Customer Case Study · Data Protection
Finding out where member data was
actually at risk — then fixing it
How Small Robot assessed and is uplifting the data protection and data loss prevention capability of a leading Australian superannuation provider — turning a four-week assessment into an active remediation programme.
Client name and logo withheld at the customer's request(name withheld)
The starting point
A fund holding sensitive member data at scale, wanting an honest, independent view of how well it was actually protected.
The client is one of Australia's leading superannuation providers — an organisation that holds long-term financial and personal data for a large member base, under regulatory obligations that treat data protection as a standing requirement, not a project. That combination makes data loss prevention (DLP) a genuinely high-stakes capability: the cost of getting it wrong is measured in regulatory exposure and member trust, not just remediation effort.
Rather than assume its existing controls were adequate, the fund engaged Small Robot to independently assess its data protection and DLP posture — and to help close the gaps that assessment found.
The challenge
Understand the real state of data protection before deciding what to fix.
No independent baseline
Policy documents, technical controls and day-to-day practice don't always agree with each other. Without an independent assessment, the fund had no reliable way to know where its actual DLP exposure sat — only where policy said it should sit.
Strategic and tactical gaps, tangled together
Some issues were quick configuration fixes. Others were structural — the kind of gap that needs a programme of work, not a setting change. Both had to be identified and correctly separated before remediation could be prioritised sensibly.
What Small Robot did — the assessment
Four weeks, three lenses: what's written down, what's configured, and what people actually do.
- Document and policy analysis. Reviewed the fund's data protection and DLP policies, standards and governance documentation against what good practice — and the fund's own regulatory obligations — actually require.
- Technical controls and configuration analysis. Assessed how DLP and related data protection controls were actually configured and operating, not just how they were meant to work on paper.
- Senior and technical stakeholder interviews. Spoke with both executive stakeholders — for direction, ownership and risk appetite — and technical staff — for how controls really get used day to day. The two views rarely match perfectly, and the gap between them is often where the real risk lives.
The output was a report of key findings and recommendations, structured so the fund could clearly separate quick wins — tactical fixes deliverable in weeks — from strategic recommendations — structural changes that would take longer and need sustained investment.
What Small Robot did — the remediation
An engagement that is still running, by design.
The findings report was the start of the work, not the end of it. Remediation has been underway for more than eight weeks and continues today, split deliberately into two tracks:
Timeline reflects the described phases — a four-week assessment followed by an ongoing, two-track on-going remediation programme.
The results so far
| Area | Before | After |
|---|---|---|
| Independent baseline | No independent view of DLP posture — reliant on internal assumptions | Comprehensive baseline established via document, technical and stakeholder-based assessment |
| DLP detection & response | Gaps in detection and response identified during the assessment | Materially improved following quick-win implementation Complete |
| Direction & expectations | Inconsistent understanding of data-handling expectations across the business | Clearer direction and expectations now set, enterprise-wide Complete |
| Strategic controls | Structural gaps identified in the assessment report | Remediation underway In progress |
Being clear about what's finished
The tactical work is done and already showing results. The strategic work is not — it is still being delivered and will be ongoing for some time, which is expected for an organisation of this size and structure.
In their words
“We are impressed with the outcomes produced by the team and our internal team are looking for more opportunities for us to work together.”
Where things stand today
Quick wins and tactical recommendations are implemented and already delivering better DLP detection and response. Strategic remediation continues, more than eight weeks in, with Small Robot still engaged alongside the fund's own team to see it through. This is an active engagement, not a closed case study.