
Recurring problems we are brought in to solve, and the approach we take to each — written so you can judge the thinking, not just the outcome.
Each one follows the same shape: what the organisation was facing, how we approached it, and what actually changed.
A department facing its first GovAssure cycle, unsure which systems were in scope and whether its evidence would survive independent review.
Read the case studyAn organisation with far more suppliers than it could assess, treating every one of them to the same depth and therefore assuring none of them well.
Read the case studyA delivery programme told that Secure by Design was mandatory, with the self-assessment treated as a document to complete near go-live.
Read the case studyAn operator whose operational technology had been assessed with methods designed for corporate IT, producing findings its engineers could not act on.
Read the case studyThese are anonymised, representative engagements. We do not publish client names, or figures we cannot substantiate, without explicit permission — particularly in government and critical infrastructure, where naming a client can itself be a security concern.