Case Studies

Real engagements. Measurable outcomes.

Every case study below represents a real client challenge, a real engagement, and a real outcome. Client names and identifying details are anonymised at their request — the findings and results are not.

Holistic Security client engagements
Cyber Essentials
Cyber EssentialsCyber Essentials Basic & Plus

Cyber Essentials Basic and Plus certification delivered for a professional services firm with a fragmented device estate

The challenge

A mid-size professional services firm with 320 staff across four UK offices had never undergone formal cyber certification. Their device estate had grown organically — a mix of managed laptops, BYOD mobile devices, and legacy on-premise servers — with no consistent patch management or boundary firewall policy in place. A major public sector client required Cyber Essentials Plus certification as a contractual prerequisite.

Our approach

We conducted a scoping exercise to define the certification boundary, followed by a readiness assessment against all five Cyber Essentials technical controls. We identified and remediated gaps across patch management, access control, and malware protection before submitting for Basic certification. We then conducted the Plus verification — including authenticated vulnerability scanning and hands-on technical testing of sampled devices — to achieve the higher tier.

Key findings & outcomes

  • Cyber Essentials Basic certification achieved within 3 weeks of engagement start
  • Cyber Essentials Plus verified on first submission — no re-test required
  • 47 out-of-support software instances identified and remediated prior to assessment
  • Public sector contract secured — estimated £1.8M annual revenue unlocked

3weeks

Basic to certified

47

Vulnerabilities remediated

1st

Attempt Plus pass

We'd been told CE Plus would take months and be disruptive. It wasn't. They scoped it tightly, fixed what needed fixing, and we passed first time.

— IT Director, Professional Services Firm
Healthcare
HealthcareInfrastructure Penetration Testing + GRC

Critical patient data exposure discovered across an NHS-affiliated hospital trust's legacy estate

The challenge

A large NHS-affiliated hospital trust was preparing for a CQC inspection and needed independent validation of their network security posture. Their estate included significant legacy infrastructure running unsupported operating systems.

Our approach

We conducted an authenticated internal infrastructure penetration test across 14 network segments, followed by a gap assessment against NHS DSPT requirements. The legacy estate presented significant challenges — several systems could not be patched without clinical risk.

Key findings & outcomes

  • Critical unauthenticated RCE vulnerability on a PACS imaging server serving 3 hospitals
  • Patient record database accessible from the guest WiFi network via misconfigured VLAN
  • Compensating controls designed for 6 systems that could not be patched
  • Full DSPT compliance achieved within 90 days of engagement completion

3

Hospitals protected

90days

To DSPT compliance

6

Legacy systems mitigated

Finding the PACS vulnerability before an attacker did was the outcome that mattered. The compliance work was important — but that finding was critical.

— Head of IT Security, NHS Trust
SaaS & Technology
SaaS & TechnologyWeb Application Penetration Testing + DevSecOps

IDOR vulnerability chain exposing all customer data in a Series B fintech platform

The challenge

A Series B fintech startup was preparing for SOC 2 Type II certification and needed a thorough web application security assessment of their core platform — a multi-tenant financial data aggregation service handling data for 180,000 end users.

Our approach

We conducted a black-box web application penetration test followed by a grey-box API security assessment. We also reviewed their CI/CD pipeline configuration and implemented automated security tooling as part of a DevSecOps integration sprint.

Key findings & outcomes

  • IDOR chain allowing any authenticated user to access all other users' financial data
  • Broken object-level authorisation across 7 API endpoints
  • SAST, DAST, and SCA tooling integrated into CI/CD pipeline within 2 weeks
  • SOC 2 Type II certification achieved 4 months after engagement

180k

Users protected

7

API auth flaws fixed

4months

To SOC 2 Type II

The IDOR finding would have been catastrophic if a researcher or attacker had found it first. The DevSecOps work means we'll catch the next one ourselves.

