Detailed project case study
Cybersecurity, GDPR & Compliance Uplift
A broad security and compliance uplift spanning identity, data protection, secure transfer, firewalls and operational governance.
Strengthened security and compliance across the estate through better access control, data protection, secure transfer, firewall governance and regulatory readiness.
Context
Regional operations and a growing digital estate increased exposure across identity, data movement, endpoints and suppliers. Controls needed to improve without making everyday delivery unworkable.
My mandate
Strengthened security and compliance across the estate through better access control, data protection, secure transfer, firewall governance and regulatory readiness.
Scope
- Enterprise
- Cybersecurity & Compliance
- simplehuman
Selected technologies
Key decisions
- Expanded MFA and strengthened identity and access controls.
What the team delivered
- Improved encrypted SFTP, firewall governance and secure data-transfer patterns.
- Aligned operational controls and evidence with GDPR, NCSC guidance and regional requirements.
Outcome
- Reduced identity, data-transfer and perimeter risk.
- Improved regulatory readiness and evidence-led governance.
- Made security ownership part of platform and operational decisions.
Evidence
Public details are limited to the operational record and outcomes that can be discussed safely. Supporting evidence is available in interview where appropriate.
What this demonstrates
This project shows risk ownership rather than a list of security tools: controls were designed around the way the business operated and the evidence it needed.