The starting position
Like most organisations we assess, the client had more security in place than they could evidence and less than they assumed. Controls existed informally — some MFA here, some patching there — but nothing was measured against the Essential Eight maturity model, and there was no coherent information security management system to point to when clients or insurers asked hard questions.
What we did
- Essential Eight assessment — an evidence-based review of all eight mitigation strategies, scoring actual maturity rather than intended maturity, and identifying the gaps that mattered most to their risk profile.
- Prioritised remediation roadmap — a sequenced plan that put the highest-risk, lowest-effort fixes first, so the client could show measurable progress within weeks rather than waiting for a perfect end state.
- ISO 27001-aligned governance — the policies, risk register, roles and management rhythms needed to run security as an ongoing management system, built to be auditable without burying a lean team in paperwork.
- Board and stakeholder reporting — plain-language reporting that let leadership track maturity movement and answer client due-diligence questionnaires with confidence.
The outcome
Over the four-month engagement the organisation lifted its Essential Eight maturity and established an ISO 27001-aligned security program it could actually operate — with evidenced controls, a living risk register and a governance cadence that survives staff change. Just as importantly, security stopped being an IT conversation and became a board-visible, client-facing capability.
Why we anonymise
Our clients trust us with their security posture; we do not trade that trust for marketing. We publish case studies with identifying details removed, and we are happy to walk through the approach in more detail — including what we would do differently for your environment — in a direct conversation.