— CTO, Series B Fintech
Critical Infrastructure
Critical InfrastructureSAP Security Assessment + Penetration Testing

Full organisational compromise achieved via SAP misconfigurations at a major Middle East energy supplier

The challenge

A large state-affiliated energy supplier operating across the Gulf region engaged us following an internal audit that flagged concerns about their SAP landscape. The organisation ran a complex multi-system SAP environment — ECC, Solution Manager, and PI/PO — underpinning procurement, finance, HR, and operational reporting for over 8,000 employees. No dedicated SAP security assessment had ever been conducted.

Our approach

We conducted a targeted SAP penetration test across the production landscape, beginning with unauthenticated reconnaissance of exposed SAP services. We identified and chained a series of misconfigurations — including an unprotected SAP Message Server, default RFC gateway settings, and overprivileged dialog users — to achieve full administrative access. We then demonstrated lateral movement from SAP into connected business systems without requiring any social engineering or phishing.

Key findings & outcomes

  • Unauthenticated access to SAP Message Server enabled internal service registration and traffic interception
  • RFC gateway misconfiguration exploited to execute OS-level commands on the SAP application server
  • Full SAP_ALL privileges obtained via chained privilege escalation — complete control of ECC production system
  • Lateral movement demonstrated into connected HR, finance, and operational reporting systems without credentials

3

Systems fully compromised

0

Credentials required

8k+

Employee records at risk

We assumed SAP was protected by the network perimeter. The assessment proved that assumption was completely wrong — and showed us exactly how an attacker would have moved through the entire organisation.

— Group CISO, Gulf Region Energy Supplier
Critical Infrastructure
Critical InfrastructureBreakout Testing — Kiosk & Citrix

Multiple breakout vulnerabilities discovered across hardened public-facing terminals at a European police department

The challenge

A national police department across a major European jurisdiction had deployed a fleet of hardened public-access terminals and internal Citrix-based workstations intended to provide strictly controlled access to case management and evidence systems. The terminals were considered secure by design — locked-down OS builds, restricted peripherals, and application whitelisting. The department commissioned a breakout assessment to independently validate those assumptions before a wider rollout.

Our approach

We conducted a structured breakout test across both the public kiosk estate and the internal Citrix environment, simulating a malicious user with only the access afforded to a member of the public or a low-privileged internal operator. We systematically probed application layer controls, OS-level restrictions, and the Citrix published desktop configuration for escape paths — without using any exploit code or elevated credentials.

Key findings & outcomes

  • Kiosk browser escape achieved via malformed file dialogue — full desktop access obtained within 8 minutes
  • Citrix session breakout via exposed PowerShell through a trusted application's help viewer
  • Lateral movement from the Citrix environment into protected case management network segments — no additional credentials required
  • 11 distinct breakout vectors identified across kiosk and Citrix environments — all remediated prior to wider deployment

8mins

Time to kiosk escape

11

Breakout vectors found

0

Credentials needed

We believed the terminals were hardened. Within minutes the testers were on the desktop. The findings were sobering — and exactly what we needed to see before rollout.

— Head of IT Security, European Police Department
Financial Services
Financial ServicesvCISO + ISO 27001

ISO 27001 certification and security programme built from scratch for a regulated payments firm

The challenge

A fast-growing FCA-regulated payments firm needed to achieve ISO 27001 certification within 12 months as a contractual requirement from a major banking partner. They had no dedicated security function and no existing ISMS.

Our approach

We provided a fractional vCISO to lead the programme, combining ISMS design, risk assessment, policy development, and staff awareness with hands-on technical controls implementation. We managed the certification audit directly.

Key findings & outcomes

  • Full ISMS designed and implemented from zero baseline
  • ISO 27001 certification achieved in 11 months — one month ahead of contractual deadline
  • Security function established with internal ISMS owner trained and operational
  • Banking partner contract secured — estimated £2.4M annual revenue protected

11months

Zero to certified

£2.4M

Revenue protected

1st

Attempt certification

We needed ISO 27001 or we'd lose the contract. They delivered it in 11 months from a standing start. The banking partner was satisfied on first review.

— CEO, FCA-regulated Payments Firm

Your sector. Your threat profile. Your engagement.

Every organisation faces a different risk landscape. We scope every engagement to your specific environment — not a generic template.