CASE STUDY · SECURITY & PRIVACY, ASSESSED TOGETHER
Two disciplines, one baseline, one roadmap
A listed international recruitment group had its information security and its data protection independently assessed in the same quarter. Both were scored against maturity targets, and one improvement plan came out of both. It was resourced through fractional security and data protection leadership rather than a hire, and delivered by the organisation's own people.
Three years later the security baseline was re-measured: 1.95 to 3.24.
2
disciplines assessed in the same quarter, scored against targets
135
recommendations consolidated into one roadmap of 33 work packages
1.95→3.24
security maturity re-measured against the 2020 baseline
6
years of continuous engagement, and still advising
2020 · THE BASELINE
Two assessments, deliberately at the same time
Most organisations buy these separately, a year or two apart, from different firms. This one commissioned both assessments in the same quarter. The two disciplines share a policy framework, a training programme, a third-party population, a risk register and a board — assessed apart, each review recommends its own version of the same six things. Technical control testing was deliberately excluded from both and run concurrently by a separate third party.
Information security, 2020
Independently assessed and scored across the five NIST CSF functions on a five-level maturity scale, through stakeholder interviews and review of supporting evidence. Thirty-four recommendations raised.
Assessed position against the targets agreed at the time. Scale 0–5; overall position between initial and repeatable.
Data protection, 2020
Assessed against consolidated requirements spanning the GDPR jurisdictions and further territories across three continents, over governance, records and operational controls. A hundred and one recommendations raised.
Scored categories grouped into eight related areas, weighted so the overall average holds at 1.1. Every underlying category scored between 0.7 and 1.7. No maturity target was set for data protection in 2020, so the dashed ring marks 3.0 — implemented and documented. Scale 0–5.
The organisation's own view was considerably higher. Its internal maturity assessment was refreshed three times during the review, and each time the figures were discussed the average fell, from 4.0, to 3.7, to 3.2, against the independently assessed 1.1. Nothing changed in those weeks except how clearly the maturity levels were understood.
The report put it in one line: previous self-assessments had over-estimated maturity.
A self-assessment measures how confident you are. It does not measure what you can evidence.
2020 · THE PLAN
One roadmap out of both
The two assessments produced 135 recommendations between them: 34 on security, 101 on data protection. Handed over as two documents, that becomes two programmes competing for the same people. Instead they were consolidated into a single improvement plan taken to the board: six workstreams, thirty-three work packages, and every package traced back to the numbered recommendations it closed, in both reports.
Information Security
01
Security Hygiene
Policy and minimum standards, roles and responsibilities, threat and risk assessment of critical assets, onboarding and ongoing training.
02
Mature Controls
Documented and embedded operational processes, an ongoing security testing programme, third-party security risk management.
03
Measured Security
Management reporting, operational process testing, staff awareness testing.
Data Protection
01
Framework
Global framework, placement of the DPO, roles and responsibilities, policy framework and local standards, privacy by design, training.
02
Demonstrable Accountability
Board statement, business self-assessments, data flow mapping, records management, risk assessments, compliance monitoring.
03
Operational Remediation
Lawful basis management, data subject rights, data retention management, third-party management.
Both streams put governance and roles and responsibilities in the first quarter. Both put testing, compliance monitoring and assurance deliberately last, there is no point testing a control that has not been defined yet. Effort was split openly between ICA Consultancy and the organisation's own people, with more than half the total resting with the business.
2021 · RESOURCING
Resourced fractionally, not hired
Neither capability was recruited. Both were held fractionally, in parallel, and structured to be independent of one another, because the assessments had found the opposite arrangement to be a problem in itself.
INSIDE THE PROGRAMME
Ran delivery across both streams and chaired the programme’s steering committee, reporting into the board’s risk committee. Authored the policy and minimum standards framework the 2020 review had called for.
15
work packages delivered across the three security workstreams
DELIBERATELY OUTSIDE THE PROGRAMME · LATER TAKEN IN HOUSE
Placed outside the delivery team, to advise and assure rather than deliver. In 2020 the DPO had sat inside the security function and reported through it, while also designing the processing, authoring the training, maintaining the records and the risk register, and personally handling data subject requests. All first-line work.
30
work packages delivered across the data protection programme
A DPO who builds the thing cannot independently assure it, and the regulation expects an unfiltered line to the board. Repositioning the role was scoped as the first work package of the data protection programme, a finding acted on, not a preference.
Once transformation completed, both roles stepped down to a lower ongoing cadence with a pool of flexible days drawable against either. That is the arrangement the security advisory has run on ever since, drawn against when it is needed, renewed as the work requires, rather than a fixed monthly retainer paid whether or not there is anything to do.
