Customer Case Study · Data Protection
An enterprise-wide data protection
assessment — clear enough to act on alone
How Small Robot assessed the data protection posture of a leading Australian telecommunications provider across its entire enterprise, in a report clear enough for the client's own team to implement without further support.
Client name and logo withheld at the customer's request(name withheld)
The starting point
A national telecommunications provider, holding customer data at a scale few sectors match, wanting a clear-eyed view of its data protection posture.
The client is one of Australia's leading telecommunications providers — a business that holds customer, billing and network data across millions of accounts, under privacy and telecommunications-sector obligations that make data protection a standing regulatory concern, not a one-off project.
Rather than assume existing controls and policy were keeping pace with the business, the client engaged Small Robot to assess its data protection posture across the entire enterprise — not a single business unit or system, the whole organisation.
The challenge
An enterprise-wide view is hard to get — and hard to act on once you have it.
Scale and fragmentation
A telecommunications enterprise of this size spans many systems, business units and data flows. An assessment scoped to "the whole enterprise" has to actually cover that ground, not sample a convenient slice of it.
Findings senior leadership would actually act on
An assessment is only useful if its findings are credible enough, and clear enough, for senior leadership to back — and specific enough for the client's own team to execute without needing the assessor back in the room.
What Small Robot did
Four weeks, enterprise-wide, three lenses on the same question.
- Document and policy analysis. Reviewed data protection policies, standards and governance documentation against what the business's own obligations actually require.
- Technical controls and configuration analysis. Assessed how data protection controls were actually configured and operating in practice, across the enterprise rather than a single system or team.
- Senior and technical stakeholder interviews. Spoke with both executive stakeholders and technical staff, to understand where documented policy, technical reality and everyday practice agreed — and where they didn't.
The output was a single report of key findings and prioritised recommendations, covering the client's entire enterprise rather than a subset of it.
Delivered in one engagement
A single, defined assessment — not the start of an ongoing remediation programme.
Phase boundaries are illustrative of a typical four-week enterprise assessment.
The results
A report senior leadership backed — and the client's own team could run with.
| Area | Before | After |
|---|---|---|
| Enterprise visibility | No consolidated, independent view of data protection posture across the whole business | Single enterprise-wide assessment covering policy, technical controls and practice |
| Leadership confidence | Assumed adequacy of existing controls, untested independently | Findings well received by senior leadership, with clear backing to act on them |
| Path to remediation | No prioritised, actionable set of recommendations | Recommendations specific enough for the client's own team to implement without further external support |
Why this engagement looks different
Unlike a follow-on remediation engagement, Small Robot's role here ended at the report. That's not a gap in the story — the recommendations were actionable enough, and clear enough, that the client's own team took them from there.
Where things stand today
The assessment is complete and the report has been actioned by the client's own team. This was a defined, single engagement rather than an ongoing programme — a clean example of an assessment doing exactly what it was meant to do: give leadership a credible view of the real state of play, and give the team enough clarity to act on it themselves.