The challenge
A UK public sector organisation delivering essential services to citizens needed to strengthen its security posture. Its network had grown over many years around a traditional perimeter model, while staff increasingly worked remotely and relied on a growing number of cloud applications.
The organisation faced rising expectations from auditors and assurance bodies, alongside an evolving threat landscape. In particular:
- Broad network access meant a single compromised account could reach sensitive systems
- Privileged access was difficult to track and review
- Security tooling was fragmented, making it slow to detect and investigate incidents
- Evidence for compliance reviews was gathered manually and took significant effort
Our approach
We began with an independent assessment against recognised frameworks, including the NCSC’s Zero Trust architecture principles and the NIST Cybersecurity Framework. This established a clear baseline and a prioritised roadmap that the leadership team could fund and govern with confidence.
Rather than attempting a disruptive overhaul, we delivered Zero Trust in manageable phases:
- Identity first: consolidating identities, enforcing multi-factor authentication and introducing risk-based conditional access for every critical service
- Least-privilege access: replacing standing administrator rights with just-in-time, approved and time-limited privileged access
- Device health: ensuring only managed, compliant devices could reach sensitive data
- Segmentation: limiting lateral movement by separating critical systems and applying policy at the application level
- Unified monitoring: bringing security signals into a single platform with clear playbooks for investigation and response
We worked closely with service owners and staff at each stage, so that changes were understood, well communicated and caused minimal disruption to frontline services.
The outcome
The organisation now operates with a modern, identity-centric security model that is better suited to hybrid working and cloud services.
- Every critical service is protected by conditional access and multi-factor authentication
- Standing privileged accounts were reduced by around 70%
- Threats are detected and contained roughly twice as quickly
- Compliance evidence is largely automated, reducing the burden of audits and assurance reviews
The organisation has a clear roadmap for continued improvement and the internal capability to sustain it.


