The starting point
The challenge
The firm’s systems had grown through a series of individual decisions. Its leadership suspected there were security gaps, but did not have a clear account of the exposure or which work should come first.
The brief was to review the environment and explain the findings in terms the business could use to make decisions.
What we did
The work
Assess the environment
We reviewed the environment and confirmed twelve distinct risks. Several were critical. Each finding was explained in terms of its business impact.
Prioritise and remediate
We ranked the findings so the most serious work happened first, then remediated each one and checked that the fix held.
Move into ongoing management
After remediation, the firm moved onto managed services so its environment would continue to be monitored and maintained.
What changed
The outcome
The engagement continued beyond the security report. The firm addressed the identified exposures and put ongoing management in place for its systems.
Findings addressed
All twelve identified risks were remediated.
A documented record
The firm received an account of what had been found and what had been done.
Ongoing oversight
Managed services followed the assessment and remediation work.
The client in this record is described by sector rather than named. Why we describe our work that way.