Detailed project case study

Cybersecurity, GDPR & Compliance Uplift

A broad security and compliance uplift spanning identity, data protection, secure transfer, firewalls and operational governance.

Portfolio headline

Strengthened security and compliance across the estate through better access control, data protection, secure transfer, firewall governance and regulatory readiness.

01

Context

Regional operations and a growing digital estate increased exposure across identity, data movement, endpoints and suppliers. Controls needed to improve without making everyday delivery unworkable.

02

My mandate

Strengthened security and compliance across the estate through better access control, data protection, secure transfer, firewall governance and regulatory readiness.

03

Scope

  • Enterprise
  • Cybersecurity & Compliance
  • simplehuman

Selected technologies

  • MFA
  • Microsoft Intune
  • Encrypted SFTP
  • Firewalls
  • GDPR
  • NCSC guidance
  • Access control
  • Security governance
04

Key decisions

  • Expanded MFA and strengthened identity and access controls.
05

What the team delivered

  • Improved encrypted SFTP, firewall governance and secure data-transfer patterns.
  • Aligned operational controls and evidence with GDPR, NCSC guidance and regional requirements.
06

Outcome

  • Reduced identity, data-transfer and perimeter risk.
  • Improved regulatory readiness and evidence-led governance.
  • Made security ownership part of platform and operational decisions.
07

Evidence

Public details are limited to the operational record and outcomes that can be discussed safely. Supporting evidence is available in interview where appropriate.

08

What this demonstrates

This project shows risk ownership rather than a list of security tools: controls were designed around the way the business operated and the evidence it needed.