Case study · 17 April 2026

Zero-trust uplift for a multi-site organisation

Summary
Context

The challenge

A national organisation needed stronger assurance across distributed sites without halting operations. Legacy perimeter thinking no longer matched how staff worked: remote access, contractor access, and business-managed devices increased the attack surface.

Details

What we did

We aligned leadership on a pragmatic definition of zero trust: continuous verification of identity, device health, and least-privilege access, implemented in phases that could be measured each month.

1. Identity and access segmentation

We modernised conditional access policies for cloud workloads, reduced standing privileges for administrators, and introduced time-bound elevation for break-glass scenarios.

2. Endpoint baselines and patch discipline

We defined a minimum security baseline for corporate devices, prioritised critical vulnerability remediation windows, and introduced reporting that made gaps visible to owners - not buried in tickets.

3. Telemetry and governance

We connected key signals (sign-in risk, device compliance, privileged activity) into monthly governance forums. Decisions were recorded as explicit risk acceptance where required, which reduced “silent drift”.

Outcomes

  • Fewer uncontrolled admin pathways into core business systems
  • Stronger confidence in device compliance reporting before major change windows
  • Clearer prioritisation of remediation work based on business criticality

Lessons learnt

Zero trust is not a product purchase - it is an operational rhythm. The organisation succeeded because security, IT operations, and business stakeholders shared the same scoreboard and iterated monthly.

Related

Pre-travel hardening, secure communications, and rapid response for executives travelling across APAC.

Practical readiness: playbooks, drills, and leadership cadence for credible response.