Skip to main content

Case Studies

Quantified outcomes, not testimonials.

Illustrative engagements modelled on the incident and enforcement patterns we work against. Not accounts of specific clients.

How we build these — and why there are no client names

Every engagement above is a composite. We take the identity failure patterns visible in public breach disclosures, regulatory enforcement actions, and examination findings from 2024 onward, and combine two or three of them into a single scenario — varying sector, size, and geography so that no real organisation can be identified from the detail.

What is real: the failure modes, the regulatory drivers, the control changes, and the sequence of work. The scope of each engagement is what a small team can actually deliver in weeks.

What is not: the organisations. There is no client here whose name we are withholding, and the figures are representative of the pattern rather than extracted from a specific client's records. We keep an internal record of which public incidents informed each scenario; it is not published, because publishing it would defeat the point.

We could write this page the other way — assert live client work, cite NDAs, imply permissioned metrics. Every consultancy does. It is a factual claim about provenance, and we would rather it be one you can trust than one that sounds better.

Wondering whether one of these scenarios is already yours?

The same patterns show up long before anyone calls them an incident. A 30-minute Identity Risk Review names which of them your systems is currently carrying — and what it would take to close each one.

Book an Identity Risk Review