Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Case Studies

Cybersecurity Case Studies: Work We Can Talk About

We name clients where they have agreed to it, and describe the work without naming them where they have not. The scope, the approach and the numbers are exactly as delivered.

01SaaS, SOC 2

A SaaS Platform Reaches SOC 2 Type II on the First Attempt

Audit Exceptions
0
To Audit Ready
16 weeks
Faster Deal Reviews
3x

The Challenge

Enterprise deals kept stalling in security review. There was no formal control set, and evidence was scattered across half a dozen tools with nobody owning it.

What We Did

We ran a readiness assessment, agreed a control set sized to the company rather than the standard, automated evidence collection, and put the team through a mock audit before the real one.

02Healthcare, DPDP Act

A Hospital Network Builds DPDP Act Readiness Across 12 Facilities

Obligations Covered
94%
Facilities Onboarded
12
Breach Response SLA
48 hours

The Challenge

Patient data moved through dozens of systems with no data map, no consent record and no tested plan for a breach. Clinical operations could not pause for any of it.

What We Did

Data discovery and mapping first, then consent workflow design, DPO advisory and staff training, phased facility by facility so care delivery was never interrupted.

03Financial Services, Application Security

A Lending Platform Closes Critical Application Risk Before Scale-up

Findings Fixed
27
Criticals Closed
100%
Mean Time to Fix
9 days

The Challenge

Feature releases were outpacing security review, and a regulator-mandated audit was three months out with no assessment on record.

What We Did

Full web and API VAPT, secure code review of the payment and disbursement flows, fix support sprints with the engineering team, and verified retests, all inside the audit window.

Why No Client Is Named Here

Every engagement on this page is real and every figure is the one we delivered. None of the three clients has agreed in writing to be named, and until one does, naming them is not ours to do. Testing work in particular sits under a non-disclosure agreement that outlives the engagement, and a client who let us publish their security posture would be publishing a map of what was once weak.

So the record here is deliberately thin on identity and specific on work. If you want more than a page can carry, ask on the scoping call: we can walk you through the deliverable in anonymised form, including how a finding was written up and what the retest showed, which tells you more about how we work than a logo wall would.

In Their Words

What the Teams We Worked with Said Afterwards

The report was the first one our board actually read. Two pages of what mattered, then the detail our engineers needed. Every critical was retested and closed within a month.
Head of Engineering, fintech platformMumbai
We went from hoping we were fine to a SOC 2 Type II with zero exceptions. They did not just audit us, they taught our team how to keep it running.
CTO, B2B SaaS companyBengaluru
They found a critical issue three hours into testing and called us straight away instead of saving it for the report. That is the difference between a vendor and a partner.
CISO, healthcare groupDelhi NCR

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Why are none of your clients named?

Because none of the three has given written permission, and permission is the only thing that would make naming them right. Security work runs under a non-disclosure agreement that does not lapse when the invoice is paid, and for testing engagements there is a second reason beyond the contract: a named case study tells a reader which company had which weakness, which is useful to more people than us. Where a client does agree, we name them and say so on the page, which is what the introduction above means by work we can talk about. Everything else stays anonymised: the sector, the scope, the approach and the numbers are exactly as delivered, and the identity is the only thing withheld. If that is not enough to judge us on, the scoping call is where to press.

What do the numbers on each case study actually count?

Each figure counts something specific rather than something impressive. Audit exceptions are the exceptions recorded in the auditor's own report, so zero means the report carried none. Time to audit ready runs from the kickoff to the point the control set and evidence were complete enough for fieldwork, not to the certificate. Findings fixed and criticals closed are counted against the retest, so a finding only counts as closed when we retested it and it was gone. Mean time to fix measures from the day a finding was reported to the day its fix passed that retest, which makes it a measure of the client's engineering as much as ours. None of the three is a percentage of something unstated or a multiple with no baseline, which is the usual way a case study flatters itself. If a number matters to your decision, ask for the detail behind it on the scoping call and we will show you how it was arrived at.

Can we speak to one of your clients as a reference?

Sometimes, and we will ask rather than promise. When a prospective client asks for a reference we go to the client whose work most resembles theirs and ask whether they are willing to take a call. Some agree and some do not, and we do not pass on a name before they have said yes. Where nobody is available we offer the next best thing instead of nothing: a walkthrough of the actual deliverable with the client's details removed, so you can see how findings are written, how severity is argued, and what a retest record looks like. Most buyers tell us the redacted report answers the question they were really asking, which is whether the work is any good rather than whether someone else liked us. It is also the fairer test, because a reference call reaches whoever was willing to take it, and a deliverable is the thing you will actually receive.

If we hire you, will our engagement end up on this page?

Only if you tell us in writing that it can, after the work is finished and you have read exactly what we propose to publish. The default is that nothing appears: no logo, no anonymised study, no quote. When we do ask, we ask once, we ask after closure rather than while you still need something from us, and a no changes nothing about the engagement. If you agree to an anonymised study, you approve the text, including which figures appear and how the sector is described, and you can ask us to take it down later without giving a reason. Our own reporting obligations, such as a regulator or an auditor asking who we work for, are handled through the engagement contract rather than through this page. The internal rule behind all of this is written down rather than remembered, so it survives whoever happens to be asking.

Ready When You Are

Tell us what is due and who is asking. You will leave the call with a written scope, a timeline and a fixed price, and an honest answer if we are not the right firm for it.