top of page

CASE STUDY · ENTERPRISE SECURITY STRATEGY

Compliance as an outcome, not an objective

An award-winning internet and hosting provider set out to grow its market share, and recognised that a bigger presence meant a bigger target. They wanted a security strategy built around the threats they would actually face — with ISO 27001 compliance falling out of it rather than driving it.

3

phases of engagement: threat and capability review, strategy, first-year plan

36

months of strategy, structured as three twelve-month phases

2

frameworks, a capability model on NIST CSF, mapped back to ISO 27001

1

ive resilience exercise that changed the organisation's mind overnight

Everyone else sent them the same proposal

The client approached their existing providers and several well-known names first.

What came back was untailored. Proposals that answered a generic version of the question and left their wider concerns untouched.

 

What they actually wanted was harder to buy: a strategy that satisfied ISO 27001, but that started from a company-wide understanding of their own threat landscape and an honest read of what they could and could not currently defend against.

So the objectives were set explicitly at the outset. Understand the specific threat landscape. Assess current capability and maturity against it. Work culturally rather than imposing a model. Leave the client able to keep delivering the strategy themselves. Help the organisation understand the problems the strategy solves. And make compliance an outcome of the strategy, not its purpose.

Starting with who would actually attack them

A hosting provider serving both homes and businesses is a target twice over: directly, and as a route to its customers.

The review reflected that. We produced a prioritised list of threat actors likely to target the client directly or use them to reach someone else, and identified the indirect exposure created when one of their customers is the real objective.

Those threats were then assessed against the client's own business strategy, which grow as the business grows, and which recede.

Stakeholder engagement ran from the CEO down. Not for the sake of thoroughness, but because a security strategy the executive does not recognise as addressing their concerns is a document rather than a strategy.

The review also surfaced unknown unknowns: exposure the client did not know it had.

Why compliance came second

The capability model was built on the NIST Cyber Security Framework, extended beyond cyber to cover information security, then mapped back to ISO 27001.

That order matters. Build to the compliance framework first and you get a control set that satisfies an auditor and may or may not reflect your threats. Build the capability model first and map it, and every maturity improvement shows up in the compliance framework automatically, because compliance becomes a consequence of being secure rather than a separate workstream.

The client got a secure operating environment that enabled compliance, rather than a compliance programme they hoped would make them secure.

“No tick-box exercise, and no framework adopted without being understood.”

What was designed

A three-phase strategy, each phase twelve months, covering security priorities, response tooling and capability, presented as a single defined position.

The threat landscape

Prioritised threat actors, direct and indirect, assessed against the business strategy.

Immediate tactical changes

Gaps that could not wait for the strategy, addressed in parallel with it.

A security baseline

The position everything after it would be measured against.

Measuring effectiveness

An agreed approach to knowing whether any of it was working.

Capability to improve

An honest read of what the organisation could change itself, and what it could not.

Phases of implementation

Three twelve-month phases, sequenced to what the business could absorb.

A control framework

Built on NIST CSF, extended to information security, mapped to ISO 27001.

A first-year plan

Work packages and initiatives, matched against in-flight projects already moving.

Three Phases

Baseline and immediate gaps

Tactical changes made straight away, the baseline established, and the first year's work packages delivered against it.

Capability build

Response tooling and capability developed against the priorities the threat review identified.

Maturity and measurement

Effectiveness measured against the baseline, with maturity improvements reflected automatically in the compliance framework.

Then we made the threats real

A strategy document argues that the threat is real. An exercise demonstrates it.

The strategy presentation was followed by a cyber resilience exercise, delivered with a specialist third party as a single seamless engagement: a real-time scenario built around the client's own environment and services. It is the same approach we now run as cyber incident response exercises.

 

It produced an overnight change in how the organisation thought about security. The consequences were concrete — a revamp of their approach to risk management, a reappraisal of business resilience, and a substantially increased security budget.

The second is what moves money.

What Changed

Looking ahead

The engagement continues. ICA Consultancy is augmenting the client's team through delivery of the first phase, handing over progressively as their capability matures, providing ad-hoc access to virtual resources and supporting the purchase of new commercial solutions.

What began as a fixed-price, fixed-outcome engagement became a deeper integration into the client's strategy, and will continue in some form until that strategy is delivered.

Building a security strategy around your actual threats?

ICA Consultancy provides enterprise security strategy, capability modelling and Capability as a Service to organisations across the UK and Europe.

bottom of page