Whitesec ID
Case Studies

How our engagements run in practice

From the initial challenge and the steps taken, through to results that can be evidenced.

Client identities are anonymised under confidentiality agreements. Specific references are shared at proposal stage.

Engagement Portfolio

Six patterns of work we handle most often

The structure is the same throughout — challenge, approach, outcome — so it is easy to compare against your own situation.

  • Securities & Capital Markets

    ISO 27001 certification as a condition of institutional due diligence

    Duration:
    6 months

    Challenge

    An institutional partner demanded evidence of a working information security management system, while internal policies were scattered and had never been audited.

    What we did

    • Gap analysis across every ISO/IEC 27001 clause and Annex A control
    • ISMS scope, risk register, and Statement of Applicability
    • Implementation support alongside the internal IT and compliance teams
    • Internal audit and management review ahead of the certification audit

    Outcome

    • ISMS documentation centralised and consistent across business units
    • Passed Stage 1 and Stage 2 audits with an independent certification body
    • Security evidence requests answered from a single prepared pack
  • Fintech Lending

    OJK licensing readiness and AFPI requirement fulfilment

    Duration:
    4 months

    Challenge

    A peer-to-peer lending provider needed to complete its IT governance documentation and security control evidence for the licensing process.

    What we did

    • Mapping regulator requirements against the controls already running
    • Building the IT risk management framework, BCP, and DRP
    • Application security testing reported in the regulator's format
    • Rehearsed question-and-answer sessions ahead of the supervisory assessment

    Outcome

    • A complete and internally consistent licensing document pack
    • Security testing findings closed before submission
    • Internal team ready to answer the regulator's technical questions
  • Data Centre & Infrastructure

    Recurring security testing to meet customer SLA commitments

    Duration:
    6-monthly cycle

    Challenge

    An infrastructure provider was contractually required to hand independent security testing results to enterprise customers each contract period.

    What we did

    • Testing web applications, APIs, and network infrastructure against OWASP
    • Manual verification of every finding to remove false positives
    • CVSS v3.1 risk ratings with controlled exploitation evidence
    • Retesting after remediation as proof that findings were closed

    Outcome

    • Technical report and executive summary ready to share with customers
    • Clear remediation priorities for the engineering team
    • Contractual periodic testing commitments met
  • Energy & Resources

    24/7 security monitoring for operational infrastructure

    Duration:
    Ongoing service

    Challenge

    Logs were available from a range of devices, but nobody was watching them, so anomalies only surfaced once operations were already affected.

    What we did

    • Integrating log sources into the SIEM and baselining the environment
    • Writing detection rules and tuning them to suppress false alerts
    • Agreed incident response playbooks and escalation paths
    • Tabletop exercises with the IT team and management

    Outcome

    • Complete security visibility in a single dashboard
    • Detection and response times measured against an SLA
    • Monthly reporting that both engineers and management can read
  • Public Sector & Institutions

    Records reorganisation and a retention schedule aligned to ANRI guidance

    Duration:
    5 months

    Challenge

    Physical and digital records kept accumulating without classification, so document requests during audits could not be met on time.

    What we did

    • Inventory of record types, volume, and condition in every unit
    • Classification scheme and retention schedule design
    • Digitisation of priority records with media conversion quality control
    • Custodian training and lawful disposal procedures

    Outcome

    • Records retrievable through classification and metadata
    • Orderly retention and disposal with formal minutes
    • Ready for document requests whenever an audit arrives
  • E-Commerce & SaaS

    Personal data protection compliance from data mapping to the DPO function

    Duration:
    5 months

    Challenge

    The platform processed personal data at scale with no data flow map, no documented lawful basis, and no data subject rights procedure.

    What we did

    • Data mapping and records of processing activities
    • Gap assessment against the obligations of Law No. 27 of 2022
    • Privacy policies, consent mechanisms, and data subject rights procedures
    • Support in establishing the Data Protection Officer function

    Outcome

    • Personal data flows documented alongside their lawful basis
    • Data subject requests handled through a defined procedure
    • Ready for privacy questions from partners and the authority
Sector Coverage

Experience across regulated industries

Regulatory obligations and risk tolerance differ by sector. Our approach adapts rather than copying a template.

Discuss your case
  • Banking & Digital Finance
  • Fintech & Securities
  • Telecommunications
  • E-Commerce
  • SaaS & Cloud Services
  • Government Institutions

The organisations we have supported are listed on the Why Whitesec ID.

Ready to build stronger security?

Talk your organisation's needs through with our team. Free, and without obligation.