Out in the world.
Every study is a real engagement, anonymised. Client names stay confidential by design — the work doesn't need them.
From data-risk findings to action in twelve weeks.
A global agribusiness company
The company knew its data risks in outline but not in the specifics that let anyone act: sensitive information — personal, financial, intellectual property, and regulated data — spread across a large estate, exposure and oversharing unquantified, and retention practices leaving redundant data accumulating risk. Four priorities were clear — classify the sensitive, identify the exposure, realign the access, retire the redundant — and the brief was equally clear: findings that turn into action, not another assessment that ends as a report.
From the server room to a private cloud.
A national healthcare distribution company
The company's infrastructure had grown up on premises — servers owned, housed, and maintained by the business, with the refresh cycles, capacity ceilings, and single-site risk that model carries. In a business whose operations the healthcare supply chain depends on, the question was not whether to move, but how to move without interrupting the work: a platform decision that had to serve reliability first and modernisation second.
Data governance that leadership could finally see.
A major Australian superannuation and investment company
One of Australia's largest pension payers faced a widening gap between its data governance and its obligations: a growing set of Australian and US regulatory demands, contractual data and intellectual property that needed stronger protection, and a leadership team yet to be convinced that centralised data governance was worth funding. Governance existed on paper; what was missing was a program the business could see working.
A cyber strategy the whole business could execute.
An ASX-listed resources company
A globally operating, ASX-listed resources company needed structure and insight in its cyber risk management: stakeholders across the business held different views of the priorities, the roadmap ahead was unclear, and internal capability needed lifting from within rather than replacing from outside. The goal was not a report — it was a cyber program the organisation could align on and execute with confidence.
Guardrails that let AI move fast, safely.
A leading online marketplace company
Generative AI initiatives were scaling quickly across the organisation — every department wanted in — but the guardrails had not kept pace: no clear guidance on approved tools and systems, limited internal AI-security depth, and no structured way to see or manage the risks the new systems introduced. The business needed to keep moving at the speed the market expected, with a level of safety and visibility it did not yet have.
One identity program across many brands.
A diversified ASX-listed services company
Operating multiple consumer brands across distinct service industries, the company's identity estate had grown brand by brand: password management, privileged access, and identity governance each handled differently in different places, with no single view of the gaps and no agreed path to close them. Thousands of end users and privileged users needed managing as one program rather than many.
Talk to a partner about comparable work.
Whether you are framing a board-level technology decision, scoping a platform build, or recovering a transformation that has stalled — we lead with senior judgement, not a sales pitch. The first conversation is always free.
Contact us