Validate Your Defences

From assessment to implementation for a manufacturer

The assessment had been done. It was competent, it was eighteen months old, and not one of its recommendations had been implemented.

This is the most common failure in security work and it is rarely a failure of knowledge. The organisation knew what to do. It did not have the hands, the sequence or the confidence to start, and every month that passed made the document look more out of date and easier to set aside.

What we changed

We did not redo the assessment. We took the existing one, checked what was still true, and turned it into work that could actually be picked up.

  • Grouped forty recommendations into six pieces of work with a beginning and an end
  • Sequenced them so each one made the next easier rather than harder
  • Named who would do each, from their team or ours, before starting anything
  • Set the first review for two weeks in, not two quarters

Nine of the forty recommendations had already been implemented by the internal team. Nobody had recorded it, so the list still showed them as outstanding and the team still felt they had made no progress.

Working through it

We stayed for the delivery. That is the difference between this engagement and the one before it. Where the internal team could do the work, they did, and we reviewed it. Where they lacked a specific skill or the time, we did it and handed it over with enough documentation that they could maintain it.

Where it left them

Five of the six pieces are complete, and the sixth has a date. More usefully, the team now has a way of working through this kind of list that does not depend on us being in the room.

The findings became fixes rather than another report, which was the only outcome that would have justified doing the assessment at all.

← All customers

If you need help, we're here.

Tell us where you are, and we'll help you find the right first step.

Talk to us