top of page

CASE STUDIES

What the work actually found

Engagements written up as they happened, the scope, what surfaced, and what the organisation did about it. Clients are anonymised unless they have agreed otherwise.
INCIDENT RESPONSE EXERCISING

Two organisations, the same ransomware, three hours each

A UK specialist bank and a national multi-site operator, both taken through the same scenario. Neither struggled technically. Both stalled at the same place, decisions nobody was written down as being allowed to make.

21

findings raised, only four were technical control gaps

ENTERPRISE RISK MANAGEMENT

Group-wide risk management, from food safety to cyber

A multi-site chilled food manufacturer wanted one method across every risk domain in the group, governance and process agreed first, tooling chosen afterwards against a known specification.

8

risk domains, scored one way, run by the business itself

FRACTIONAL CISO

No in-house security leadership. A board with a need.

No security leadership, no maturity baseline, and a board that needed assurance it could not yet get. Three phases, from standing up governance to a register the board can watch trending.

15

risks scored across three phases of the programme

ENTERPRISE SECURITY STRATEGY

Compliance as an outcome, not an objective

A hosting provider growing its market share knew a bigger presence meant a bigger target. Every proposal they'd received was generic. They wanted a strategy built from their own threat landscape, with ISO 27001 falling out of it rather than driving it.

36

months of strategy, built on a NIST capability model mapped to ISO 27001

How we write these up

Every case study is drawn from the engagement's own record, the report, the register, the assessment. Findings are attributed to the group rather than to individuals, clients are anonymised by sector unless they have agreed to be named, and where a figure is a projection rather than a result, the page says so on the page. If a claim here matters to a decision you are making, ask us for the detail behind it.

Recognise your organisation in any of these?

ICA Consultancy provides cyber security, data protection and risk services to regulated and multi-site organisations across the UK.

bottom of page