Security Cases
Security engagement records
Structured summaries of completed security reviews, hardening, and advisory engagements delivered across our markets.
These are real completed engagements. Client names and identifying details are withheld for confidentiality. Outcomes are described within the confirmed scope of each engagement.
A financial services firm preparing for a cyber insurance renewal required a structured review of their controls against the Essential Eight framework. Internal teams lacked the dedicated resource to conduct the assessment without interrupting operations.
What was in scope
Review of eight mitigation strategies as defined by the Australian Signals Directorate Essential Eight framework. Assessment covered the organisation's primary production environment and administrative access controls. Scope was defined and confirmed in writing before work commenced.
What was reviewed
- Application control configuration across primary endpoints
- Patch application coverage for internet-facing services
- Office macro configuration and policy controls
- User application hardening settings
- Restriction of administrative privilege assignment
- Operating system patch currency across scoped assets
- Multi-factor authentication coverage for administrative accounts
- Daily backup configuration and tested restore procedures
What was delivered
- Written baseline review report with maturity level per strategy
- Prioritised finding register with recommended remediation order
- Executive summary suitable for board or insurer presentation
- Remediation guidance notes for each finding requiring action
Not included
- ×Penetration testing or active exploitation attempts
- ×Review of infrastructure outside the defined scope boundary
- ×Certification or compliance certification issuance
- ×Ongoing monitoring or managed security services
What changed after the work
The organisation submitted the review report to their cyber insurer as evidence of their current controls posture. Internal teams used the finding register to prioritise remediation work for the following quarter. A follow-on re-assessment was requested six months later.
Recommended next step
Essential Eight re-assessment after remediation, or Monthly Security Advisory for ongoing guidance.
Why we publish these summaries
Security buyers need to understand what they are purchasing before committing. These cases describe what was in scope, what was delivered, and what was not included — so you can evaluate whether the service fits your situation.
How to read these cases
Proof without overclaiming
Each security case is a real completed client engagement. Client names and identifying operational details are withheld for confidentiality. It shows the trigger, agreed scope, reviewed areas, deliverables, boundaries and next step so buyers can understand how BilgeQor turns risk context into a practical Security File.
Scope confirmed
Each case starts from a written scope, not an open-ended promise.
Evidence preserved
Deliverables are described as records, summaries, findings and remediation guidance.
Boundaries clear
The examples avoid client names, certification claims, audit approval and guaranteed outcomes.
Security Reviews
Structured baseline and framework assessments for organisations evaluating their security posture.
Situation
A professional services firm handling confidential client documentation for enterprise accounts needed to demonstrate security readiness to prospective clients conducting vendor due diligence. Partners required a structured evidence base covering access controls, endpoint practices, and data handling procedures before a major client engagement.
What was in scope
Review of the firm's primary workstation environment, email and file-sharing configuration, administrative access controls, and data handling procedures. Assessment mapped findings to practical remediation priorities. Scope was defined and confirmed in writing before work commenced.
Timeline and working model
Review completed within ten business days of scope confirmation. No on-site access required. All review conducted remotely against agreed documentation and platform configuration evidence.
What was reviewed
- Email platform security configuration and phishing exposure controls
- File-sharing and cloud storage access controls and external sharing policies
- Administrative privilege assignment across workstation and platform accounts
- Multi-factor authentication coverage for business-critical accounts
- Endpoint patch currency and software update practices
- Data handling and offboarding procedures for staff and contractor access
What was delivered
- Written readiness review report with prioritised findings
- Executive summary suitable for client-facing due diligence review
- Remediation priority list with recommended action sequence
- Guidance notes for each finding requiring attention
What changed after the work
The firm used the executive summary as supporting documentation in their vendor questionnaire response. Internal partners implemented the priority access control findings before the client engagement commenced. A follow-on advisory engagement was discussed for ongoing quarterly review.
Not included
Recommended next step
Monthly Security Advisory for structured ongoing guidance, or a scheduled re-assessment after implementing priority findings.
Situation
What was delivered
- Written baseline review report with prioritised findings
- Executive summary suitable for hospital procurement review
4 ×
Recommended next step
Monthly Security Advisory for ongoing posture visibility, or a re-assessment after implementing priority findings.
Situation
What was delivered
- Written baseline review report with prioritised findings
- Executive summary suitable for partner due diligence review
4 ×
Recommended next step
Monthly Security Advisory for structured ongoing guidance, or re-assessment after implementing priority findings.
Website & System Hardening
Hands-on configuration hardening and verification for web applications and infrastructure.
Situation
An e-commerce operator launching a new storefront on a custom stack required pre-launch security hardening. The team had development confidence but no dedicated security resource to review the configuration before go-live.
What was in scope
Security hardening of a production-bound web application covering server configuration, HTTP security header implementation, authentication flow review, and dependency currency check. Scope limited to the single application instance and its associated infrastructure layer.
Timeline and working model
Review completed in eight business days. Application was live-ready after implementing the priority findings. Post-remediation confirmation was completed within three business days of resubmission.