The data protection role did not stay fractional, and was never meant to. As the volume of processing grew, a permanent in-house Data Protection Officer became the right answer, and the organisation recruited one. ICA Consultancy handed over and ran alongside the incoming DPO for a short period, so what they inherited was a working framework, a maintained set of records and a live risk register, not a folder of documents and a handover note.
A fractional role that makes itself unnecessary has done its job. The point of holding a capability is to establish it, evidence it, and leave it somewhere it can be owned.
THE ENGAGEMENT
Six years, measured from the same starting point
2020
Two independent assessments
Information security posture independently reviewed and scored; data protection reviewed across the GDPR jurisdictions and further territories on three continents. Both scored on the same maturity scale, with targets set for security. A third party assessed technical controls concurrently.
2020
One improvement plan to the board
135 recommendations consolidated into six workstreams and thirty-three work packages, phased across five quarters, with effort and cost attached and split between ICA Consultancy and the business.
2021
Two remediation programmes, run in parallel
Delivered through fractional security leadership and a fractional DPO. Forty-five work packages in execution: policy and standards framework, asset management, incident management, access management, vulnerability management, third-party risk, alongside records of processing, lawful basis, retention, international transfers, data subject rights, training and assurance.
2023
Board action mapping, then independent re-assessment
The board’s cyber action list mapped against two commissioned engagements, with coverage stated honestly action by action — including where the work would deliver roadmap planning rather than full strategy. Then the security baseline re-measured, and a fresh strategic roadmap alongside it.
2026
Re-baselined again
Maturity re-assessed against version 2.0 of the framework, with a further roadmap. The advisory arrangement continues as it has for years — principal risk reviews, oversight of customer due diligence, audit meetings and policy reviews, drawn against as needed and renewed each time the work calls for it.
2023 · THE PROOF
Re-measured against the original baseline
In late 2023 the organisation was independently re-assessed across the same five functions and, beneath them, twenty-three individual capabilities.
Protect gained two full levels and passed its original target. Detect gained one and a half. Overall maturity moved from 1.95 to 3.24 against an original target of 3.75, and the target was then revised upward to 4.0, set at capability level rather than domain level, to avoid gold-plating controls the business had no need of.
Recommendation volume tells the same story from the other direction: 135 open in 2020, 37 in 2023.
2023 · THE DATA PROTECTION OUTCOME
Confirmed by a different assessor, on a different framework
The data protection programme was not re-scored in 2023. It did not need to be, because the security re-assessment reported on it independently.
Recorded as good practice
The 2023 security assessment listed effective data governance, with data subject request and privacy impact assessment processes embedded, among the organisation's strengths. A separate assessor, on a separate framework, three years after the programme.
SOURCE · 2023 SECURITY ASSESSMENT
Adopted as the model
Among the board's cyber actions for the following year: build a security champions model, explicitly modelled on the data protection programme. The engagement approach became the organisation's own template for business engagement.
SOURCE · BOARD ACTION LIST, 2023
The remaining data protection gaps named in 2023 were narrow and specific, completing the retention schedule, consent management tooling, and classification to support data loss prevention, rather than structural.
The clearest evidence is what the organisation did next: it brought the Data Protection Officer role in house permanently, because the volume of processing warranted it. An organisation that had over-estimated its own maturity in 2020 was, within a few years, funding a full-time role to run what the programme had built.
THE FINDING WORTH TAKING AWAY
What moved, and what did not
The strongest 2023 scores were all in controls owned and delivered by the IT function: access control, data security, protective technology, detection, response planning — several at 4.0. Technical controls had reached the point where further risk reduction would cost more than it returned. Two capabilities had not moved at all.
1.2
Third-party security
Assessment happening only at contract initiation, and only above a value threshold. Nothing in-life, nothing at exit — leaving the organisation unable to assess supply chain disruption risk.
RAISED IN 2020 · STILL OPEN IN 2023
2.0
Recovery planning
No business continuity plans available, no post-pandemic disruption scenarios identified, and no recovery objectives given to IT to plan against. Response would have been ad hoc.
RAISED IN 2020 · STILL OPEN IN 2023
Neither gap was for want of expertise. Risk management, IT, procurement and the programme office could each contribute part of both. No one owned the whole of either.
The same structural fault had appeared in both disciplines, three years apart: a second-line function doing first-line work, and first-line capabilities left unowned because a specialist had been brought in. It is the reason both fractional roles were scoped to advise and assure rather than to absorb.
Technical controls improve when you fund them. Supply chain risk and continuity improve only when somebody in the business owns them.
