to everybody. That is not a compliment to us, it is a diagnosis. A product organized around an org chart will always hand the integration work to the customer, and the fastest way to see it is to send someone from outside to walk the whole floor and write down what they hear. The prototype was the visible output. Getting four internal teams to agree, for the first time, on one customer and one product was the thing that made it possible.








Fortress came in asking for a module and came out with a named product, a unified architecture, and the prototype it took to its own leadership.
Research figures are drawn from WANDR’s internal and external findings reports for Fortress, delivered 2023. Outcome 04 reflects Fortress’ decision at WANDR’s project close-out in May 2023, when the concept moved into Fortress’ internal development.
The WANDR team impressed us right away, quickly understanding a complex business, engaging our stakeholders, and delivering value. It was refreshing and a joy to work with WANDR.