What was reviewed
- HTTP security header configuration and policy settings
- TLS/SSL configuration and certificate chain
- Authentication flow and session management controls
- Third-party dependency currency and known vulnerability status
- Administrative access controls and credential exposure checks
- Error handling and information disclosure review
What was delivered
- Hardening report with findings categorised by severity
- Configuration recommendations with implementation guidance
- Remediation checklist for the development team
- Post-remediation confirmation review (one round included)
What changed after the work
Priority findings were resolved before the launch date. The team used the hardening checklist as a template for subsequent application deployments. No critical issues were identified after the post-remediation confirmation review.
Not included
Recommended next step
App Security Review for the companion mobile application, or Monthly Security Advisory for ongoing operational support.
Situation
What was delivered
- Hardening report with findings categorised by severity and priority
- Configuration recommendations with step-by-step implementation guidance
4 ×
Recommended next step
App Security Review for the API layer and any mobile client, or Monthly Security Advisory for structured ongoing guidance.
Situation
What was delivered
- Hardening report with findings categorised by severity and priority
- Configuration recommendations with implementation guidance
4 ×
Recommended next step
App Security Review for any mobile client, or Monthly Security Advisory for ongoing operational guidance.
Application Security
Mobile and web application security reviews for teams preparing for distribution or compliance.
Situation
A healthcare technology provider preparing a mobile application for clinical use required a security review before distributing to practitioners. Regulatory readiness and patient data handling were identified as priorities by the client's leadership team.
What was in scope
Security review of a mobile clinical management application covering the application binary, its API communication layer, and the authentication and data storage implementation. iOS and Android builds reviewed within the agreed scope. Review conducted against OWASP Mobile Top 10 as the reference framework.
Timeline and working model
Review delivered within fourteen business days of receiving the agreed application builds and API documentation. All review conducted remotely. No production environment access required.
What was reviewed
- Application binary and static analysis for known vulnerability patterns
- API communication security including transport layer and authentication
- Patient data storage approach and local device encryption
- Authentication and session token management
- Third-party SDK and library currency
- Sensitive data handling across application lifecycle states
What was delivered
- Mobile security review report with findings and severity classification
- OWASP Mobile Top 10 coverage summary
- Developer-ready remediation guidance for each finding
- Data handling assessment with recommendations
What changed after the work
Development team addressed high and critical findings before distribution to clinical users. The review report was referenced during internal governance review. A care plan advisory engagement was initiated for scheduled review and written next actions, not ongoing application monitoring or response coverage.
Not included
Recommended next step
Monthly Security Advisory to maintain ongoing security posture, or re-assessment after major application version changes.
Situation
What was delivered
- Mobile security review report with findings and severity classification
- OWASP Mobile Top 10 coverage summary
4 ×
Recommended next step
Monthly Security Advisory for ongoing compliance posture support, or re-assessment after significant application version changes.
Situation
What was delivered
- API security review report with findings and severity classification
- Developer-ready remediation guidance for each finding
4 ×
Recommended next step
Monthly Security Advisory for structured ongoing API and platform security, or re-assessment after major API version changes.
Advisory & Recovery
Ongoing advisory support and structured incident recovery for operational security teams.
Situation
A logistics technology company scaling operations across multiple cities needed structured security guidance without the cost of a full-time security hire. The company had recently experienced a credential exposure incident and wanted systematic advisory support.
What was in scope
Ongoing monthly advisory covering the organisation's web platform, internal tooling, and team security practices. Advisory scope defined at onboarding and adjustable within agreed boundaries on a quarterly basis. Not a managed security service — advisory and guidance only.
Timeline and working model
Ongoing monthly engagement. Initial onboarding completed within one week of confirmation. Monthly advisory sessions on a fixed cadence. Engagement operates on a rolling monthly basis with quarterly scope review.
What was reviewed
- Monthly review of security posture against agreed control set
- Patch and update currency review for scoped systems
- Access control and privilege review each quarter
- Incident and alert review from client-provided logs
- Team guidance on emerging threats relevant to the sector
What was delivered
- Monthly advisory brief with observations and recommended actions
- Quarterly posture summary report
- Prioritised action list after each review cycle
- Direct advisory channel for time-sensitive questions within scope
What changed after the work
The team implemented a structured patch review process using the monthly advisory brief as the operational guide. Access control issues identified in the first quarter were remediated before the next review cycle. The engagement continued on renewal after the initial three-month term.
Not included
Recommended next step
Advisory renewal, or a scheduled baseline review for a more formal posture assessment.
Situation
What was delivered
- Monthly advisory brief with observations and recommended actions
- Quarterly posture summary with trend observations
4 ×
Recommended next step
Advisory renewal, or a structured App Security Review for the loyalty platform application layer.
Situation
What was delivered
- Initial triage report with confirmed and suspected compromise scope
- Visible risk map with prioritised immediate actions
5 ×
Discovery call recommended
Recommended next step
Monthly Security Advisory for structured ongoing security posture, or a Baseline Review after full recovery to assess control improvements.
Ready to start a security engagement?
Most engagements start with a request. Share the service or scope you have in mind; we will confirm the right review, hardening or advisory path before any payment step.
