Case studies / selected work

Case studies

Seven pieces of work we have built, secured, or run. Each one records what the situation was, what we did, and what changed. Every client is described by its sector rather than named, and we leave out any detail that would help an attacker or breach a client confidence.

AcrossFour disciplines
Each recordSituation, work, outcome
ClientsAnonymised by default
Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber EssentialsCertification body Cyber Essentials PlusCertified NCSC AssuredCyber Advisor MicrosoftCertified Expert
Case Studies / 01 · Selected work

Seven pieces of work

Security reviews and remediation, Zero Trust and identity, certification, migrations to Microsoft 365 and to the cloud, and full desktop virtualisation. Different sectors, one accountable team behind all of it. Why each one is described by sector rather than named is set out below.

SecurityCase 01

Security assessment and remediation

A security review found a set of critical vulnerabilities. We remediated them, then moved the firm onto managed services so the gaps stay closed.

12 risks identifiedRemediated then managed
Professional services Read case study
SecurityCase 02

A Zero Trust implementation

Centralised authorisation on Entra ID, with device lockdown, single sign on, and Conditional Access policies applied consistently across every platform.

Zero Trust across platformsFull single sign on
Defence Read case study
CloudCase 03

Ageing servers, retired to the cloud

Migration from ageing on-premises servers to hosted cloud infrastructure: file server, Active Directory, and line of business apps, all reachable over secure VPN connectivity.

No CapEx on hardwareNo server room
Manufacturing Read case study
MigrationCase 04

From Google Workspace to Microsoft 365

A migration from Google Workspace to Microsoft 365, with mailboxes, files, and user profiles moved across, staged and tested to minimise disruption to operations.

50+ users migratedStaged cutover
Aerospace Read case study
ComplianceCase 05

From no formal IT to Cyber Essentials certified

A standing start taken to certification: device management, a hosted VPN, written policies, regular patching, and a clean Cyber Essentials pass.

Certified Cyber Essentials8 weeks
Construction Read case study
SecurityCase 06

Basic Microsoft 365 to a secured environment

Taking organisations from a basic Microsoft 365 setup to a secured environment, with Defender, Intune, and Conditional Access deployed and configured.

Defender deployedCA policies in place
Various sectors Read case study
CloudCase 07

Azure Virtual Desktop for a remote first team

Full desktop virtualisation for a remote first financial services team: work from anywhere, on any device, with the whole estate managed centrally.

BYOD enabledAnywhere on any device
Finance Read case study
Case Studies / 02 · How we work

How does an engagement run?

Different problems, one way of working. We start by understanding what matters, fix the highest risks first, and build security and evidence in from the start rather than bolting them on. The responsibility stops with us.

01Understand firstWe learn how you work before we propose anything, and we check the assumptions with you.
02Fix what mattersA prioritised plan that deals with the serious risks and the quick wins first, at your pace.
03Build it inSecurity and governance are designed in from the start, not retrofitted to pass a review.
04Prove itClear evidence and a record of what was done, the way insurers and auditors want it.
Case Studies / 03 · How we tell it

How we describe the work

We apply to ourselves the rule we set our clients: nothing goes on this page that would help someone attack the organisation it is about.

01

The problem

What was at stake and why it mattered, in business terms anyone can follow.

02

The approach

How we thought about it and what we did, without the operational detail an attacker could use.

03

The outcome

What changed, and the limits of what we can show. We do not dress up figures or claim precision we cannot stand behind.

04

The discretion

Every client above is described by its sector rather than named. That is not modesty: a named client alongside the detail of what was weak and what we changed is useful to anyone planning an attack on them, and it is their information to disclose, not ours. We name a client only with written consent, and none has been given for the work on this page.

A simple test before anything goes public: could this help someone attack or embarrass a client? If so, we abstract it until the answer is no.

Talk to us about your project.

Bring us the system to build, the risk to close, or the migration you have been putting off.

Reading, Berkshire  /  clients described by sector, named only with written consent  /  reply within one working day