Not-for-profit

A national charity reaches Essential Eight Maturity Level 2 in six months

01The challenge

60 staff, a national footprint and funders who had started asking security questions the charity could not answer. An initial assessment put them at Maturity Level Zero on five of the eight Essential Eight controls.

They had a small budget, no security staff, and volunteers with access to donor data.

Colleagues working side by side at laptops and monitors in a bright open-plan office

02The approach

Assess honestly, then sequence by effort against risk. MFA and patching first, because they close the most exposure for the least disruption. Application control and administrative privilege restriction next, which took longer because they change how people work.

Restore testing documented from the first month, so the evidence accumulated as we went rather than being assembled before an audit. Executive reporting written for a board, not for engineers.

03The results

Maturity Level 2 across all eight controls in six months, with a maintained evidence pack that answers funder questionnaires in an afternoon.

The charity now completes security due diligence without stopping anyone’s day job.

By the numbers

The outcomes that mattered.

ML2
Across all eight controls
6 months
End to end

The service behind this

ISO 27001 & Essential Eight

Explore this service

Start here

Want results like these?

A no-obligation conversation about your infrastructure, security posture and operational risk. No lock-in, and a response within one business day.