Business Connected — IT & CommunicationsBook an assessment
Home  /  Success stories
Client success stories

Real jobs, with the client details removed.

We do not publish customer names or logos without written permission, and most of our clients would rather we didn’t — particularly the ones where the story starts with a security gap. So these are de-identified: the work is exactly as it happened, the client is not identifiable.

Food & fresh produce~120 staffVictoriaSMB1001 Gold

A supermarket questionnaire with a deadline attached

The situation

A grower and packer supplying major retailers received a supplier security questionnaire with their contract renewal. It asked about multi-factor authentication coverage, endpoint detection, email authentication and incident response. They could not answer four of the eleven questions, and the renewal date was eight weeks out.

What we found

Multi-factor authentication was enabled but not enforced — roughly a third of accounts had never enrolled. Email had SPF but no DKIM and a DMARC record set to none, so nothing was actually being rejected. Backups ran nightly and had never been restore-tested. There was no written incident response plan.

What we did

Gap-assessed against SMB1001 Gold and worked the findings register in risk order: conditional access to enforce MFA on every account, DKIM signing published and DMARC moved to reject over three weeks of monitoring, managed endpoint detection deployed across every device including the packing shed terminals, and a restore test run against the ERP database in front of their operations manager.

Where it landed

Certified to Gold inside the renewal window, with an evidence pack that answered the questionnaire directly. The same pack has since been reused for two further customer reviews and their insurance renewal.

Commercial fit-out~40 staffProvider transitionMicrosoft 365

Inheriting a tenant that nobody owned

The situation

A commercial interiors contractor decided to change providers after a period of slow response and no visibility. The outgoing provider held the only global administrator account for the Microsoft 365 tenant, and there was no documentation of the environment at all.

What we found

Twelve more licences assigned than there were people. Four ex-staff mailboxes still active, one with a forwarding rule to an external address. No device management, no conditional access, and project site connectivity being handled with consumer routers and a mobile hotspot in a site hut.

What we did

Ran the tenant handover formally — established our own delegated access, secured a break-glass account held by the client, and removed the previous provider’s standing privileges. Audited licensing and reclaimed the surplus at the anniversary date. Disabled the forwarding rule and reviewed the mailbox it pointed at. Enrolled every device in Intune with compliance policies, then enforced conditional access. Standardised site connectivity on business-grade hardware with 4G failover.

Where it landed

Complete environment documentation handed to the client, licence spend reduced at the first renewal, and a named engineer who now knows every site. The client holds their own tenant keys — if they ever leave us, the handover takes a day.

Allied health4 sitesIntune & conditional accessEssential Eight

Four clinics, four ways of doing everything

The situation

An allied health group that had grown by acquisition ended up with four practices running four different setups: three email domains, two file server arrangements, shared logins at reception, and clinicians who could not work at a site other than their own.

What we found

Shared reception accounts meant no attribution — there was no way to tell who had accessed a patient record. Devices were unmanaged and unencrypted. Backups existed at two of the four sites. Nobody could say with confidence what a departing staff member still had access to.

What we did

Consolidated to a single Microsoft 365 tenant and one identity per person, with the legacy domains kept for mail flow so no referral bounced. Replaced shared reception logins with individual accounts and role-based permissions. Enrolled every clinical device in Intune with enforced encryption, short screen-lock and remote wipe. Applied conditional access so a clinician can work from any site on a compliant device and nowhere else. Standardised backup across all four practices and tested the restore.

Where it landed

One identity, one device standard, and an access review that can be produced on request. Cutover was staged clinic by clinic outside consulting hours — no session of patient bookings was lost.

What they have in common

Nothing here was exotic.

Every one of these engagements came down to the same three things: find out what is actually configured, fix it in risk order, and write it down so it can be proved. There is no clever product in any of these stories.

The gap was never where they thought

In all three cases the client’s stated problem was a symptom. The questionnaire, the slow provider, the four different setups — each one was downstream of something nobody owned.

Evidence mattered as much as controls

Two of the three needed to prove security to someone else. Having the control and being able to demonstrate it are separate pieces of work, and only one of them is technical.

Nobody lost a working day

Cutovers were staged around harvest, around consulting hours, around site programmes. That scheduling is most of the skill.

Your situation is probably one of these three.

A questionnaire you cannot answer, a provider who has gone quiet, or growth that left you with four ways of doing everything. Start with an assessment.

No obligation. We will tell you if you do not need us.