Cybersecurity and compliance case studies
Real work with context, decisions and measurable outcomes: ISO 27001, ENS and DORA implementations, pentesting and social engineering, 24/7 managed SOC, ransomware response and security audits — delivered by the same team that operates and responds to incidents.
Case studies based on real projects delivered by Hard2bit. To preserve confidentiality, data, figures, services and contextual details have been modified or rounded, so no case corresponds exactly to an identifiable client.
Manufacturing · Compliance
ISO 27001 from scratch at a manufacturing company
From no ISMS at all to certification in ten months, triggered by an enterprise customer's supply-chain requirement — with no major non-conformities at audit.
SaaS · AI · Public sector
ENS medium level at an AI SaaS company
ENS certification in six months to bid for public-sector contracts, with a cloud-native platform and AI functionality inside the scope.
Automotive · Offensive security
Web and API pentesting at an automotive group
Three applications, fourteen vulnerabilities and two critical findings exposing customer data. Closure verified through retesting.
Energy · Assessment
Internal and external security audit at an energy company
A complete picture of external and internal exposure: attack surface, Active Directory, segmentation and a risk-prioritised remediation plan.
Financial services · Compliance · DORA
DORA compliance programme at a financial institution
Gap analysis, ICT risk framework and the Register of Information delivered on time: 34 providers classified, 6 critical ones with renegotiated clauses and 0 supervisor observations.
Legal · Incident response
Ransomware response at a law firm
Containment, forensics and recovery without paying the ransom. Exfiltration analysis limited the impact to 3 matters and protected legal professional privilege. No client walked away.
Healthcare · Managed defence
24/7 managed SOC at a private healthcare group
From overnight blindness to a median detection time of 11 minutes: EDR across 1,100 endpoints, legacy medical kit isolated, monthly exposed-credential monitoring and 3 out-of-hours incidents contained.
Retail · Human risk
Social engineering and human risk at a retail chain
Phishing, vishing and authorised physical intrusion as the baseline, then a role-based programme that lifted reporting from 4% to 38% — and stopped a real CEO fraud attempt.
International group · Managed services
Managed infrastructure and security at an international company
Nearly a decade with a dedicated on-site team and, for the last three years, vulnerability management with remediation reporting to the European parent: every KPI met.
Financial services · Vulnerability management
Vulnerability management at a financial services company
Three years of continuous programme: risk-based prioritisation, coordinated remediation and monthly committees. Criticals open beyond 30 days brought close to zero.
Real estate · Vulnerability management
Vulnerability management at a digital real-estate platform
High-traffic portals and APIs with weekly releases: continuous web-asset inventory and the exposure window for criticals cut from weeks to days.
Services · 24/7 multi-tenant SOC
24/7 multi-tenant SOC for a large services group
Over 200 of the group's client websites monitored 24/7 from our SOC, with industrialised onboarding, detection in minutes, plus support with migrations and infrastructure.
Industry · Critical infrastructure
Infrastructure and SQL performance at an industrial multinational
Years of collaboration in a high-confidentiality environment: critical processes down from hours to minutes, every change audited and zero security incidents.
Technology · Offensive security
Pentesting a data platform serving institutional clients
A multi-tenant data platform whose clients demand guarantees: 11 vulnerabilities, 2 high-severity tenant-isolation findings fixed and verified by retest.
Frequently asked questions about our cases
Are Hard2bit's case studies real projects?
Yes — every case draws on real projects delivered by the Hard2bit team. To preserve confidentiality, data, figures, services and contextual details have been modified or rounded, so no case corresponds exactly to an identifiable client; the problem, the approach and the kind of outcome reflect real work.
Why are they published in anonymised form?
For two reasons: the confidentiality we sign with every client, and consistency with what we sell — a cybersecurity firm that exposes its clients on its website does not understand its own trade. In sectors such as legal or financial services, discretion is part of the service.
Can I speak to reference clients before engaging?
In advanced procurement processes, yes — with the client's express permission we can arrange verifiable references from the same sector or regulatory framework under a non-disclosure agreement.
What kinds of project do these cases cover?
Compliance (ISO 27001, ENS, DORA), offensive security (web and API pentesting, social engineering), managed defence (24/7 SOC/MDR), incident and ransomware response, and full security audits. We work with organisations of any sector and size.
How would a project like this start at my organisation?
The same way these cases did: an initial no-obligation conversation to understand your context, a scoped assessment, and a proposal with concrete phases, timelines and deliverables. Tell us your situation via the contact page.
Does your situation look like one of these?
Tell us your context and we'll give you an honest view of what we would do: scope, phases and the evidence you'd hold at the end.