Customer Case Study · Cybersecurity Assessment
Securing a business that was growing
faster than its own risk profile
How Small Robot assessed the cybersecurity posture of a fast-growing, engineering-led technology company — across on-premise infrastructure, cloud services and SaaS, for a workforce of more than 500 developers and data scientists — with findings delivered as capability heat maps the board could act on directly.
Client name, logo and identifying sector detail withheld at the customer's request(name withheld)
The starting point
A business growing fast enough that its security posture risked being left behind.
The client is a fast-growing Australian technology company, built around a large engineering and data science function — more than 500 developers, alongside a range of data scientists, working across a genuinely complex technical estate. Rapid growth is a good problem to have, but it puts pressure on exactly the things security depends on: consistent controls, clear ownership, and visibility that keeps pace with how fast the environment itself is changing.
At the centre of that environment sat a very large volume of customer-related data — multiple petabytes of it — held across a genuinely hybrid estate: on-premise servers and services, cloud-based services, and a range of SaaS platforms. The board wanted assurance that security had kept pace with growth, not fallen behind it.
The challenge
Assess a genuinely complex, hybrid environment — without missing where the real risk actually sits.
Scale and complexity
On-premise infrastructure, cloud services and SaaS, all operating side by side, supporting a 500-plus person engineering organisation and its data science practice. That combination produces a genuinely large and varied attack surface.
Protecting data at serious scale
Multiple petabytes of customer-related data is not a workload you can secure with a generic checklist. Growth had outpaced the last honest, independent look at how well that data — and the environment around it — was actually protected.
What Small Robot did
The same proven method as Small Robot's data protection assessments — taken a lot wider, and a lot deeper.
Small Robot ran this assessment using the same core methodology as its data protection assessments elsewhere — document and policy analysis, technical controls and configuration analysis, and interviews with both senior and technical stakeholders. The difference here was breadth and depth: over eight weeks — double the standard four-week baseline — the assessment covered the full hybrid estate and the scale of engineering activity running on top of it.
- On-premise infrastructure and services — assessed alongside, not instead of, the cloud and SaaS estate.
- Cloud-based services — configuration and controls reviewed against actual usage, not just documented intent.
- SaaS estate — brought into the same assessment rather than treated as out of scope, as it often is.
- Developer and data science environments — assessed in their own right, given the scale of engineering and data science activity across the business.
- Capability heat maps. Findings were delivered as heat maps across three capability areas — visibility, detection and response — so the board and leadership could see at a glance where capability was strong and where it wasn't, across every part of the environment.
The same baseline methodology used elsewhere, extended to cover the client's full hybrid environment and engineering scale.
Findings the board could act on
A capability heat map, not a wall of findings.
Rather than a conventional findings list, the report presented capability maturity as a heat map across visibility, detection and response — read across every part of the environment assessed. That format is what made the report land with the board: it showed exactly where the gaps sat, without requiring a technical background to see it.
Structural template only. The maturity levels shown are placeholders to illustrate the format — they are not this client's actual findings.
The results
Board-level backing, and remediation that didn't wait for a handover.
| Area | Before | After |
|---|---|---|
| Environment-wide visibility | Visibility fragmented across on-premise, cloud and SaaS, with no consolidated view | Consolidated capability heat map across the full hybrid environment |
| Detection & response maturity | Maturity varied by environment, with no board-level visibility of where | Mapped and communicated clearly enough for the board to prioritise investment |
| Remediation | Findings would have needed a separate delivery engagement to act on | Recommendations implemented directly, jointly with the in-house team Joint delivery |
| Assurance over customer data | No recent, independent assessment matched to the scale of data actually held | Multi-petabyte customer data estate assessed as part of the full environment review |
Where things stand today
The recommendations from the assessment have been implemented, with Small Robot and the client's in-house team working through them together rather than the client being left to execute alone. For a business growing this quickly, the combination of an independent, board-credible view of risk, delivered clearly, followed by the hands-on remediation is what closed the gap between growth and security maturity.