Case Studies
Real problems, measured outcomes — a sample of the work we have done and the results we have helped clients achieve.
Passing a CBK audit with zero material findings
A mid-sized financial services company preparing for a CBK regulatory audit needed an independent assessment of its internet-facing systems and internal network before the examination window.
A two-week external and internal penetration test across web applications, VPN infrastructure, and Active Directory — scoped tightly to avoid disruption to live banking operations.
We surfaced critical findings, including an unauthenticated API endpoint exposing customer account data. All were remediated before the audit, and the client passed with no material security findings raised.
A board-approved roadmap to ISO 27001
An international NGO was required by a major donor to demonstrate ISO 27001 alignment. With no existing ISMS, they needed to understand the gap before committing to certification.
A structured gap assessment against all ISO 27001:2022 Annex A controls, a review of existing policies and technical controls, and interviews with department heads across IT, HR, and finance.
We delivered a gap report and a phased remediation roadmap sized for a lean IT team — which the client used to secure board budget approval for an ISMS implementation project.
Closing critical AWS gaps ahead of enterprise sales
A SaaS startup processing health data needed to demonstrate security rigour to enterprise customers running procurement due diligence. Its AWS environment had grown quickly without a formal review.
We audited the AWS environment against CIS Benchmark Level 2, reviewed IAM roles and policies, checked S3 bucket permissions, and assessed logging and monitoring posture.
We found high-severity misconfigurations including publicly accessible S3 buckets. All critical findings were remediated quickly, and the client shared our report with enterprise prospects as evidence of due diligence.