Case Studies
Quantified outcomes, not testimonials.
Illustrative engagements modelled on the incident and enforcement patterns we work against. Not accounts of specific clients.
Ending permanent admin access at a community bank, before the next review
Community bank · ~$900M in assets · 210 staff, 3-person IT team · FFIEC follow-up review in one quarter
24 → 2
permanent admin accounts (emergency use only)
15 min
elevation window, down from permanent
0
identity findings at the follow-up review
2 days
evidence prep, down from 3 weeks
Taming 1,400 machine identities at a Series B payments platform
Series B payments platform · ~180 employees · one security engineer · SOC 2 Type II deadline in 5 months
1,400
NHIs inventoried & owned
78% → 6%
cloud keys older than 90 days
31
privilege escalation paths closed
Pass
SOC 2 Type II, first attempt
Closing the password-only front door at a community hospital
Community hospital · one site plus four clinics · 4-person IT team, no dedicated security staff
100%
MFA coverage on remote access
18
vendor accounts scoped to their BAA and given expiry dates
0
patient-data findings at the next audit
15 min
break-glass activation, fully logged
Governing AI agents that touch PHI in clinical research
Clinical-research healthtech · ~50 employees · LLM pipelines over sensitive patient data · HITRUST on the roadmap
0 → 27
AI agent identities governed & owned
Zero
standing access to PHI, any identity
Automated
HIPAA Section 164.312 evidence collection
HITRUST-ready
control evidence on demand
How we build these — and why there are no client names
Every engagement above is a composite. We take the identity failure patterns visible in public breach disclosures, regulatory enforcement actions, and examination findings from 2024 onward, and combine two or three of them into a single scenario — varying sector, size, and geography so that no real organisation can be identified from the detail.
What is real: the failure modes, the regulatory drivers, the control changes, and the sequence of work. The scope of each engagement is what a small team can actually deliver in weeks.
What is not: the organisations. There is no client here whose name we are withholding, and the figures are representative of the pattern rather than extracted from a specific client's records. We keep an internal record of which public incidents informed each scenario; it is not published, because publishing it would defeat the point.
We could write this page the other way — assert live client work, cite NDAs, imply permissioned metrics. Every consultancy does. It is a factual claim about provenance, and we would rather it be one you can trust than one that sounds better.
Wondering whether one of these scenarios is already yours?
The same patterns show up long before anyone calls them an incident. A 30-minute Identity Risk Review names which of them your systems is currently carrying — and what it would take to close each one.
Book an Identity Risk Review