CASE STUDIES
What the work actually found
Engagements written up as they happened, the scope, what surfaced, and what the organisation did about it. Clients are anonymised unless they have agreed otherwise.
INCIDENT RESPONSE EXERCISING
Two organisations, the same ransomware, three hours each
A UK specialist bank and a national multi-site operator, both taken through the same scenario. Neither struggled technically. Both stalled at the same place, decisions nobody was written down as being allowed to make.
21
findings raised, only four were technical control gaps
ENTERPRISE RISK MANAGEMENT
Group-wide risk management, from food safety to cyber
A multi-site chilled food manufacturer wanted one method across every risk domain in the group, governance and process agreed first, tooling chosen afterwards against a known specification.
8
risk domains, scored one way, run by the business itself
FRACTIONAL CISO
No in-house security leadership. A board with a need.
No security leadership, no maturity baseline, and a board that needed assurance it could not yet get. Three phases, from standing up governance to a register the board can watch trending.
15
risks scored across three phases of the programme
ENTERPRISE SECURITY STRATEGY
Compliance as an outcome, not an objective
A hosting provider growing its market share knew a bigger presence meant a bigger target. Every proposal they'd received was generic. They wanted a strategy built from their own threat landscape, with ISO 27001 falling out of it rather than driving it.
36
months of strategy, built on a NIST capability model mapped to ISO 27001
How we write these up
Every case study is drawn from the engagement's own record, the report, the register, the assessment. Findings are attributed to the group rather than to individuals, clients are anonymised by sector unless they have agreed to be named, and where a figure is a projection rather than a result, the page says so on the page. If a claim here matters to a decision you are making, ask us for the detail behind it.
