Cybersecurity and compliance case studies

Real work with context, decisions and measurable outcomes: ISO 27001, ENS and DORA implementations, pentesting and social engineering, 24/7 managed SOC, ransomware response and security audits — delivered by the same team that operates and responds to incidents.

Case studies based on real projects delivered by Hard2bit. To preserve confidentiality, data, figures, services and contextual details have been modified or rounded, so no case corresponds exactly to an identifiable client.

Manufacturing · Compliance

ISO 27001 from scratch at a manufacturing company

From no ISMS at all to certification in ten months, triggered by an enterprise customer's supply-chain requirement — with no major non-conformities at audit.

ISO 27001ISMSManufacturing
Read the case

SaaS · AI · Public sector

ENS medium level at an AI SaaS company

ENS certification in six months to bid for public-sector contracts, with a cloud-native platform and AI functionality inside the scope.

ENSCloudAI
Read the case

Automotive · Offensive security

Web and API pentesting at an automotive group

Three applications, fourteen vulnerabilities and two critical findings exposing customer data. Closure verified through retesting.

PentestingWeb/APIOWASP
Read the case

Energy · Assessment

Internal and external security audit at an energy company

A complete picture of external and internal exposure: attack surface, Active Directory, segmentation and a risk-prioritised remediation plan.

Security auditInfrastructureEnergy
Read the case

Financial services · Compliance · DORA

DORA compliance programme at a financial institution

Gap analysis, ICT risk framework and the Register of Information delivered on time: 34 providers classified, 6 critical ones with renegotiated clauses and 0 supervisor observations.

DORAThird partiesFinancial
Read the case

Legal · Incident response

Ransomware response at a law firm

Containment, forensics and recovery without paying the ransom. Exfiltration analysis limited the impact to 3 matters and protected legal professional privilege. No client walked away.

RansomwareForensicsLegal
Read the case

Healthcare · Managed defence

24/7 managed SOC at a private healthcare group

From overnight blindness to a median detection time of 11 minutes: EDR across 1,100 endpoints, legacy medical kit isolated, monthly exposed-credential monitoring and 3 out-of-hours incidents contained.

SOC / MDRNIS2Healthcare
Read the case

Retail · Human risk

Social engineering and human risk at a retail chain

Phishing, vishing and authorised physical intrusion as the baseline, then a role-based programme that lifted reporting from 4% to 38% — and stopped a real CEO fraud attempt.

Social engineeringAwarenessRetail
Read the case

International group · Managed services

Managed infrastructure and security at an international company

Nearly a decade with a dedicated on-site team and, for the last three years, vulnerability management with remediation reporting to the European parent: every KPI met.

Managed servicesVulnerabilitiesGroup KPIs
Read the case

Financial services · Vulnerability management

Vulnerability management at a financial services company

Three years of continuous programme: risk-based prioritisation, coordinated remediation and monthly committees. Criticals open beyond 30 days brought close to zero.

VulnerabilitiesSLAsFinancial
Read the case

Real estate · Vulnerability management

Vulnerability management at a digital real-estate platform

High-traffic portals and APIs with weekly releases: continuous web-asset inventory and the exposure window for criticals cut from weeks to days.

VulnerabilitiesWeb/APIReal estate
Read the case

Services · 24/7 multi-tenant SOC

24/7 multi-tenant SOC for a large services group

Over 200 of the group's client websites monitored 24/7 from our SOC, with industrialised onboarding, detection in minutes, plus support with migrations and infrastructure.

SOC / MDRMulti-tenantServices
Read the case

Industry · Critical infrastructure

Infrastructure and SQL performance at an industrial multinational

Years of collaboration in a high-confidentiality environment: critical processes down from hours to minutes, every change audited and zero security incidents.

InfrastructureSQLHigh confidentiality
Read the case

Technology · Offensive security

Pentesting a data platform serving institutional clients

A multi-tenant data platform whose clients demand guarantees: 11 vulnerabilities, 2 high-severity tenant-isolation findings fixed and verified by retest.

PentestingAPIsMulti-tenant
Read the case

Frequently asked questions about our cases

Are Hard2bit's case studies real projects?

Yes — every case draws on real projects delivered by the Hard2bit team. To preserve confidentiality, data, figures, services and contextual details have been modified or rounded, so no case corresponds exactly to an identifiable client; the problem, the approach and the kind of outcome reflect real work.

Why are they published in anonymised form?

For two reasons: the confidentiality we sign with every client, and consistency with what we sell — a cybersecurity firm that exposes its clients on its website does not understand its own trade. In sectors such as legal or financial services, discretion is part of the service.

Can I speak to reference clients before engaging?

In advanced procurement processes, yes — with the client's express permission we can arrange verifiable references from the same sector or regulatory framework under a non-disclosure agreement.

What kinds of project do these cases cover?

Compliance (ISO 27001, ENS, DORA), offensive security (web and API pentesting, social engineering), managed defence (24/7 SOC/MDR), incident and ransomware response, and full security audits. We work with organisations of any sector and size.

How would a project like this start at my organisation?

The same way these cases did: an initial no-obligation conversation to understand your context, a scoped assessment, and a proposal with concrete phases, timelines and deliverables. Tell us your situation via the contact page.

Does your situation look like one of these?

Tell us your context and we'll give you an honest view of what we would do: scope, phases and the evidence you'd hold at the end.