Securing a business that was growing faster than its own risk profile


Securing a business that was growing faster than its own risk profile
Case Study — Enterprise Cybersecurity Assessment | Small Robot

Customer Case Study · Cybersecurity Assessment

Securing a business that was growing
faster than its own risk profile

How Small Robot assessed the cybersecurity posture of a fast-growing, engineering-led technology company — across on-premise infrastructure, cloud services and SaaS, for a workforce of more than 500 developers and data scientists — with findings delivered as capability heat maps the board could act on directly.

Client name, logo and identifying sector detail withheld at the customer's request
Client
Fast-growing Australian technology company
(name withheld)
Scale
500+ developers & a data science practice
Duration
Eight weeks — wider & deeper than the standard baseline
Environment
On-premise, cloud & SaaS
Data at stake
Multiple petabytes of customer-related data
Reception
Well received by the board & senior leadership

The starting point

A business growing fast enough that its security posture risked being left behind.

The client is a fast-growing Australian technology company, built around a large engineering and data science function — more than 500 developers, alongside a range of data scientists, working across a genuinely complex technical estate. Rapid growth is a good problem to have, but it puts pressure on exactly the things security depends on: consistent controls, clear ownership, and visibility that keeps pace with how fast the environment itself is changing.

At the centre of that environment sat a very large volume of customer-related data — multiple petabytes of it — held across a genuinely hybrid estate: on-premise servers and services, cloud-based services, and a range of SaaS platforms. The board wanted assurance that security had kept pace with growth, not fallen behind it.

The challenge

Assess a genuinely complex, hybrid environment — without missing where the real risk actually sits.

Scale and complexity

On-premise infrastructure, cloud services and SaaS, all operating side by side, supporting a 500-plus person engineering organisation and its data science practice. That combination produces a genuinely large and varied attack surface.

Protecting data at serious scale

Multiple petabytes of customer-related data is not a workload you can secure with a generic checklist. Growth had outpaced the last honest, independent look at how well that data — and the environment around it — was actually protected.

What Small Robot did

The same proven method as Small Robot's data protection assessments — taken a lot wider, and a lot deeper.

Small Robot ran this assessment using the same core methodology as its data protection assessments elsewhere — document and policy analysis, technical controls and configuration analysis, and interviews with both senior and technical stakeholders. The difference here was breadth and depth: over eight weeks — double the standard four-week baseline — the assessment covered the full hybrid estate and the scale of engineering activity running on top of it.

  • On-premise infrastructure and services — assessed alongside, not instead of, the cloud and SaaS estate.
  • Cloud-based services — configuration and controls reviewed against actual usage, not just documented intent.
  • SaaS estate — brought into the same assessment rather than treated as out of scope, as it often is.
  • Developer and data science environments — assessed in their own right, given the scale of engineering and data science activity across the business.
  • Capability heat maps. Findings were delivered as heat maps across three capability areas — visibility, detection and response — so the board and leadership could see at a glance where capability was strong and where it wasn't, across every part of the environment.
BASELINE METHOD Document & policy · technical controls · stakeholder interviews ON-PREMISE INFRASTRUCTURE CLOUD SERVICES SaaS ESTATE DATA SCIENCE ENVIRONMENTS DEVELOPER ENVIRONMENTS 500+ ENGINEERS AT SCALE

The same baseline methodology used elsewhere, extended to cover the client's full hybrid environment and engineering scale.

Findings the board could act on

A capability heat map, not a wall of findings.

Rather than a conventional findings list, the report presented capability maturity as a heat map across visibility, detection and response — read across every part of the environment assessed. That format is what made the report land with the board: it showed exactly where the gaps sat, without requiring a technical background to see it.

ON-PREMISE CLOUD SaaS DEVELOPER ENVS DATA / ML ENVS VISIBILITY DETECTION RESPONSE Filled = illustrative maturity level (placeholder — not real findings) Unfilled = headroom to improve

Structural template only. The maturity levels shown are placeholders to illustrate the format — they are not this client's actual findings.

The results

Board-level backing, and remediation that didn't wait for a handover.

Board-levelthe report was well received by the board and senior leadership
8 weeksdouble the standard four-week baseline, to match the scope
Multi-PBcustomer-related data assessed as part of a genuinely hybrid, complex estate
Joint deliveryrecommendations implemented by Small Robot and the in-house team together
AreaBeforeAfter
Environment-wide visibility Visibility fragmented across on-premise, cloud and SaaS, with no consolidated view Consolidated capability heat map across the full hybrid environment
Detection & response maturity Maturity varied by environment, with no board-level visibility of where Mapped and communicated clearly enough for the board to prioritise investment
Remediation Findings would have needed a separate delivery engagement to act on Recommendations implemented directly, jointly with the in-house team Joint delivery
Assurance over customer data No recent, independent assessment matched to the scale of data actually held Multi-petabyte customer data estate assessed as part of the full environment review

Where things stand today

The recommendations from the assessment have been implemented, with Small Robot and the client's in-house team working through them together rather than the client being left to execute alone. For a business growing this quickly, the combination of an independent, board-credible view of risk, delivered clearly, followed by the hands-on remediation is what closed the gap between growth and security maturity.